One Zero-Day, 6 High-Risk Flaws
10
Dec
2025

One Zero-Day, 6 High-Risk Flaws

Microsoft patched 57 vulnerabilities in its Patch Tuesday December 2025 update, including one exploited zero-day and six high-risk vulnerabilities. The…

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS
10
Dec
2025

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers…

The US Won't Sanction China for Salt Typhoon Hacking
10
Dec
2025

The US Won’t Sanction China for Salt Typhoon Hacking

An AI image creator startup left its database unsecured, exposing more than a million images and videos its users had…

Windows Defender Firewall Flaw Allows Attackers to Access Sensitive Data
10
Dec
2025

Windows Defender Firewall Flaw Allows Attackers to Access Sensitive Data

Microsoft has officially addressed a new security vulnerability affecting the Windows Defender Firewall Service that could allow threat actors to…

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability
10
Dec
2025

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting…

2 Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’
10
Dec
2025

2 Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’

To try to determine the probability of those name repetitions being a coincidence, Cary checked two databases of Chinese names…

Microsoft Releases New Guidance to Combat the Shai-Hulud 2.0 Supply Chain Threat
10
Dec
2025

Microsoft Releases New Guidance to Combat the Shai-Hulud 2.0 Supply Chain Threat

Microsoft has published comprehensive guidance addressing the Shai-Hulud 2.0 supply chain attack, one of the most significant cloud-native ecosystem compromises…

North Korean Hackers Deploy EtherRAT Malware in React2Shell Exploits
10
Dec
2025

North Korean Hackers Deploy EtherRAT Malware in React2Shell Exploits – Hackread – Cybersecurity News, Data Breaches, AI, and More

A team of cybersecurity researchers at Sysdig, a firm specialising in protecting cloud and container-based apps, has found a new…

Microsoft logo
10
Dec
2025

December Patch Tuesday fixes three zero-days, including one that hijacks Windows devices

These updates from Microsoft fix serious security issues, including three that attackers are already exploiting to take control of Windows…

React Server Components crisis escalates as security teams respond to compromises
10
Dec
2025

React Server Components crisis escalates as security teams respond to compromises

Security teams on Tuesday said they are responding to a rising number of potential compromises linked to a critical vulnerability…

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks
10
Dec
2025

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks

A sophisticated new phishing framework dubbed “Spiderman” has emerged in the cybercrime underground, dramatically lowering the barrier to entry for…

Gemini Zero-Click Flaw Let Attackers Access Gmail, Calendar, and Google Docs
10
Dec
2025

Gemini Zero-Click Flaw Let Attackers Access Gmail, Calendar, and Google Docs

A critical vulnerability in Google Gemini Enterprise and Vertex AI Search, dubbed GeminiJack, that allows attackers to exfiltrate sensitive corporate data…