Aggregator
US Warns of Ongoing Pro-Russia Critical Infrastructure Hacks
U.S. and allied agencies warned of low-skill Russian-linked hacktivists breaching critical infrastructure by exploiting weak remote access tools, as federal prosecutors charged a Ukrainian national with helping orchestrate operations targeting water and energy systems.
OpenAI Braces for AI Models That Could Breach Defenses
OpenAI said Wednesday it is preparing for artificial intelligence models to reach "high" cybersecurity risk levels, marking an escalation in the dual-use capabilities that could strengthen defenses or enable sophisticated attacks.
Saviynt Gets $700M at $3B Valuation to Fuel Identity Defense
Backed by $700 million in funding from KKR at a $3 billion valuation, Saviynt plans to accelerate innovation in identity security for humans, machines and AI agents. The Series B investment supports global expansion and continued platform development to meet evolving enterprise needs.
UK ICO Fines LastPass Over 2022 Data Breach
The British data regulator imposed a fine of 1.2 million pounds against password manager LastPass over a 2022 data breach that exposed the data of millions of its customers. Unidentified hackers stole backup data from LastPass's Amazon Web Services S3 bucket.
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
New infosec products of the week: December 12, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Apptega, Backslash Security, BigID, Black Kite, Bugcrowd, NinjaOne, Nudge Security, and Veza. Apptega Policy Manager streamlines policy creation and compliance oversight Apptega revealed its Policy Manager module, expanding the company’s platform to automate the creation, review, and oversight of custom business policies. With this enhancement, Apptega enables partners and in-house security and compliance teams to maintain auditable policies with minimal … More →
The post New infosec products of the week: December 12, 2025 appeared first on Help Net Security.
SpearSpray: The Stealthy Tool That Bypasses Lockout Policies in Active Directory
SpearSpray is an advanced password spraying tool designed specifically for Active Directory environments. It combines user enumeration via LDAP
The post SpearSpray: The Stealthy Tool That Bypasses Lockout Policies in Active Directory appeared first on Penetration Testing Tools.
PATCH NOW: Google Issues Emergency Chrome Update for Actively Exploited Zero-Day
Google has released an unscheduled Chrome update to patch a zero-day vulnerability already being exploited in active attacks.
The post PATCH NOW: Google Issues Emergency Chrome Update for Actively Exploited Zero-Day appeared first on Penetration Testing Tools.
Микки Маус и Sora. Disney официально пускает ИИ в свои вселенные (но живых актеров трогать нельзя).
PATCH NOW: Microsoft Fixes 57 Flaws, Including Three Zero-Days Actively Exploited
Microsoft has released its December security updates: Patch Tuesday brings fixes for 57 vulnerabilities, including three zero-days (one
The post PATCH NOW: Microsoft Fixes 57 Flaws, Including Three Zero-Days Actively Exploited appeared first on Penetration Testing Tools.
Japan’s Largest Scam: Chinese Duo Used Hijacked Accounts to Manipulate Stock Prices
The investigation in Japan has detained two Chinese nationals suspected of orchestrating the largest known market-manipulation scheme involving
The post Japan’s Largest Scam: Chinese Duo Used Hijacked Accounts to Manipulate Stock Prices appeared first on Penetration Testing Tools.
ChimeraWire: The Click-Fraud Trojan Disguised as a Human User
Experts at Doctor Web have identified a new click-fraud trojan, Trojan.ChimeraWire, which disguises itself as the activity of
The post ChimeraWire: The Click-Fraud Trojan Disguised as a Human User appeared first on Penetration Testing Tools.
Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
The financially motivated group Storm-0249, long known as a broker of initial access for ransomware operators, has markedly
The post Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks appeared first on Penetration Testing Tools.
React2Shell Exploit: Botnets Target 150K+ Devices Daily with Node.js Flaw
A newly discovered vulnerability in Node.js, designated CVE-2025-55182 and informally dubbed React2Shell, has become a favored weapon of
The post React2Shell Exploit: Botnets Target 150K+ Devices Daily with Node.js Flaw appeared first on Penetration Testing Tools.
Khashoggi’s Widow Files French Complaint Over Pegasus Spyware Infection
The widow of Saudi dissident journalist Jamal Khashoggi has filed a complaint with the French prosecutor’s office, alleging
The post Khashoggi’s Widow Files French Complaint Over Pegasus Spyware Infection appeared first on Penetration Testing Tools.
Digital War Crimes: ICC Drafts Policy to Judge Cyber-Enabled Genocide and Aggression
The International Criminal Court has released a draft policy aimed at confronting crimes committed through digital technologies. The
The post Digital War Crimes: ICC Drafts Policy to Judge Cyber-Enabled Genocide and Aggression appeared first on Penetration Testing Tools.