Critical Net-SNMP Flaw CVE-2025-68615 Allows Remote Buffer Overflow and Service Crashes
https://thecyberexpress.com/cve-2025-68615-critical-net-snmp-snmptrapd/
https://thecyberexpress.com/cve-2025-68615-critical-net-snmp-snmptrapd/
The Cyber Express
CVE-2025-68615: Critical Net-SNMP Snmptrapd Flaw
CVE-2025-68615 is a critical Net-SNMP snmptrapd vulnerability enabling buffer overflow, service crashes, and potential remote code execution.
Trust Wallet warns users to update Chrome extension after $7M security loss
https://securityaffairs.com/186163/cyber-crime/trust-wallet-warns-users-to-update-chrome-extension-after-7m-security-loss.html
https://securityaffairs.com/186163/cyber-crime/trust-wallet-warns-users-to-update-chrome-extension-after-7m-security-loss.html
Security Affairs
Trust Wallet warns users to update Chrome extension after $7M security loss
Trust Wallet urged users to update its Chrome extension after a security incident caused about $7 million in losses.
NPM package with 56,000 downloads compromises WhatsApp accounts
https://securityaffairs.com/186174/malware/npm-package-with-56000-downloads-compromises-whatsapp-accounts.html
https://securityaffairs.com/186174/malware/npm-package-with-56000-downloads-compromises-whatsapp-accounts.html
Security Affairs
NPM package with 56,000 downloads compromises WhatsApp accounts
An NPM package with over 56,000 downloads stole WhatsApp credentials, hid its activity, and installed a backdoor.
LangChain core vulnerability allows prompt injection and data exposure
https://securityaffairs.com/186185/hacking/langchain-core-vulnerability-allows-prompt-injection-and-data-exposure.html
https://securityaffairs.com/186185/hacking/langchain-core-vulnerability-allows-prompt-injection-and-data-exposure.html
Security Affairs
LangChain core vulnerability allows prompt injection and data exposure
A critical flaw in LangChain Core could allow attackers to steal sensitive secrets and manipulate LLM responses via prompt injection.
DIY or Pay Up: Framework’s New Price Hike and the “Bring Your Own RAM” Era
https://securityonline.info/diy-or-pay-up-frameworks-new-price-hike-and-the-bring-your-own-ram-era/
https://securityonline.info/diy-or-pay-up-frameworks-new-price-hike-and-the-bring-your-own-ram-era/
Daily CyberSecurity
DIY or Pay Up: Framework’s New Price Hike and the "Bring Your Own RAM" Era
Framework raises laptop prices again due to soaring RAM costs, now urging customers to buy their own memory elsewhere via integrated PCPartPicker links.
Beyond the Frame: How MIT & NVIDIA’s FoundationMotion is Teaching AI to Truly “See” Movement
https://securityonline.info/beyond-the-frame-how-mit-nvidias-foundationmotion-is-teaching-ai-to-truly-see-movement/
https://securityonline.info/beyond-the-frame-how-mit-nvidias-foundationmotion-is-teaching-ai-to-truly-see-movement/
Daily CyberSecurity
Beyond the Frame: How MIT & NVIDIA’s FoundationMotion is Teaching AI to Truly "See" Movement
MIT and NVIDIA unveil FoundationMotion, an automated system that enables AI to master complex video motion, outperforming Gemini in autonomous driving scenes.
The Hot Seat: OpenAI Offers $555K to Lead Safety Amid Wrongful-Death Lawsuits
https://securityonline.info/the-hot-seat-openai-offers-555k-to-lead-safety-amid-wrongful-death-lawsuits/
https://securityonline.info/the-hot-seat-openai-offers-555k-to-lead-safety-amid-wrongful-death-lawsuits/
Daily CyberSecurity
The Hot Seat: OpenAI Offers $555K to Lead Safety Amid Wrongful-Death Lawsuits
Sam Altman is hiring a Head of Preparedness with a $555K salary to combat AI mental health risks and lawsuits. Is this the most stressful job in tech?
Open-Source Standoff: GitHub Freezes Rockchip’s Code After Two-Year FFmpeg License Battle
https://securityonline.info/open-source-standoff-github-freezes-rockchips-code-after-two-year-ffmpeg-license-battle/
https://securityonline.info/open-source-standoff-github-freezes-rockchips-code-after-two-year-ffmpeg-license-battle/
Daily CyberSecurity
Open-Source Standoff: GitHub Freezes Rockchip’s Code After Two-Year FFmpeg License Battle
GitHub disables Rockchip's MPP repository after a DMCA takedown by FFmpeg. The move follows a two-year standoff over blatant LGPL license violations.
Beyond the Hype: General AI Surges as Image and Writing Tools Face a 2025 Reality Check
https://securityonline.info/beyond-the-hype-general-ai-surges-as-image-and-writing-tools-face-a-2025-reality-check/
https://securityonline.info/beyond-the-hype-general-ai-surges-as-image-and-writing-tools-face-a-2025-reality-check/
Daily CyberSecurity
Beyond the Hype: General AI Surges as Image and Writing Tools Face a 2025 Reality Check
Similarweb’s Dec 2025 report reveals a shift: General AI and Voice grow while creative tools slip. Gemini leads growth as the market pivots to automation.
Security Affairs newsletter Round 556 by Pierluigi Paganini – INTERNATIONAL EDITION
https://securityaffairs.com/186200/breaking-news/security-affairs-newsletter-round-556-by-pierluigi-paganini-international-edition.html
https://securityaffairs.com/186200/breaking-news/security-affairs-newsletter-round-556-by-pierluigi-paganini-international-edition.html
Security Affairs
security-affairs-newsletter-round-556-by-pierluigi-paganini-international-edition
A new round of weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs in your email box
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 77
https://securityaffairs.com/186206/malware/security-affairs-malware-newsletter-round-76-2.html
https://securityaffairs.com/186206/malware/security-affairs-malware-newsletter-round-76-2.html
Security Affairs
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 77
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
Stolen LastPass backups enable crypto theft through 2025
https://securityaffairs.com/186191/digital-id/stolen-lastpass-backups-enable-crypto-theft-through-2025.html
https://securityaffairs.com/186191/digital-id/stolen-lastpass-backups-enable-crypto-theft-through-2025.html
Security Affairs
Stolen LastPass backups enable crypto theft through 2025
Stolen vault backups from the 2022 LastPass breach are still being cracked, allowing attackers to steal crypto as late as 2025.
Condé Nast faces major data breach: 2.3M WIRED records leaked, 40M more at risk
https://securityaffairs.com/186224/data-breach/conde-nast-faces-major-data-breach-2-3m-wired-records-leaked-40m-more-at-risk.html
https://securityaffairs.com/186224/data-breach/conde-nast-faces-major-data-breach-2-3m-wired-records-leaked-40m-more-at-risk.html
Security Affairs
Condé Nast faces major data breach: 2.3M WIRED records leaked, 40M more at risk
Hacker claims Condé Nast breach, leaking 2.3M WIRED subscriber records and threatening to expose up to 40M more from other brands.
The $70 Chip War: Why Google is Firing Execs and Apple is Bracing for a 230% Price Surge
https://securityonline.info/the-70-chip-war-why-google-is-firing-execs-and-apple-is-bracing-for-a-230-price-surge/
https://securityonline.info/the-70-chip-war-why-google-is-firing-execs-and-apple-is-bracing-for-a-230-price-surge/
Daily CyberSecurity
The $70 Chip War: Why Google is Firing Execs and Apple is Bracing for a 230% Price Surge
Google and Microsoft execs are clashing with South Korean suppliers as a massive HBM shortage forces Apple to face a 230% price hike for iPhone RAM.
Fixing the “RAM Tax”: Microsoft’s New Plan to Make File Explorer Search 2X Faster
https://securityonline.info/fixing-the-ram-tax-microsofts-new-plan-to-make-file-explorer-search-2x-faster/
https://securityonline.info/fixing-the-ram-tax-microsofts-new-plan-to-make-file-explorer-search-2x-faster/
Daily CyberSecurity
Fixing the "RAM Tax": Microsoft’s New Plan to Make File Explorer Search 2X Faster
Microsoft is testing a major fix for Windows 11 File Explorer that eliminates redundant indexing, slashing RAM and CPU usage for faster file searches.
“Prefix Swap” Panic: Sophisticated “Jackson” Imposter Infiltrates Maven Central
https://securityonline.info/prefix-swap-panic-sophisticated-jackson-imposter-infiltrates-maven-central/
https://securityonline.info/prefix-swap-panic-sophisticated-jackson-imposter-infiltrates-maven-central/
Daily CyberSecurity
"Prefix Swap" Panic: Sophisticated "Jackson" Imposter Infiltrates Maven Central
Aikido Security uncovers the first sophisticated malware on Maven Central: a "prefix swap" attack on the Jackson library used to steal data.
The Stalled Update: Why Your Samsung’s Google Play Patch is Stuck in 2025
https://securityonline.info/the-stalled-update-why-your-samsungs-google-play-patch-is-stuck-in-2025/
https://securityonline.info/the-stalled-update-why-your-samsungs-google-play-patch-is-stuck-in-2025/
Daily CyberSecurity
The Stalled Update: Why Your Samsung’s Google Play Patch is Stuck in 2025
Samsung confirms it has "frozen" Google Play system updates to protect One UI 8 stability. Learn why your Galaxy is stuck and when it will resume in 2026.
The Christmas Drain: How a Backdoor in Trust Wallet v2.68 Stole $7M
https://securityonline.info/the-christmas-drain-how-a-backdoor-in-trust-wallet-v2-68-stole-7m/
https://securityonline.info/the-christmas-drain-how-a-backdoor-in-trust-wallet-v2-68-stole-7m/
Daily CyberSecurity
The Christmas Drain: How a Backdoor in Trust Wallet v2.68 Stole $7M
A malicious update to Trust Wallet v2.68.0 enabled a $7M Christmas Day heist. Users must update to v2.69.0 immediately to secure their funds.
The Performance Propeller: Google Proposes Upstreaming Its High-Octane Optimizer to LLVM
https://securityonline.info/the-performance-propeller-google-proposes-upstreaming-its-high-octane-optimizer-to-llvm/
https://securityonline.info/the-performance-propeller-google-proposes-upstreaming-its-high-octane-optimizer-to-llvm/
Daily CyberSecurity
The Performance Propeller: Google Proposes Upstreaming Its High-Octane Optimizer to LLVM
Google is upstreaming Propeller to LLVM, bringing its 10% performance boost for the Linux kernel and large-scale apps to the standard compiler toolchain.
EmEditor Compromised: “WALSHAM” Imposter Poisons Official Installer with Spyware
https://securityonline.info/emeditor-compromised-walsham-imposter-poisons-official-installer-with-spyware/
https://securityonline.info/emeditor-compromised-walsham-imposter-poisons-official-installer-with-spyware/
Daily CyberSecurity
EmEditor Compromised: "WALSHAM" Imposter Poisons Official Installer with Spyware
EmEditor confirms its official site was compromised, redirecting users to a malicious MSI signed by WALSHAM INVESTMENTS LIMITED to steal sensitive data.
CVE-2025-54322 (CVSS 10): AI Agents Uncover Critical Zero-Day in Global Networking Gear
https://securityonline.info/cve-2025-54322-cvss-10-ai-agents-uncover-critical-zero-day-in-global-networking-gear/
https://securityonline.info/cve-2025-54322-cvss-10-ai-agents-uncover-critical-zero-day-in-global-networking-gear/
Daily CyberSecurity
CVE-2025-54322 (CVSS 10): AI Agents Uncover Critical Zero-Day in Global Networking Gear
pwn.ai reveals CVE-2025-54322, the first remotely exploitable zero-day found by autonomous AI agents, targeting Xspeeder SD-WAN gear globally.