Sha1-Hulud 2.0 Supply Chain Attack: 25K+ npm Repos Exposed | Wiz Blog
https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
Shai Hulud 2.0 Strikes Again: Malware Supply-Chain Attack Hits Zapier & ENS Domains
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
poc_25_js_engine_security_in_2025.pdf
https://saelo.github.io/presentations/poc_25_js_engine_security_in_2025.pdf
Harvard University discloses data breach affecting alumni, donors
https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/
HEXACON 2025 - Crash One: A StarBucks Story (CVE-2025-24277) by Csaba Fitzl & Gergely Kalman - YouTube
https://youtu.be/IQzeFnqywh8?si=pz1hIsFoDPioB1Q0
Edit fiddle - JSFiddle - Code Playground
https://jsfiddle.net/4v6xksaf/
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs
https://thehackernews.com/2025/11/chinese-ai-model-deepseek-r1-generates.html
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
Add Magento SessionReaper (CVE-2025-54236) exploit module by Chocapikk · Pull Request #20725 · rapid7/metasploit-framework · GitHub
https://github.com/rapid7/metasploit-framework/pull/20725
ClickFix attack uses fake Windows Update screen to push malware
https://www.bleepingcomputer.com/news/security/clickfix-attack-uses-fake-windows-update-screen-to-push-malware/
Internet Speed Test | Fast.com
http://fast.com
Malicious Blender model files deliver StealC infostealing malware
https://www.bleepingcomputer.com/news/security/malicious-blender-model-files-deliver-stealc-infostealing-malware/
x64 Return Address Spoofing | HulkOps
https://hulkops.gitbook.io/blog/red-team/x64-return-address-spoofing
Real-estate finance services giant SitusAMC breach exposes client data
https://www.bleepingcomputer.com/news/security/real-estate-finance-services-giant-situsamc-breach-exposes-client-data/
Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
https://hackread.com/7-zip-vulnerability-public-exploit-manual-update/
Flare-On 12 – Task 9 | hasherezade's 1001 nights
https://hshrzd.wordpress.com/2025/11/20/flare-on-12-task-9/
Sha1-Hulud Supply Chain Attack: 800+ npm Packages and Thousands of GitHub Repos Compromised
https://cybersecuritynews.com/sha1-hulud-supply-chain-attack/
Microsoft to remove WINS support after Windows Server 2025
https://www.bleepingcomputer.com/news/microsoft/microsoft-to-remove-wins-support-after-windows-server-2025/