12/12

Project Zero: A look at an Android ITW DNG exploit

https://googleprojectzero.blogspot.com/2025/12/a-look-at-android-itw-dng-exploit.html
Project Zero: A look at an Android ITW DNG exploit

🔴 Executive Offense - (Release) The Arcanum Prompt Injection Taxonomy v1.5

https://executiveoffense.beehiiv.com/p/executive-offense-release-the-arcanum-prompt-injection-taxonomy-v1-5
🔴 Executive Offense - (Release) The Arcanum Prompt Injection Taxonomy v1.5

MKVCinemas streaming piracy service with 142M visits shuts down

https://www.bleepingcomputer.com/news/security/mkvcinemas-streaming-piracy-service-with-142m-visits-shuts-down/
MKVCinemas streaming piracy service with 142M visits shuts down

Ransomware Decryption Intelligence

https://blog.bushidotoken.net/2021/10/ransomware-decryption-intelligence.html
Ransomware Decryption Intelligence

Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite

https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/
Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite

Former Accenture Employee Charged Over Cybersecurity Fraud - SecurityWeek

https://www.securityweek.com/former-accenture-employee-charged-over-cybersecurity-fraud/
Former Accenture Employee Charged Over Cybersecurity Fraud - SecurityWeek

CISA orders feds to patch actively exploited Geoserver flaw

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/
CISA orders feds to patch actively exploited Geoserver flaw

https://arxiv.org/pdf/2512.09882

https://arxiv.org/pdf/2512.09882

Gogs Zero-Day RCE (CVE-2025-8110) Actively Exploited | Wiz Blog

https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
Gogs Zero-Day RCE (CVE-2025-8110) Actively Exploited | Wiz Blog

Notepad++ fixes flaw that let attackers push malicious update files

https://www.bleepingcomputer.com/news/security/notepad-plus-plus-fixes-flaw-that-let-attackers-push-malicious-update-files/
Notepad++ fixes flaw that let attackers push malicious update files

Fake ‘One Battle After Another’ torrent hides malware in subtitles

https://www.bleepingcomputer.com/news/security/fake-one-battle-after-another-torrent-hides-malware-in-subtitles/
Fake ‘One Battle After Another’ torrent hides malware in subtitles

Kali Linux 2025.4 released with 3 new tools, desktop updates

https://www.bleepingcomputer.com/news/security/kali-linux-20254-released-with-3-new-tools-desktop-updates/
Kali Linux 2025.4 released with 3 new tools, desktop updates