Risk
-
Over 4,300 Domains Used in Mass Phishing Campaign Targeting Hotel Guests
Researchers say a Russian-speaking threat actor registered more than 4,300 domains this year to run a large phishing campaign impersonating hotel booking services and harvesting payment data and credentials.
-
CISA orders federal agencies to remediate two exploited Cisco firewall flaws
CISA ordered U.S. federal agencies to remediate two actively exploited Cisco ASA and Firepower vulnerabilities (CVE-2025-20333, CVE-2025-20362), warned that some devices reported as patched remain vulnerable, and added three flaws to its KEV catalog with a December 3, 2025 remediation deadline.
-
International police action disrupts Rhadamanthys, VenomRAT and Elysium operations
Authorities in nine countries, coordinated by Europol and Eurojust, dismantled infrastructure for Rhadamanthys, VenomRAT and Elysium by taking down 1,025 servers, seizing 20 domains and arresting a suspect in Greece as part of Operation Endgame.
-
Researchers: npm registry flooded by tens of thousands of fake packages in two‑year spam campaign
Researchers have identified a two‑year spam campaign that has flooded the npm registry with tens of thousands of fake packages using a worm-like mechanism to auto-publish new packages and potentially monetize the effort via the TEA protocol; investigators say attribution is unconfirmed and registry operators have removed the packages.
-
UK introduces Cyber Security and Resilience Bill to bolster critical infrastructure defenses
The UK government has introduced the Cyber Security and Resilience Bill to tighten protections for hospitals, energy, water and transport systems, build on the NIS Regulations, require managed service providers to meet security standards and report major incidents quickly, and impose turnover-based penalties for serious breaches.
-
Researchers detail Android RAT ‘Fantasy Hub’ sold as Malware‑as‑a‑Service on Telegram
Security researchers and industry trackers say an Android remote access trojan named Fantasy Hub is being sold on Russian‑language Telegram channels as a Malware‑as‑a‑Service, offering device takeover, SMS interception, APK trojanising, and subscription pricing while mirroring features seen in other Android RATs and banking trojans.
-
Researchers: Actors abused Triofox antivirus feature to execute code as SYSTEM
Researchers say the UNC6485 cluster exploited CVE-2025-12480 in Gladinet Triofox by spoofing a localhost host header to bypass authentication, then abused the product’s antivirus configuration to run a malicious payload as SYSTEM; vendors have released patches and investigators provided indicators of compromise.
-
Researchers link WhatsApp-propagated Maverick malware to Brazilian banking trojans
Researchers say Maverick, a WhatsApp-propagated malware, shares code and tactics with the Brazilian banking trojan Coyote and is being spread via automated WhatsApp Web sessions, with analysts noting ties to a group called Water Saci.
-
North Korean-linked group used Google device service to wipe South Korean Android phones
South Korean researchers say the North Korean-linked KONNI group abused Google’s device-management features to remotely factory-reset Android phones, using stolen credentials harvested via phishing and RATs spread over KakaoTalk.
-
U.S. Treasury sanctions eight people and two firms tied to North Korean money‑laundering and cybercrime
The U.S. Treasury has sanctioned eight individuals and two entities alleged to have laundered proceeds from North Korean cybercrime and fraudulent IT‑worker schemes, naming banks, an IT company and several representatives in China and Russia and linking crypto flows to those operations.










