RondoDox botnet exploits React2Shell flaw to breach Next.js servers
31
Dec
2025

RondoDox botnet exploits React2Shell flaw to breach Next.js servers

The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. First…

DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware
31
Dec
2025

DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware

Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and…

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry
31
Dec
2025

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry

Dec 31, 2026Ravie LakshmananCybersecurity / Malware Cybersecurity researchers have disclosed details of what appears to be a new strain of…

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins
31
Dec
2025

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to…

API Connect Bug
31
Dec
2025

IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass

Dec 31, 2026Ravie LakshmananAPI Security / Vulnerability IBM has disclosed details of a critical security flaw in API Connect that…

Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation
31
Dec
2025

Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation

Large Language Models (LLMs) have revolutionized software development, democratizing coding capabilities for non-programmers. However, this accessibility has introduced a severe…

2 US Cybersecurity Experts Guilty of Extortion Scheme for ALPHV Ransomware
31
Dec
2025

2 US Cybersecurity Experts Guilty of Extortion Scheme for ALPHV Ransomware – Hackread – Cybersecurity News, Data Breaches, AI, and More

Two Americans who built their careers protecting companies from online threats have admitted to doing the exact opposite. Ryan Goldberg,…

APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities
31
Dec
2025

APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities

APT36, also known as Transparent Tribe, has launched a new malware campaign that targets Indian government and strategic entities by…

30,000 Korean Air Employee Records Stolen After Third-Party Software Hack
31
Dec
2025

30,000 Korean Air Employee Records Stolen as Cl0p Leaks Data Online – Hackread – Cybersecurity News, Data Breaches, AI, and More

In a worrying turn of events for the aviation industry, Korean Air has confirmed that the personal details of roughly…

AI-Powered Pentesting Tool With Claude, GPT, and Gemini models to Detect vulnerabilities
31
Dec
2025

AI-Powered Pentesting Tool With Claude, GPT, and Gemini models to Detect vulnerabilities

NeuroSploitv2 is an AI-powered penetration testing framework that automates critical aspects of offensive security operations through advanced language models. The…

Fears Mount That US Federal Cybersecurity Is Stagnating—or Worse
31
Dec
2025

Fears Mount That US Federal Cybersecurity Is Stagnating—or Worse

This fall’s weekslong government shutdown only added to concerns about the state of federal cybersecurity—creating the possibility of blind spots…

VPN to view adult content
31
Dec
2025

In 2025, age checks started locking people out of the internet

If 2024 was the year lawmakers talked about online age verification, 2025 was the year they actually flipped the switch.​…