Three hacking groups, two vulnerabilities and all eyes on China
How Agentic BAS AI Turns Threat Headlines Into Defense Strategies
Picus Security explains why relying on LLM-generated attack scripts is risky and how an agentic approach maps real threat intel to safe, validated TTPs. Their breakdown shows how teams can turn headline threats into reliable defense checks without unsafe automation.
Zero-Day to Zero-Hour: React2Shell (CVE-2025-55182) Becomes One of the Most Rapidly Weaponized RSC Vulnerability
China-nexus groups rapidly exploited React2Shell (CVE-2025-55182). Learn how the React Server Components flaw was weaponized within minutes of disclosure.
Russian police bust bank-account hacking gang that used NFCGate-based malware
UK intelligence warns AI 'prompt injection' attacks might never go away
Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration
Learn how QuasarRAT configuration extraction works using pythonnet, dnlib and IL analysis to recover encrypted .NET malware settings.
CERT-AGID 29 novembre – 5 dicembre: phishing a tema Governo italiano e Agenzia delle Entrate
Settimana segnata da un forte incremento dei fake PagoPA, dall’emergere di phishing che imita il Governo e l’Agenzia delle Entrate e da nuove minacce mobili distribuite via SMS.
OpenAI denies rolling out ads on ChatGPT paid plans
ChatGPT is allegedly showing ads to those who pay $20 for the Plus subscription, but OpenAI says this is an app recommendation feature, not an ad.
Portugal updates cybercrime law to exempt security researchers
Portugal has modified its cybercrime law to establish a legal safe harbor for good-faith security research and to make hacking non-punishable under certain strict conditions.
CMMC Final Assessment: What I Did Right, What I’d Change, and How You Can Prepare
A senior security analyst shares key lessons, wins, and improvements from completing a CMMC audit to help others prepare effectively.
SecjuiceCON 2026
SecjuiceCON is an online event for infosec and OSINT industry insiders, and we'd love for you to talk to our audience about your wisdom and learnings.
Data Breach at Mid South Pulmonary & Sleep Specialists: Anubis Speaks
Mid South Pulmonary & Sleep Specialists (MSPS), a major clinical center specializing in respiratory diseases and sleep disorders in Tennessee, has been hit by a severe cyberattack claimed by the ransomware group Anubis.
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors.
New wave of VPN login attempts targets Palo Alto GlobalProtect portals
A campaign has been observed targeting Palo Alto GlobalProtect portals with login attempts and launching scanning activity against SonicWall SonicOS API endpoints.
LockBit Returns With New Data Leak Site, 7 Victims
The LockBit ransomware group is making a comeback, with a new data leak site and seven new victims. Can the top ransomware group of all time get back to the top?
Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill
A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious connections to a Kremlin-connected oligarch whose Russian university builds drones for Russia's war against Ukraine.
KinoKong - 817,808 breached accounts
In March 2021, the Russian online streaming service KinoKong suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed over 800k unique email addresses along with names, usernames, IP addresses and MD5 password hashes.
Maryland man sentenced for N. Korea IT worker scheme involving US government contracts
Barts Health NHS discloses data breach after Oracle zero-day hack
Barts Health NHS Trust has announced that Clop ransomware actors have stolen files from a database by exploiting a vulnerability in its Oracle E-business Suite software.
Google rilascia patch per 107 vulnerabilità Android: due zero-day sotto attacco
L’Android Security Bulletin del mese di dicembre 2025 contiene gli aggiornamenti di sicurezza che correggono 107 vulnerabilità nel sistema operativo mobile di Google. Tra queste, anche due zero-day che la società ha confermato essere state sfruttate attivamente in attacchi reali. Ecco tutti i dettagli
A Practical Guide to Continuous Attack Surface Visibility
Passive scan data goes stale fast as cloud assets shift daily, leaving teams blind to real exposures. Sprocket Security shows how continuous, automated recon gives accurate, up-to-date attack surface visibility.
FBI warns of virtual kidnapping scams using altered social media photos
The FBI warns that criminals are altering images shared on social media and using them as fake proof of life photos in virtual kidnapping ransom scams.
Chinese hackers exploiting React2Shell bug impacting countless websites, Amazon researchers say
Voucher digitali MIMIT: come accedere ai 150 milioni per la resilienza digitale delle PMI
PMI e lavoratori autonomi potranno ottenere le agevolazioni pari a 150 milioni di euro, stanziati dal Ministero delle Imprese e del Made in Italy, per pianificare gli investimenti per migliorare la propria postura cyber. Ecco il perimetro del voucher cyber del Mimit e come accedervi
Sintesi riepilogativa delle campagne malevole nella settimana del 29 novembre – 5 dicembre
Iniezione indiretta di prompt: a rischio le informazioni aziendali
Lakera ha pubblicato una ricerca in cui dimostra che l'iniezione indiretta di prompt permette agli attaccanti di prendere di mira i dati acquisiti dall'IA.
Petco confirms security lapse exposed customers’ personal data
The pet company has published almost no details about what happened, who was affected, and what personal data was exposed.
Così basta un clic per consegnare porta di casa e telecamere a un hacker
Una vulnerabilità di Tuya, una delle piattaforme di domotica più popolari al mondo, permetteva a un malintenzionato di collegare tutti i device smart delle vittime al proprio account Alexa, esponendo centinaia di migliaia di dispositivi smart in tutto il mondo. La scoperta del Gruppo Abissi
On cyber, Trump’s national security strategy emphasizes industry and regional partners
L’unica soluzione certa è non fidarsi mai
Approcciarsi per soluzioni alla sicurezza cyber non fa altro che rinviare l'inevitabile momento in cui tutta quella fiducia assumerà l'amaro sapore della delusione scoprendosi così decisamente malriposta