Coupang Breach Suspect Tried to Hide Evidence by Throwing Laptop in River
https://thecyberexpress.com/coupang-breach-suspect-threw-laptop-in-river/
https://thecyberexpress.com/coupang-breach-suspect-threw-laptop-in-river/
The Cyber Express
Coupang Breach Suspect Threw Laptop In River To Cover Tracks
A former employee behind the recent Coupang breach tried to cover his tracks by smashing his MacBook Air and throwing it into a river, the company said.
MongoBleed defect swirls, stamping out hope of year-end respite
https://cyberscoop.com/mongobleed-vulnerability-mongodb-exploitation/
https://cyberscoop.com/mongobleed-vulnerability-mongodb-exploitation/
CyberScoop
MongoBleed defect swirls, stamping out hope of year-end respite
The high-severity vulnerability is under active exploitation and affects many versions of MongoDB, a nearly ubiquitous open-source database.
AI doesn’t care if it’s in California or Texas. It just runs.
https://cyberscoop.com/ai-regulation-unified-federal-standards-needed-op-ed/
https://cyberscoop.com/ai-regulation-unified-federal-standards-needed-op-ed/
CyberScoop
AI doesn’t care if it’s in California or Texas. It just runs.
The accelerated expansion of state-level regulation highlights a growing urgency. Policy and security leaders are navigating a fast-paced regulatory landscape without a clear, unified direction.
The £1.5bn Showdown: Apple Appeals Landmark Ruling Over “Unfair” App Store Fees
https://securityonline.info/the-1-5bn-showdown-apple-appeals-landmark-ruling-over-unfair-app-store-fees/
https://securityonline.info/the-1-5bn-showdown-apple-appeals-landmark-ruling-over-unfair-app-store-fees/
Daily CyberSecurity
The £1.5bn Showdown: Apple Appeals Landmark Ruling Over "Unfair" App Store Fees
Apple appeals a £1.5bn UK ruling that labeled its 30% App Store fee "unfair." Over 19 million users could receive payouts if the $2bn fine is upheld.
Beyond SOS: Samsung’s Exynos 5410 Brings 5G Video Calls to the Middle of Nowhere
https://securityonline.info/beyond-sos-samsungs-exynos-5410-brings-5g-video-calls-to-the-middle-of-nowhere/
https://securityonline.info/beyond-sos-samsungs-exynos-5410-brings-5g-video-calls-to-the-middle-of-nowhere/
Daily CyberSecurity
Beyond SOS: Samsung’s Exynos 5410 Brings 5G Video Calls to the Middle of Nowhere
Samsung’s Exynos 5410 modem enables 5G satellite video calls for the Galaxy S26, shifting mobile tech from emergency texts to global broadband connectivity.
The Arms Dealer Returns: Why NVIDIA is Retreating from the Cloud War
https://securityonline.info/the-arms-dealer-returns-why-nvidia-is-retreating-from-the-cloud-war/
https://securityonline.info/the-arms-dealer-returns-why-nvidia-is-retreating-from-the-cloud-war/
Daily CyberSecurity
The Arms Dealer Returns: Why NVIDIA is Retreating from the Cloud War
NVIDIA folds DGX Cloud into its engineering arm to focus on internal R&D. Is the AI "arms dealer" quitting the cloud war to protect its chip monopoly?
The $339 Trillion Glitch: Ubisoft Loses Control of Rainbow Six Siege in Massive Breach
https://securityonline.info/the-339-trillion-glitch-ubisoft-loses-control-of-rainbow-six-siege-in-massive-breach/
https://securityonline.info/the-339-trillion-glitch-ubisoft-loses-control-of-rainbow-six-siege-in-massive-breach/
Daily CyberSecurity
The $339 Trillion Glitch: Ubisoft Loses Control of Rainbow Six Siege in Massive Breach
Ubisoft takes Rainbow Six Siege offline after a massive backend breach. Hackers gifted 2 billion credits to players and hijacked the game's ban system.
CVE-2025-13915: Critical 9.8 Flaw in IBM API Connect Lets Attackers Bypass Login
https://securityonline.info/cve-2025-13915-critical-9-8-flaw-in-ibm-api-connect-lets-attackers-bypass-login/
https://securityonline.info/cve-2025-13915-critical-9-8-flaw-in-ibm-api-connect-lets-attackers-bypass-login/
Daily CyberSecurity
CVE-2025-13915: Critical 9.8 Flaw in IBM API Connect Lets Attackers Bypass Login
IBM issues a 9.8 critical alert for API Connect! CVE-2025-13915 allows unauthenticated remote access. Update to v10.0.11 or apply iFixes now.
CVE-2025-52691 (CVSS 10): Critical SmarterMail Flaw Opens Servers to Unauthenticated Attacks
https://securityonline.info/cve-2025-52691-cvss-10-critical-smartermail-flaw-opens-servers-to-unauthenticated-attacks/
https://securityonline.info/cve-2025-52691-cvss-10-critical-smartermail-flaw-opens-servers-to-unauthenticated-attacks/
Daily CyberSecurity
CVE-2025-52691 (CVSS 10): Critical SmarterMail Flaw Opens Servers to Unauthenticated Attacks
SmarterMail hits a 10/10 CVSS severity! CVE-2025-52691 allows unauthenticated RCE via arbitrary file uploads. Update to Build 9413 immediately!
CISA Alert: MongoBleed Added to KEV Catalog as 80,000+ Servers Face Active Exploitation
https://securityonline.info/cisa-alert-mongobleed-added-to-kev-catalog-as-80000-servers-face-active-exploitation/
https://securityonline.info/cisa-alert-mongobleed-added-to-kev-catalog-as-80000-servers-face-active-exploitation/
Daily CyberSecurity
CISA Alert: MongoBleed Added to KEV Catalog as 80,000+ Servers Face Active Exploitation
CISA adds MongoBleed (CVE-2025-14847) to its KEV Catalog after confirming active exploitation. 80,000+ MongoDB servers are at risk. Patch by Jan 19!
The Year Linux Went “Rusty”: 2025’s Most Audacious Kernel Breakthroughs
https://securityonline.info/the-year-linux-went-rusty-2025s-most-audacious-kernel-breakthroughs/
https://securityonline.info/the-year-linux-went-rusty-2025s-most-audacious-kernel-breakthroughs/
Daily CyberSecurity
The Year Linux Went "Rusty": 2025's Most Audacious Kernel Breakthroughs
From Meta adopting the Steam Deck scheduler to the first Rust CVE, 2025 was the year Linux matured, clashed, and conquered. Read the full year-end wrap.
The Memory Rebellion: SoftBank & Intel’s SAIMEMORY Aims to Topple HBM Dominance
https://securityonline.info/the-memory-rebellion-softbank-intels-saimemory-aims-to-topple-hbm-dominance/
https://securityonline.info/the-memory-rebellion-softbank-intels-saimemory-aims-to-topple-hbm-dominance/
Daily CyberSecurity
The Memory Rebellion: SoftBank & Intel’s SAIMEMORY Aims to Topple HBM Dominance
SAIMEMORY, backed by SoftBank, Intel, and now Fujitsu, is developing a low-power HBM successor to end the AI memory shortage and challenge Korean dominance.
The Big Screen Remembers: Samsung & Google Bring Vision AI to Your Photos
https://securityonline.info/the-big-screen-remembers-samsung-google-bring-vision-ai-to-your-photos/
https://securityonline.info/the-big-screen-remembers-samsung-google-bring-vision-ai-to-your-photos/
Daily CyberSecurity
The Big Screen Remembers: Samsung & Google Bring Vision AI to Your Photos
Samsung's 2026 TVs will natively integrate Google Photos and Vision AI, bringing exclusive Memories, AI editing, and video generation to the big screen.
Romania’s Oltenia Energy Complex suffers major ransomware attack
https://securityaffairs.com/186290/cyber-crime/romanias-oltenia-energy-complex-suffers-major-ransomware-attack.html
https://securityaffairs.com/186290/cyber-crime/romanias-oltenia-energy-complex-suffers-major-ransomware-attack.html
Security Affairs
Romania’s Oltenia Energy Complex suffers major ransomware attack
A ransomware attack hit Romania’s Oltenia Energy Complex on December 26, knocking out IT systems at the country’s largest coal power producer
Bugs that survive the heat of continuous fuzzing
https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/
https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/
The GitHub Blog
Bugs that survive the heat of continuous fuzzing
Learn why some long-enrolled OSS-Fuzz projects still contain vulnerabilities and how you can find them.
CNIL Fines NEXPUBLICA FRANCE €1.7 Million for GDPR Security Failures
https://thecyberexpress.com/gdpr-fine-on-nexpublica-france/
https://thecyberexpress.com/gdpr-fine-on-nexpublica-france/
The Cyber Express
CNIL Slaps €1.7M GDPR Fine On NEXPUBLICA FRANCE
The GDPR fine reflects the sensitivity of the data exposed and the potential harm caused to affected individuals.
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/186297/hacking/u-s-cisa-adds-a-flaw-in-mongodb-server-to-its-known-exploited-vulnerabilities-catalog.html
https://securityaffairs.com/186297/hacking/u-s-cisa-adds-a-flaw-in-mongodb-server-to-its-known-exploited-vulnerabilities-catalog.html
Security Affairs
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a MongoDB Server flaw to its Known Exploited Vulnerabilities catalog.
Lithuanian suspect arrested over KMSAuto malware that infected 2.8M systems
https://securityaffairs.com/186308/malware/lithuanian-suspect-arrested-over-kmsauto-malware-that-infected-2-8m-systems.html
https://securityaffairs.com/186308/malware/lithuanian-suspect-arrested-over-kmsauto-malware-that-infected-2-8m-systems.html
Security Affairs
Lithuanian suspect arrested over KMSAuto malware that infected 2.8M systems
A Lithuanian national was arrested for allegedly spreading KMSAuto malware that stole clipboard data and infected 2.8 million systems
Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver
https://securityaffairs.com/186318/security/mustang-panda-deploys-toneshell-via-signed-kernel-mode-rootkit-driver.html
https://securityaffairs.com/186318/security/mustang-panda-deploys-toneshell-via-signed-kernel-mode-rootkit-driver.html
Security Affairs
Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver
China-linked APT Mustang Panda used a signed kernel-mode rootkit driver to load shellcode and deploy its ToneShell backdoor.
OpenAI says prompt injection may never be ‘solved’ for browser agents like Atlas
https://cyberscoop.com/openai-chatgpt-atlas-prompt-injection-browser-agent-security-update-head-of-preparedness/
https://cyberscoop.com/openai-chatgpt-atlas-prompt-injection-browser-agent-security-update-head-of-preparedness/
CyberScoop
OpenAI says prompt injection may never be ‘solved’ for browser agents like Atlas
OpenAI says prompt injection attacks can hijack browser-based AI agents like ChatGPT Atlas, prompting a security update after internal testing found new multi-step exploits.
❤1
Latest Oracle EBS Victims Include Korean Air, University of Phoenix
https://thecyberexpress.com/oracle-ebs-victims-university-of-phoenix/
https://thecyberexpress.com/oracle-ebs-victims-university-of-phoenix/
The Cyber Express
Oracle EBS Victims Include Korean Air, University Of Phoenix
The CL0P ransomware group’s Oracle EBS victims continue to grow, with Korean Air and the University of Phoenix the latest to reveal data breach details.