PoC Released: MongoBleed Exploit Allows Unauthenticated Attackers to Drain MongoDB Memory
https://securityonline.info/poc-released-mongobleed-exploit-allows-unauthenticated-attackers-to-drain-mongodb-memory/
https://securityonline.info/poc-released-mongobleed-exploit-allows-unauthenticated-attackers-to-drain-mongodb-memory/
Daily CyberSecurity
PoC Released: MongoBleed Exploit Allows Unauthenticated Attackers to Drain MongoDB Memory
MongoBleed (CVE-2025-14847) allows unauthenticated MongoDB memory leaks. With Joe Desimone's PoC released, upgrade to v8.0.17 or v7.0.28 now!
The iOS 26.2 Trap: New WebKit Integer Overflow Discovered with PoC—Is Your iPhone at Risk?
https://securityonline.info/the-ios-26-2-trap-new-webkit-integer-overflow-discovered-with-poc-is-your-iphone-at-risk/
https://securityonline.info/the-ios-26-2-trap-new-webkit-integer-overflow-discovered-with-poc-is-your-iphone-at-risk/
Daily CyberSecurity
The iOS 26.2 Trap: New WebKit Integer Overflow Discovered with PoC—Is Your iPhone at Risk?
Joseph Goydish uncovers a critical integer overflow in iOS 26.2’s WebKit. Proof of Concept shows how attackers can crash browsers or trigger RCE.
2025 Changed How I See Cybersecurity in ASEAN—and It Wasn’t About Technology
https://thecyberexpress.com/cybersecurity-in-asean/
https://thecyberexpress.com/cybersecurity-in-asean/
The Cyber Express
Why Trust Is ASEAN’s New Cyber Perimeter
The most damaging cyber incidents across ASEAN this year did not start with malware, zero-days, or system breaches.
Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor
https://securityaffairs.com/186213/apt/evasive-panda-cyberespionage-campaign-uses-dns-poisoning-to-install-mgbot-backdoor.html
https://securityaffairs.com/186213/apt/evasive-panda-cyberespionage-campaign-uses-dns-poisoning-to-install-mgbot-backdoor.html
Security Affairs
Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor
A China-linked APT used DNS poisoning to deliver the MgBot backdoor in targeted cyber-espionage attacks in Türkiye, China, and India.
Why Peak Shopping Seasons Are Now Peak Cyber Risk Periods
https://thecyberexpress.com/the-global-commerce-vulnerability-window/
https://thecyberexpress.com/the-global-commerce-vulnerability-window/
The Cyber Express
The Global Commerce Vulnerability Window
Experts refer to these periods as the Global Commerce Vulnerability Window, marked by intense transaction volumes and limited human oversight.
Shai-Hulud Returns with ‘Golden Path’ Malware in Latest NPM Supply Chain Attack
https://thecyberexpress.com/shai-hulud-golden-path-malwar-npm-supply-chain/
https://thecyberexpress.com/shai-hulud-golden-path-malwar-npm-supply-chain/
The Cyber Express
Shai-Hulud Returns With ‘Golden Path’ Malware In Latest NPM Attacks
Weeks after the devastating "Second Coming" campaign crippled thousands of development environments, the threat actor behind the Shai-Hulud worm has returned.
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor
https://securelist.com/honeymyte-kernel-mode-rootkit/118590/
https://securelist.com/honeymyte-kernel-mode-rootkit/118590/
Securelist
The HoneyMyte APT now protects malware with a kernel-mode rootkit
Kaspersky discloses a 2025 HoneyMyte (aka Mustang Panda or Bronze President) APT campaign, which uses a kernel-mode rootkit to deliver and protect a ToneShell backdoor.
Former Georgian Security Chief Grigol Liluashvili Arrested on Multiple Bribery Charges
https://thecyberexpress.com/grigol-liluashvili-arrested/
https://thecyberexpress.com/grigol-liluashvili-arrested/
The Cyber Express
Grigol Liluashvili Arrested In Georgia Corruption Case
The Grigol Liluashvili arrest follows earlier reporting on scam call centers in Tbilisi, including the Scam Empire investigation.
👍1
Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets
https://thecyberexpress.com/critical-mongobleed-flaw-exploited-in-the-wild/
https://thecyberexpress.com/critical-mongobleed-flaw-exploited-in-the-wild/
The Cyber Express
Critical 'MongoBleed' Flaw Exploited In The Wild To Leak Database Secrets - The Cyber Express
Dubbed "MongoBleed" and tracked as CVE-2025-14847, the flaw represents a catastrophic breakdown in how MongoDB handles compressed data.
Korean Air discloses data breach after the hack of its catering and duty-free supplier
https://securityaffairs.com/186275/data-breach/korean-air-discloses-data-breach-after-the-hack-of-its-catering-and-duty-free-supplier.html
https://securityaffairs.com/186275/data-breach/korean-air-discloses-data-breach-after-the-hack-of-its-catering-and-duty-free-supplier.html
Security Affairs
Korean Air discloses data breach after the hack of its catering and duty-free supplier
Korean Air employee discloses a data breach after a hack of its catering and duty-free supplier, KC&D, affecting thousands of staff.
Happy 16th Birthday, KrebsOnSecurity.com!
https://krebsonsecurity.com/2025/12/happy-16th-birthday-krebsonsecurity-com/
https://krebsonsecurity.com/2025/12/happy-16th-birthday-krebsonsecurity-com/
Krebs on Security
Happy 16th Birthday, KrebsOnSecurity.com!
KrebsOnSecurity.com celebrates its 16th anniversary today! A huge "thank you" to all of our readers -- newcomers, long-timers and drive-by critics alike. Your engagement this past year here has been tremendous and truly a salve on a handful of dark…
Coupang Breach Suspect Tried to Hide Evidence by Throwing Laptop in River
https://thecyberexpress.com/coupang-breach-suspect-threw-laptop-in-river/
https://thecyberexpress.com/coupang-breach-suspect-threw-laptop-in-river/
The Cyber Express
Coupang Breach Suspect Threw Laptop In River To Cover Tracks
A former employee behind the recent Coupang breach tried to cover his tracks by smashing his MacBook Air and throwing it into a river, the company said.
MongoBleed defect swirls, stamping out hope of year-end respite
https://cyberscoop.com/mongobleed-vulnerability-mongodb-exploitation/
https://cyberscoop.com/mongobleed-vulnerability-mongodb-exploitation/
CyberScoop
MongoBleed defect swirls, stamping out hope of year-end respite
The high-severity vulnerability is under active exploitation and affects many versions of MongoDB, a nearly ubiquitous open-source database.
AI doesn’t care if it’s in California or Texas. It just runs.
https://cyberscoop.com/ai-regulation-unified-federal-standards-needed-op-ed/
https://cyberscoop.com/ai-regulation-unified-federal-standards-needed-op-ed/
CyberScoop
AI doesn’t care if it’s in California or Texas. It just runs.
The accelerated expansion of state-level regulation highlights a growing urgency. Policy and security leaders are navigating a fast-paced regulatory landscape without a clear, unified direction.
The £1.5bn Showdown: Apple Appeals Landmark Ruling Over “Unfair” App Store Fees
https://securityonline.info/the-1-5bn-showdown-apple-appeals-landmark-ruling-over-unfair-app-store-fees/
https://securityonline.info/the-1-5bn-showdown-apple-appeals-landmark-ruling-over-unfair-app-store-fees/
Daily CyberSecurity
The £1.5bn Showdown: Apple Appeals Landmark Ruling Over "Unfair" App Store Fees
Apple appeals a £1.5bn UK ruling that labeled its 30% App Store fee "unfair." Over 19 million users could receive payouts if the $2bn fine is upheld.
Beyond SOS: Samsung’s Exynos 5410 Brings 5G Video Calls to the Middle of Nowhere
https://securityonline.info/beyond-sos-samsungs-exynos-5410-brings-5g-video-calls-to-the-middle-of-nowhere/
https://securityonline.info/beyond-sos-samsungs-exynos-5410-brings-5g-video-calls-to-the-middle-of-nowhere/
Daily CyberSecurity
Beyond SOS: Samsung’s Exynos 5410 Brings 5G Video Calls to the Middle of Nowhere
Samsung’s Exynos 5410 modem enables 5G satellite video calls for the Galaxy S26, shifting mobile tech from emergency texts to global broadband connectivity.
The Arms Dealer Returns: Why NVIDIA is Retreating from the Cloud War
https://securityonline.info/the-arms-dealer-returns-why-nvidia-is-retreating-from-the-cloud-war/
https://securityonline.info/the-arms-dealer-returns-why-nvidia-is-retreating-from-the-cloud-war/
Daily CyberSecurity
The Arms Dealer Returns: Why NVIDIA is Retreating from the Cloud War
NVIDIA folds DGX Cloud into its engineering arm to focus on internal R&D. Is the AI "arms dealer" quitting the cloud war to protect its chip monopoly?
The $339 Trillion Glitch: Ubisoft Loses Control of Rainbow Six Siege in Massive Breach
https://securityonline.info/the-339-trillion-glitch-ubisoft-loses-control-of-rainbow-six-siege-in-massive-breach/
https://securityonline.info/the-339-trillion-glitch-ubisoft-loses-control-of-rainbow-six-siege-in-massive-breach/
Daily CyberSecurity
The $339 Trillion Glitch: Ubisoft Loses Control of Rainbow Six Siege in Massive Breach
Ubisoft takes Rainbow Six Siege offline after a massive backend breach. Hackers gifted 2 billion credits to players and hijacked the game's ban system.
CVE-2025-13915: Critical 9.8 Flaw in IBM API Connect Lets Attackers Bypass Login
https://securityonline.info/cve-2025-13915-critical-9-8-flaw-in-ibm-api-connect-lets-attackers-bypass-login/
https://securityonline.info/cve-2025-13915-critical-9-8-flaw-in-ibm-api-connect-lets-attackers-bypass-login/
Daily CyberSecurity
CVE-2025-13915: Critical 9.8 Flaw in IBM API Connect Lets Attackers Bypass Login
IBM issues a 9.8 critical alert for API Connect! CVE-2025-13915 allows unauthenticated remote access. Update to v10.0.11 or apply iFixes now.
CVE-2025-52691 (CVSS 10): Critical SmarterMail Flaw Opens Servers to Unauthenticated Attacks
https://securityonline.info/cve-2025-52691-cvss-10-critical-smartermail-flaw-opens-servers-to-unauthenticated-attacks/
https://securityonline.info/cve-2025-52691-cvss-10-critical-smartermail-flaw-opens-servers-to-unauthenticated-attacks/
Daily CyberSecurity
CVE-2025-52691 (CVSS 10): Critical SmarterMail Flaw Opens Servers to Unauthenticated Attacks
SmarterMail hits a 10/10 CVSS severity! CVE-2025-52691 allows unauthenticated RCE via arbitrary file uploads. Update to Build 9413 immediately!
CISA Alert: MongoBleed Added to KEV Catalog as 80,000+ Servers Face Active Exploitation
https://securityonline.info/cisa-alert-mongobleed-added-to-kev-catalog-as-80000-servers-face-active-exploitation/
https://securityonline.info/cisa-alert-mongobleed-added-to-kev-catalog-as-80000-servers-face-active-exploitation/
Daily CyberSecurity
CISA Alert: MongoBleed Added to KEV Catalog as 80,000+ Servers Face Active Exploitation
CISA adds MongoBleed (CVE-2025-14847) to its KEV Catalog after confirming active exploitation. 80,000+ MongoDB servers are at risk. Patch by Jan 19!