12/18

New password spraying attacks target Cisco, PAN VPN gateways

https://www.bleepingcomputer.com/news/security/new-password-spraying-attacks-target-cisco-pan-vpn-gateways/
New password spraying attacks target Cisco, PAN VPN gateways

BlueDelta’s Persistent Campaign Against UKR.NET

https://www.recordedfuture.com/research/bluedeltas-persistent-campaign-against-ukrnet
BlueDelta’s Persistent Campaign Against UKR.NET

https://arxiv.org/pdf/2510.09272

https://arxiv.org/pdf/2510.09272

viewstate-security-workshop/EXPLOITING_KNOWN_MACHINE_WORKSHOP_v1.0_NahamCon2025_slides.pdf at main · irsdl/viewstate-security-workshop · GitHub

https://github.com/irsdl/viewstate-security-workshop/blob/main/EXPLOITING_KNOWN_MACHINE_WORKSHOP_v1.0_NahamCon2025_slides.pdf
viewstate-security-workshop/EXPLOITING_KNOWN_MACHINE_WORKSHOP_v1.0_NahamCon2025_slides.pdf at main · irsdl/viewstate-security-workshop · GitHub

Microsoft: Recent Windows updates break RemoteApp connections

https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-updates-break-azure-virtual-desktop-remoteapp-sessions/
Microsoft: Recent Windows updates break RemoteApp connections

Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access

https://cybersecuritynews.com/cisco-and-palo-alto-vpn-gateways-under-attack/
Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access

The Kernel Thought it was Safe to free() this Object... - YouTube

https://youtu.be/CkZn_SZPRfo?si=UYR404rJ2q6m85Lz
The Kernel Thought it was Safe to free() this Object... - YouTube

France arrests Latvian for installing malware on Italian ferry

https://www.bleepingcomputer.com/news/security/france-arrests-latvian-for-installing-malware-on-italian-ferry/
France arrests Latvian for installing malware on Italian ferry

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

https://thehackernews.com/2025/12/cisa-flags-critical-asus-live-update.html
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

Zeroday Cloud hacking event awards $320,0000 for 11 zero days

https://www.bleepingcomputer.com/news/security/zeroday-cloud-hacking-event-awards-320-0000-for-11-zero-days/
Zeroday Cloud hacking event awards $320,0000 for 11 zero days

US seizes E-Note crypto exchange for laundering ransomware payments

https://www.bleepingcomputer.com/news/security/us-seizes-e-note-crypto-exchange-for-laundering-ransomware-payments/
US seizes E-Note crypto exchange for laundering ransomware payments

University of Sydney suffers data breach exposing student and staff info

https://www.bleepingcomputer.com/news/security/university-of-sydney-suffers-data-breach-exposing-student-and-staff-info/
University of Sydney suffers data breach exposing student and staff info

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

HPE warns of maximum severity RCE flaw in OneView software

https://www.bleepingcomputer.com/news/security/hpe-warns-of-maximum-severity-rce-flaw-in-oneview-software/
HPE warns of maximum severity RCE flaw in OneView software

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

https://thehackernews.com/2025/12/hpe-oneview-flaw-rated-cvss-100-allows.html
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution