Aggregator
Ransomware Attack Update for the 9th of December 2025
SAP fixes three critical vulnerabilities across multiple products
Sinobi
You must login to view this content
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday
Spiderman Phishing Kit Targets European Banks with Real-Time Credential Theft
Ivanti warns customers of new EPM flaw enabling remote code execution
Qilin
You must login to view this content
The Dark Web Economy Behind Ad Fraud: What Marketers Don’t See
California man pleads guilty to RICO charges as DOJ indicts crypto theft gang
Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack
The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently. Attackers maliciously modified hundreds of publicly available packages, targeting developer environments, continuous integration and continuous delivery (CI/CD) pipelines, and cloud-connected workloads to harvest credentials and configuration secrets. The Shai‑Hulud 2.
The post Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack appeared first on Microsoft Security Blog.
Organizations can now buy cyber insurance that covers deepfakes
Cybersecurity insurer Coalition said it will start covering certain incidents where AI and deepfakes lead to reputational harm.
The post Organizations can now buy cyber insurance that covers deepfakes appeared first on CyberScoop.
Joint cyber security advisory on pro-Russia hacktivists conducting opportunistic attacks on global critical infrastructure
Microsoft security advisory – December 2025 monthly rollup (AV25-822)
Microsoft’s last Patch Tuesday of 2025 addresses 57 defects, including one zero-day
Microsoft closed out the year with 1,139 total defects patched, making it the second-largest year in volume behind 2020, according to Trend Micro.
The post Microsoft’s last Patch Tuesday of 2025 addresses 57 defects, including one zero-day appeared first on CyberScoop.
LeakNet
You must login to view this content
VMware security advisory (AV25-820)
Windows PowerShell now warns when running Invoke-WebRequest scripts
Mozilla security advisory (AV25-819)
Sinobi
You must login to view this content