The Big Screen Remembers: Samsung & Google Bring Vision AI to Your Photos
https://securityonline.info/the-big-screen-remembers-samsung-google-bring-vision-ai-to-your-photos/
https://securityonline.info/the-big-screen-remembers-samsung-google-bring-vision-ai-to-your-photos/
Daily CyberSecurity
The Big Screen Remembers: Samsung & Google Bring Vision AI to Your Photos
Samsung's 2026 TVs will natively integrate Google Photos and Vision AI, bringing exclusive Memories, AI editing, and video generation to the big screen.
Romania’s Oltenia Energy Complex suffers major ransomware attack
https://securityaffairs.com/186290/cyber-crime/romanias-oltenia-energy-complex-suffers-major-ransomware-attack.html
https://securityaffairs.com/186290/cyber-crime/romanias-oltenia-energy-complex-suffers-major-ransomware-attack.html
Security Affairs
Romania’s Oltenia Energy Complex suffers major ransomware attack
A ransomware attack hit Romania’s Oltenia Energy Complex on December 26, knocking out IT systems at the country’s largest coal power producer
Bugs that survive the heat of continuous fuzzing
https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/
https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/
The GitHub Blog
Bugs that survive the heat of continuous fuzzing
Learn why some long-enrolled OSS-Fuzz projects still contain vulnerabilities and how you can find them.
CNIL Fines NEXPUBLICA FRANCE €1.7 Million for GDPR Security Failures
https://thecyberexpress.com/gdpr-fine-on-nexpublica-france/
https://thecyberexpress.com/gdpr-fine-on-nexpublica-france/
The Cyber Express
CNIL Slaps €1.7M GDPR Fine On NEXPUBLICA FRANCE
The GDPR fine reflects the sensitivity of the data exposed and the potential harm caused to affected individuals.
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/186297/hacking/u-s-cisa-adds-a-flaw-in-mongodb-server-to-its-known-exploited-vulnerabilities-catalog.html
https://securityaffairs.com/186297/hacking/u-s-cisa-adds-a-flaw-in-mongodb-server-to-its-known-exploited-vulnerabilities-catalog.html
Security Affairs
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a MongoDB Server flaw to its Known Exploited Vulnerabilities catalog.
Lithuanian suspect arrested over KMSAuto malware that infected 2.8M systems
https://securityaffairs.com/186308/malware/lithuanian-suspect-arrested-over-kmsauto-malware-that-infected-2-8m-systems.html
https://securityaffairs.com/186308/malware/lithuanian-suspect-arrested-over-kmsauto-malware-that-infected-2-8m-systems.html
Security Affairs
Lithuanian suspect arrested over KMSAuto malware that infected 2.8M systems
A Lithuanian national was arrested for allegedly spreading KMSAuto malware that stole clipboard data and infected 2.8 million systems
Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver
https://securityaffairs.com/186318/security/mustang-panda-deploys-toneshell-via-signed-kernel-mode-rootkit-driver.html
https://securityaffairs.com/186318/security/mustang-panda-deploys-toneshell-via-signed-kernel-mode-rootkit-driver.html
Security Affairs
Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver
China-linked APT Mustang Panda used a signed kernel-mode rootkit driver to load shellcode and deploy its ToneShell backdoor.
OpenAI says prompt injection may never be ‘solved’ for browser agents like Atlas
https://cyberscoop.com/openai-chatgpt-atlas-prompt-injection-browser-agent-security-update-head-of-preparedness/
https://cyberscoop.com/openai-chatgpt-atlas-prompt-injection-browser-agent-security-update-head-of-preparedness/
CyberScoop
OpenAI says prompt injection may never be ‘solved’ for browser agents like Atlas
OpenAI says prompt injection attacks can hijack browser-based AI agents like ChatGPT Atlas, prompting a security update after internal testing found new multi-step exploits.
❤1
Latest Oracle EBS Victims Include Korean Air, University of Phoenix
https://thecyberexpress.com/oracle-ebs-victims-university-of-phoenix/
https://thecyberexpress.com/oracle-ebs-victims-university-of-phoenix/
The Cyber Express
Oracle EBS Victims Include Korean Air, University Of Phoenix
The CL0P ransomware group’s Oracle EBS victims continue to grow, with Korean Air and the University of Phoenix the latest to reveal data breach details.
Two Security Experts Plead Guilty in BlackCat Ransomware Case
https://thecyberexpress.com/security-experts-blackcat-ransomware-case/
https://thecyberexpress.com/security-experts-blackcat-ransomware-case/
The Cyber Express
2 Security Experts Plead Guilty In BlackCat Ransomware Case
Two cybersecurity experts charged with deploying ransomware against five companies have pleaded guilty in the BlackCat ransomware case.
The Mole in the Machine: New Arrests in Coinbase’s $400M Insider Data Scandal
https://securityonline.info/the-mole-in-the-machine-new-arrests-in-coinbases-400m-insider-data-scandal/
https://securityonline.info/the-mole-in-the-machine-new-arrests-in-coinbases-400m-insider-data-scandal/
Daily CyberSecurity
The Mole in the Machine: New Arrests in Coinbase’s $400M Insider Data Scandal
Hyderabad police arrest another ex-Coinbase agent for selling user data. The TaskUs insider breach exposed 70k users and cost Coinbase up to $400 million.
The Insider Crisis: How Bribed Outsourced Staff Sold Out Ubisoft’s Crown Jewels
https://securityonline.info/the-insider-crisis-how-bribed-outsourced-staff-sold-out-ubisofts-crown-jewels/
https://securityonline.info/the-insider-crisis-how-bribed-outsourced-staff-sold-out-ubisofts-crown-jewels/
Daily CyberSecurity
The Insider Crisis: How Bribed Outsourced Staff Sold Out Ubisoft’s Crown Jewels
Hackers bribed Ubisoft outsourced staff for backend access, leading to a $339T currency exploit and a massive source code leak. Is outsourcing to blame?
Bixby’s Revenge: Samsung Pairs with Perplexity AI to Outsmart Google Gemini
https://securityonline.info/bixbys-revenge-samsung-pairs-with-perplexity-ai-to-outsmart-google-gemini/
https://securityonline.info/bixbys-revenge-samsung-pairs-with-perplexity-ai-to-outsmart-google-gemini/
Daily CyberSecurity
Bixby’s Revenge: Samsung Pairs with Perplexity AI to Outsmart Google Gemini
Bixby is back: Samsung’s One UI 8.5 beta reveals a deep Perplexity AI integration, bringing context-aware reasoning to the Galaxy S26 and beyond.
The $2 Billion Bet: Why Meta Just Bought the World’s Fastest-Growing AI Startup
https://securityonline.info/the-2-billion-bet-why-meta-just-bought-the-worlds-fastest-growing-ai-startup/
https://securityonline.info/the-2-billion-bet-why-meta-just-bought-the-worlds-fastest-growing-ai-startup/
Daily CyberSecurity
The $2 Billion Bet: Why Meta Just Bought the World’s Fastest-Growing AI Startup
Meta acquires Manus, the AI agent startup that hit $100M in revenue in 8 months. Zuckerberg is moving from chatbots to autonomous "digital employees."
❤1
Cybersecurity Pros Admit to Moonlighting as BlackCat Ransomware Affiliates
https://securityonline.info/cybersecurity-pros-admit-to-moonlighting-as-blackcat-ransomware-affiliates/
https://securityonline.info/cybersecurity-pros-admit-to-moonlighting-as-blackcat-ransomware-affiliates/
Daily CyberSecurity
Cybersecurity Pros Admit to Moonlighting as BlackCat Ransomware Affiliates
Two US cybersecurity pros, Ryan Goldberg and Kevin Martin, plead guilty to moonlighting as ALPHV/BlackCat affiliates, extorting $1.2M from victims.
“RondoDoX” Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT
https://securityonline.info/rondodox-strikes-back-exposed-logs-reveal-massive-9-month-campaign-targeting-next-js-and-iot/
https://securityonline.info/rondodox-strikes-back-exposed-logs-reveal-massive-9-month-campaign-targeting-next-js-and-iot/
Daily CyberSecurity
"RondoDoX" Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT
CloudSEK uncovers the RondoDoX botnet's expansion into enterprise Next.js apps via the React2Shell exploit, alongside global IoT compromises.
CVE-2025-47411: Critical Apache StreamPipes Flaw Allows Standard Users to Seize Admin Control
https://securityonline.info/cve-2025-47411-critical-apache-streampipes-flaw-allows-standard-users-to-seize-admin-control/
https://securityonline.info/cve-2025-47411-critical-apache-streampipes-flaw-allows-standard-users-to-seize-admin-control/
Daily CyberSecurity
CVE-2025-47411: Critical Apache StreamPipes Flaw Allows Standard Users to Seize Admin Control
Apache StreamPipes patches CVE-2025-47411, a logic flaw allowing users to manipulate JWT tokens and hijack admin accounts. Update to v0.98.0 now!
Coupang announces $1.17B compensation plan for 33.7M data breach victims
https://securityaffairs.com/186331/security/coupang-announces-1-17b-compensation-plan-for-33-7m-data-breach-victims.html
https://securityaffairs.com/186331/security/coupang-announces-1-17b-compensation-plan-for-33-7m-data-breach-victims.html
Security Affairs
Coupang announces $1.17B compensation plan for 33.7M data breach victims
Coupang will spend about $1.17B to compensate 33.7 million users affected by a data breach, providing purchase vouchers to those impacted.
Singapore CSA Warns of Critical SmarterMail Flaw Enabling Unauthenticated Remote Code Execution
https://thecyberexpress.com/csa-alert-cve-2025-52691/
https://thecyberexpress.com/csa-alert-cve-2025-52691/
The Cyber Express
CSA Warns Of CVE-2025-52691 SmarterMail RCE Flaw
Singapore’s CSA warns of CVE-2025-52691, a critical SmarterMail vulnerability that enables unauthenticated remote code execution.
Poland Calls for EU Investigation of TikTok Over AI-Generated Disinformation Campaign
https://thecyberexpress.com/tiktok-ai-generated-disinformation/
https://thecyberexpress.com/tiktok-ai-generated-disinformation/
The Cyber Express
Poland Calls For EU Investigation Of TikTok Over AI-Generated Disinformation Campaign
Poland submitted a formal request to the European Commission demanding investigation of TikTok for allegedly failing to moderate a large-scale disinformation campaign.
The Christmas Heist: How Shai-Hulud Hijacked Trust Wallet for an $8.5M Score
https://securityonline.info/the-christmas-heist-how-shai-hulud-hijacked-trust-wallet-for-an-8-5m-score/
https://securityonline.info/the-christmas-heist-how-shai-hulud-hijacked-trust-wallet-for-an-8-5m-score/
Daily CyberSecurity
The Christmas Heist: How Shai-Hulud Hijacked Trust Wallet for an $8.5M Score
Trust Wallet hit by an $8.5M heist after Shai-Hulud hackers poisoned the NPM supply chain. Binance is fully compensating affected version 2.68 users.