DarkSpectre Browser Extension
31
Dec
2025

DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide

The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster, has been attributed to a third attack campaign…

Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
31
Dec
2025

Hackers drain $3.9M from Unleash Protocol after multisig hijack

The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract…

New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks
31
Dec
2025

New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks

A dangerous cybercrime tool known as ErrTraffic has appeared in underground forums, making it easier for attackers to trick users…

Singapore warns China-linked group UNC3886 targets its critical infrastructure
31
Dec
2025

Singapore CSA warns of maximun severity SmarterMail RCE flaw

Singapore CSA warns of maximun severity SmarterMail RCE flaw Pierluigi Paganini December 31, 2025 Singapore’s CSA warns of CVE-2025-52691, a…

Cybersecurity Changes I Expect in 2026
31
Dec
2025

Cybersecurity Changes I Expect in 2026

Here are the major changes I see coming for Cybersecurity in 2026. It becomes very clear that the primary security…

RondoDox botnet exploits React2Shell flaw to breach Next.js servers
31
Dec
2025

RondoDox botnet exploits React2Shell flaw to breach Next.js servers

The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. First…

DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware
31
Dec
2025

DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware

Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and…

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry
31
Dec
2025

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry

Dec 31, 2026Ravie LakshmananCybersecurity / Malware Cybersecurity researchers have disclosed details of what appears to be a new strain of…

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins
31
Dec
2025

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to…

API Connect Bug
31
Dec
2025

IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass

Dec 31, 2026Ravie LakshmananAPI Security / Vulnerability IBM has disclosed details of a critical security flaw in API Connect that…

Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation
31
Dec
2025

Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation

Large Language Models (LLMs) have revolutionized software development, democratizing coding capabilities for non-programmers. However, this accessibility has introduced a severe…

2 US Cybersecurity Experts Guilty of Extortion Scheme for ALPHV Ransomware
31
Dec
2025

2 US Cybersecurity Experts Guilty of Extortion Scheme for ALPHV Ransomware – Hackread – Cybersecurity News, Data Breaches, AI, and More

Two Americans who built their careers protecting companies from online threats have admitted to doing the exact opposite. Ryan Goldberg,…