ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10573
Stored Cross-Site Scripting in Ivanti Endpoint Manager Exposes Admin Sessions

CVE-2025-10573 is a stored cross-site scripting (CWE-79) flaw in Ivanti Endpoint Manager versions prior to 2024 SU4 SR1. A remote, unauthenticated attacker can plant malicious script content in the product, and when an administrator interacts with the affected view (user interaction is required), arbitrary JavaScript executes in the context of the administrator's browser session. An attacker who succeeds can act as an EPM administrator, potentially viewing or modifying administrative data, which the scope-changed CVSS 3.1 score of 6.1 reflects via low confidentiality and integrity impact. Organizations running Ivanti EPM on-premises, typically to manage large fleets of corporate endpoints, are affected. As of now there is no known public proof-of-concept and the flaw is not in CISA KEV, but EPSS assigns a 33.5% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

Do: Upgrade Ivanti Endpoint Manager to 2024 SU4 SR1 or later as soon as possible, and apply the latest Ivanti patch rollups, since related advisories indicate Ivanti shipped fixes for multiple EPM issues in the same cycle. Until patched, restrict network access to the EPM core server and administrative console, and have administrators avoid engaging with unexpected or untrusted content in the console. After patching, review EPM administrator accounts and recent session activity for signs of unauthorized administrative actions.

6.133%
  • Ivanti Endpoint Manager prior to 2024 SU4 SR1
largetens of thousands of EPM core deployments worldwide (widely deployed enterprise endpoint-management platform)
CVE-2025-11838
+3 in the same advisory: …12195 …12196 …12026
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile U

A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

NVD description · AI analysis pending
8.7
group max
<1%
  • watchguard fireware
CVE-2025-12716
+3 in the same advisory: …12029 …8405 …12562
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain co

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

NVD description · AI analysis pending
8.7
group max
<1%
  • gitlab gitlab
CVE-2025-13184
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.

NVD description · AI analysis pending
9.811% PoC
  • totolink x5000r firmware
CVE-2025-13390
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

NVD description · AI analysis pending
9.85% PoC ×2
  • wpdirectorykit wp directory kit
CVE-2025-13607
A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

NVD description · AI analysis pending
9.3<1%
CVE-2025-14174
Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera

Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet.

Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations.

8.822% KEV
  • Google Chromium (ANGLE component)
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users)
CVE-2025-24857
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322,

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

NVD description · AI analysis pending
7.6<1%
  • denx u-boot
CVE-2025-27020
+1 in the same advisory: …27019
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system .

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.

NVD description · AI analysis pending
9.8<1%
  • nokia infinera mtc-9 firmware
CVE-2025-42880
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module.

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

NVD description · AI analysis pending
9.95%
CVE-2025-42928
Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution.

Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The system may be vulnerable when specially crafted input is used to exploit the vulnerability resulting in high impact on confidentiality, integrity and availability of the system.

NVD description · AI analysis pending
9.110%
CVE-2025-43529
Use-After-Free in Apple WebKit (Safari, iOS, macOS) Allows Arbitrary Code Execution

CVE-2025-43529 is a use-after-free (CWE-416) flaw in Apple's WebKit browser engine, fixed via improved memory management. It is triggered when a device processes maliciously crafted web content, and successful exploitation can lead to arbitrary code execution with network reachability and no privileges required (CVSS 3.1: 8.8, user interaction needed). It affects a broad range of Apple products: Safari, iPhone OS/iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, with fixes delivered in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Apple reports the issue was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-15 (a companion CVE-2025-14174 was issued for the same report). No public proof-of-concept is known, and EPSS assigns an 8.9% probability of exploitation within 30 days (95th percentile).

Do: Update affected devices to Safari 26.2, iOS/iPadOS 26.2 (or iOS/iPadOS 18.7.3 on devices that remain on the iOS 18 branch), macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2, prioritizing mobile users and high-risk targeted individuals. Federal agencies must remediate per CISA BOD 22-01 requirements since the CVE is in the KEV catalog (added 2025-12-15); also review the related CVE-2025-14174 addressed by the same updates. Check device fleet inventory for WebKit-exposed Apple hardware that cannot reach the fixed versions and confirm patches have been applied.

8.89% KEV
  • Apple Safari All versions prior to Safari 26.2
  • Apple iPhone OS (iOS) Versions prior to iOS 26.2 (legacy branch fixed in iOS 18.7.3)
  • Apple iPadOS Versions prior to iPadOS 26.2 (legacy branch fixed in iPadOS 18.7.3)
  • +4 more
masswell over 1 billion Apple devices/users across iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro running pre-26.2 (or pre-18.7.3 legacy) software
CVE-2025-55182
Unauthenticated RCE in React Server Components (React2Shell)

CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution flaw (CWE-502, deserialization of untrusted data) in React Server Components, specifically the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. It is triggered when the vulnerable code unsafely deserializes payloads from HTTP requests sent to Server Function endpoints, requiring no authentication or user interaction. An attacker gains arbitrary code execution on the affected server (CVSS scope changed, with high impact to confidentiality, integrity, and availability), and reporting notes a campaign in which hackers used the flaw to breach 766 Next.js hosts and steal credentials. Any React/Next.js application exposing Server Functions with the affected React versions is in scope, which given the ubiquity of React and Next.js is a very large deployed base. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-05 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.8%, multiple public PoC/scanner repositories are available, and coverage has dubbed the flaw React2Shell.

Do: Upgrade the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages to the vendor-patched releases (any version later than the vulnerable 19.0.0, 19.1.0, 19.1.1, and 19.2.0 line) and update Next.js per Vercel's advisory; as a KEV entry, U.S. federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Audit internet-exposed Server Function endpoints for the vulnerable React versions and review logs for exploitation activity, including the reported campaign that breached 766 Next.js hosts and stole credentials, then rotate any exposed credentials.

10.0100% KEV ransomware PoC ×7
  • Meta (Facebook) React Server Components (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • Vercel Next.js (deployments using React Server Components/Server Functions via the affected react-server-dom-* packages) Applications bundling the affected React versions (19.0.0, 19.1.0, 19.1.1, 19.2.0); Next.js-specific fixed version numbers were not provided in the data
mass≈1M+ internet-facing Next.js/React Server Components deployments (order-of-magnitude estimate)
CVE-2025-55183
Unauthenticated source code exposure in React Server Components 19.x (incl. Next.js)

CVE-2025-55183 is an information-disclosure flaw in specific configurations of React Server Components in versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, affecting the packages react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack. A specially crafted HTTP request sent to a vulnerable Server Function can cause it to unsafely return the source code of any Server Function, but only when the application has a Server Function that explicitly or implicitly exposes a stringified argument. An attacker gains unauthenticated read access to server-side application source code (CVSS 5.3, network-exploitable with no privileges or user interaction, confidentiality-only impact), which is valuable reconnaissance that can enable follow-on attacks alongside the related React RSC denial-of-service flaws. Affected are any applications running the listed React 19.x RSC packages, most prominently Next.js deployments that use React Server Components and Server Functions. A vendor advisory with public exploit guidance was published on December 11, 2025, reporting of 'React2Shell' fallout indicates public exploits are circulating, and EPSS assigns a 64.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV.

Do: Upgrade react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel to patched releases newer than the affected 19.0.0-19.2.1 versions, and update Next.js's bundled React accordingly, following the React team's December 11, 2025 advisory. Audit your application for Server Functions that explicitly or implicitly expose stringified arguments, since exploitation requires such a function to exist. Until patched, restrict and monitor external access to Server Function endpoints; no CISA KEV deadline applies yet.

5.364% PoC
  • facebook react (react-server-dom-webpack) 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, 19.2.1 (specific vulnerable configurations)
  • facebook react (react-server-dom-turbopack) 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, 19.2.1 (specific vulnerable configurations)
  • facebook react (react-server-dom-parcel) 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, 19.2.1 (specific vulnerable configurations)
  • +1 more
massplausibly on the order of 100,000-1,000,000 sites and applications (vulnerable subset of the multi-million-site Next.js/React 19 RSC install base)
CVE-2025-55184
Unauthenticated Denial-of-Service in React Server Components 19.x and Next.js

CVE-2025-55184 is a pre-authentication denial-of-service flaw in the deserialization logic of the React Server Components packages react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack in versions 19.0.0 through 19.2.1. An attacker triggers it by sending a crafted, unauthenticated HTTP request to any Server Function endpoint, where unsafe deserialization of the payload causes an infinite loop that hangs the server process. Successful attacks cause high availability impact: the affected process stops responding and subsequent HTTP requests are no longer served until the process is restarted, with no expected confidentiality or integrity loss. Any application using React 19 Server Components is affected, including Next.js deployments whose Server Functions rely on these packages. No public proof-of-concept or confirmed in-the-wild exploitation is known for this specific flaw, but the very high EPSS score (66.9% within 30 days, 99th percentile) and ongoing exploitation of related React RSC flaws (React2Shell) indicate elevated risk.

Do: Inventory all applications using React 19 Server Components (react-server-dom-webpack, -turbopack, -parcel), including Next.js builds that bundle them, and upgrade to a React 19.x release newer than 19.2.1 with the patched packages as soon as available. As an interim mitigation, restrict and rate-limit access to Server Function endpoints and monitor or auto-restart server processes that hang under crafted requests. Prioritize patching given that related React RSC vulnerabilities are already being exploited in the wild.

7.567%
  • facebook React Server Components (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, 19.2.1
  • vercel Next.js (applications using Server Functions backed by the affected React RSC packages)
masslikely hundreds of thousands to millions of Next.js/React RSC deployments, of which an unknown share exposes Server Function endpoints to the internet
CVE-2025-55754
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

NVD description · AI analysis pending
9.610%
  • apache tomcat
CVE-2025-58083
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the devi

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

NVD description · AI analysis pending
9.2<1%
CVE-2025-59718
Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy

CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days.

Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01.

9.868% KEV
  • Fortinet FortiOS 7.0.0-7.0.17, 7.2.0-7.2.11, 7.4.0-7.4.8, 7.6.0-7.6.3
  • Fortinet FortiProxy 7.0.0-7.0.21, 7.2.0-7.2.14, 7.4.0-7.4.10, 7.6.0-7.6.3
  • Fortinet FortiSwitchManager 7.0.0-7.0.5, 7.2.0-7.2.6
  • +1 more
masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the…
CVE-2025-59719
Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO)

FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible.

Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent.

9.829%
  • fortinet fortiweb 8.0.0
  • fortinet fortiweb 7.6.0 through 7.6.4
  • fortinet fortiweb 7.4.0 through 7.4.9
largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud…
CVE-2025-6218
Directory Traversal RCE in RARLAB WinRAR

RARLAB WinRAR contains a directory traversal flaw (CWE-22) in its handling of file paths within archive files, allowing a crafted archive path to traverse to unintended directories during extraction. Exploitation requires user interaction: the target must open a malicious file (e.g., a booby-trapped archive) or visit a malicious page. A successful attacker executes arbitrary code in the context of the current user, yielding full high-impact code execution on the endpoint (CVSS 3.0: 7.8, local attack vector with required user interaction). Any installation running an affected version of RARLAB WinRAR is exposed; the specific affected version range is not stated in the source data, so defenders should confirm against RARLAB's advisory. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-09, Google warned of active exploitation, public reporting ties the campaign to APT-C-08 and at least one other actor group, and EPSS stands at 90.5%.

Do: Update WinRAR to the latest vendor release that addresses CVE-2025-6218 per RARLAB's advisory (the fixed version number is not provided in the source data), and treat this as urgent given the KEV listing and 90.5% EPSS. Warn users not to open archives from untrusted or unexpected sources, and inspect email-borne .rar/.zip attachments. Hunt for unusual child processes or file writes outside expected directories following archive extraction, and note U.S. federal civilian agencies must apply mitigations under BOD 22-01.

7.891% KEV PoC ×2
  • RARLAB WinRAR
masshundreds of millions of users/installations worldwide
CVE-2025-62221
Use-After-Free Local Privilege Escalation in Windows Cloud Files Mini Filter Driver

CVE-2025-62221 is a use-after-free flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver, the in-box kernel component that handles cloud storage placeholder files. An attacker who already has low-privileged access on a local machine can trigger the flaw through operations involving the affected driver, with no user interaction required. Successful exploitation elevates the attacker's privileges on the local host, with high impact on confidentiality, integrity, and availability (CVSS 7.8), meaning effective full compromise of the machine. All listed Windows 10, Windows 11, and Windows Server builds are affected, and Microsoft shipped fixes in its December 2025 Patch Tuesday releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-09, indicating exploitation in the wild; EPSS is 2.5% (84th percentile) and no public proof-of-concept is known.

Do: Deploy Microsoft's December 2025 Patch Tuesday cumulative updates (released on or around 2025-12-09) for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or Intune, and confirm the update installed before treating hosts as remediated. Prioritize this patch given active exploitation and KEV status (federal agencies must follow BOD 22-01 timelines or the vendor's mitigations); no standalone workaround or public PoC is documented. Because this is a local privilege escalation, roll out first to fleets where low-privileged users routinely execute code, such as workstations and terminal/RDS servers.

7.83% KEV
  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2
  • Microsoft Windows Server 2019, 2022, 2022 23H2, 2025
masshundreds of millions to over 1 billion Windows 10/11 and Windows Server installations
CVE-2025-63216
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices.

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

NVD description · AI analysis pending
10.0<1% PoC
  • itel idgateway firmware
CVE-2025-63224
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices.

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

NVD description · AI analysis pending
10.0<1% PoC
  • itel idenc firmware
CVE-2025-64113
Emby Server is a user-installable home media server.

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.

NVD description · AI analysis pending
9.3<1%
  • emby emby
CVE-2025-64126
An OS command injection vulnerability exists due to improper input validation.

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker to inject arbitrary commands.

NVD description · AI analysis pending
10.02%
CVE-2025-64127
An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input.

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

NVD description · AI analysis pending
10.02%
CVE-2025-64128
An OS command injection vulnerability exists due to incomplete validation of user-supplied input.

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary commands.

NVD description · AI analysis pending
10.02%
CVE-2025-65106
LangChain is a framework for building agents and LLM-powered applications.

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.80 and 1.0.7.

NVD description · AI analysis pending
8.3<1%
CVE-2025-65108
md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome.

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library, resulting in remote code execution. This issue has been patched in version 5.2.5.

NVD description · AI analysis pending
10.0<1%
CVE-2025-65883
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execut

A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout. When an administrator logs out, the session token remains valid. An attacker on the local network can reuse this stale token to send crafted requests via the router’s diagnostic endpoint, resulting in command execution as root.

NVD description · AI analysis pending
8.4<1% PoC
  • genexis platinum 4410 firmware
CVE-2025-66489
Cal.com is open-source scheduling software.

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.

NVD description · AI analysis pending
9.9<1% PoC
  • cal cal.com
CVE-2025-66567
The ruby-saml library is for implementing the client side of a SAML authorization.

The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from the same input. This allows an attacker to execute a Signature Wrapping attack. This issue is fixed in version 1.18.0.

NVD description · AI analysis pending
9.3<1%
  • onelogin ruby-saml
CVE-2025-66570
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library.

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can inject headers named REMOTE_ADDR, REMOTE_PORT, LOCAL_ADDR, LOCAL_PORT that are parsed into the request header multimap via read_headers() in httplib.h (headers.emplace), then the server later appends its own internal metadata using the same header names in Server::process_request without erasing duplicates. Because Request::get_header_value returns the first entry for a header key (id == 0) and the client-supplied headers are parsed before server-inserted headers, downstream code that uses these header names may inadvertently use attacker-controlled values. Affected files/locations: cpp-httplib/httplib.h (read_headers, Server::process_request, Request::get_header_value, get_header_value_u64) and cpp-httplib/docker/main.cc (get_client_ip, nginx_access_logger, nginx_error_logger). Attack surface: attacker-controlled HTTP headers in incoming requests flow into the Request.headers multimap and into logging code that reads forwarded headers, enabling IP spoofing, log poisoning, and authorization bypass via header shadowing. This vulnerability is fixed in 0.27.0.

NVD description · AI analysis pending
9.8<1% PoC
  • yhirose cpp-httplib
CVE-2025-67635
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing una

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

NVD description · AI analysis pending
7.5<1%
  • jenkins jenkins
CVE-2025-67779
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case.

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

NVD description · AI analysis pending
7.520%
  • facebook react
  • facebook next.js
CVE-2025-8110
Actively Exploited Path Traversal RCE in Gogs (PutContents API)

CVE-2025-8110 is a path-traversal flaw (CWE-22) caused by improper symbolic-link handling in the PutContents API of the self-hosted Git service Gogs. An attacker with low-privileged access to the API can abuse symlinks so that file operations escape the intended directory, resulting in code execution on the server hosting Gogs. Because the attack works over the network with only low privileges and no user interaction, any Gogs deployment whose API is reachable — particularly internet-facing instances — is exposed. This is a zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-12 after reports of active attacks against 700+ instances, and at the time of the KEV listing no official patch was available, though a fix was in progress in Gogs pull request #8078. EPSS assigns an 82.5% probability of exploitation within 30 days (100th percentile), and CISA's required action is to apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

Do: Because no official patch was released at the time of the KEV listing, track gogs/gogs PR #8078 and upgrade to the fixed release as soon as it ships; in the interim, follow CISA's required action by applying vendor mitigations or restricting or discontinuing internet exposure of Gogs instances. Reduce attack surface by limiting low-privileged account access to the PutContents/write APIs and firewalling Gogs servers, and hunt for indicators of compromise on any internet-facing Gogs deployment given confirmed attacks against 700+ instances.

8.782% KEV PoC ×3
  • Gogs
moderate≈700+ instances confirmed exploited; the broader population of internet-exposed Gogs deployments is likely in the thousands to tens of thousands (estimate)
CVE-2025-9613
+2 in the same advisory: …9614 …9612
A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after compl

A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completions being delivered to the wrong security context, potentially compromising data integrity and confidentiality.

NVD description · AI analysis pending
6.5
group max
<1%
  • pcisig pci express integrity and data encryption
Full article2,913 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 15, 2025Hacking News / Cybersecurity

If you use a smartphone, browse the web, or unzip files on your computer, you are in the crosshairs this week. Hackers are currently exploiting critical flaws in the daily software we all rely on—and in some cases, they started attacking before a fix was even ready.

Below, we list the urgent updates you need to install right now to stop these active threats.

⚡ Threat of the Week

Apple and Google Release Fixes for Actively Exploited Flaws — Apple released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari web browser to address two zero-days that the company said have been exploited in highly targeted attacks. CVE-2025-14174 has been described as a memory corruption issue, while the second, CVE-2025-43529, is a use-after-free bug. They can both be exploited using maliciously crafted web content to execute arbitrary code. CVE-2025-14174 was also addressed by Google in its Chrome browser since it resides in its open-source Almost Native Graphics Layer Engine (ANGLE) library. There are currently no details on how these flaws were exploited, but evidence points to it likely having been weaponized by commercial spyware vendors.

🔔 Top News

  • SOAPwn Exploits HTTP Client Proxies in .NET for RCE — Cybersecurity researchers uncovered an unexpected behavior of HTTP client proxies in .NET applications, potentially allowing attackers to achieve remote code execution. The vulnerability has been codenamed SOAPwn. At its core, the problem has to do with how .NET applications might be vulnerable to arbitrary file writes because .NET's HTTP client proxies also accept non-HTTP URLs such as files, a behavior that Microsoft says developers are responsible for guarding against — but not likely to expect. This, in turn, can open remote code execution (RCE) attack paths through web shells and malicious PowerShell scripts in many .NET applications, including commercial products. By being able to pass an arbitrary URL to a SOAP API endpoint in an affected .NET application, an attacker can trigger a leak of NTLM challenge. The issue can also be exploited through Web Services Description Language (WSDL) imports, which can then be used to generate client SOAP proxies that can be controlled by the attacker. "The .NET Framework allows its HTTP client proxies to be tricked into interacting with the filesystem. With the right conditions, they will happily write SOAP requests into local paths instead of sending them over HTTP," watchTowr said. "In the best case, this results in NTLM relaying or challenge capture. In the worst case, it becomes remote code execution through webshell uploads or PowerShell script drops."
  • Attackers Exploit New Flaw in CentreStack and Triofox — A new vulnerability in Gladinet's CentreStack and Triofox products is being actively exploited by unknown threat actors to achieve code execution. The vulnerability, which does not have a CVE identifier, can be abused to access the web.config file, which can then be used to execute arbitrary code. At the core of the issue is a design failure in how they generate the cryptographic keys used to encrypt the access tokens the products use to control who can retrieve what files. As a result, the cryptographic keys never change and can be used to access files containing valuable data. Huntress said, as of December 10, 2025, nine organizations have been affected by the newly disclosed flaw.
  • WinRAR Flaw Exploited by Multiple Threat Actors — A high-severity flaw in WinRAR (CVE-2025-6218, CVSS score: 7.8) has come under active exploitation, fueled by three different threat actors tracked as GOFFEE (aka Paper Werewolf), Bitter (aka APT-C-08 or Manlinghua), and Gamaredon. CVE-2025-6218 is a path traversal vulnerability that allows an attacker to execute code in the context of the current user. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by December 30, 2025.
  • Exploitation of React2Shell Surges — The recently disclosed maximum-severity security flaw in React (CVE-2025-55182, CVSS score: 10.0) has come under widespread exploitation, with threat actors targeting unpatched systems to deliver various kinds of malware. Public disclosure of the flaw triggered a "rapid wave of opportunistic exploitation," according to Wiz. Google said it observed a China-nexus espionage cluster UNC6600 exploiting React2Shell to deliver MINOCAT, a tunneling utility based on Fast Reverse Proxy (FRP). Other exploitation efforts included the deployment of the SNOWLIGHT downloader by UNC6586 (China-nexus), the COMPOOD backdoor (linked to suspected China-nexus espionage activity since 2022) by UNC6588, an updated version of the Go-based HISONIC backdoor by UNC6603 (China-nexus), and ANGRYREBEL.LINUX (aka Noodle RAT) by UNC6595 (China-nexus). "These observed campaigns highlight the risk posed to organizations using unpatched versions of React and Next.js," Google said.
  • Hamas-Affiliated Group Goes After the Middle East — WIRTE (aka Ashen Lepus), a cyber threat group associated with Hamas, has been conducting espionage on government bodies and diplomatic entities across the Middle East since 2018. In recent years, the threat actor has broadened its targeting scope to include Oman and Morocco, while simultaneously evolving its capabilities. The modus operandi follows tried-and-tested cyber espionage tactics, using spear-phishing emails to deliver malicious attachments that deliver a modular malware suite dubbed AshTag. The components of the framework are embedded in a command-and-control (C2) web page within HTML tags in Base64-encoded format, from where they are parsed and decrypted to download the actual payloads. "Ashen Lepus remained persistently active throughout the Israel-Hamas conflict, distinguishing it from other affiliated groups whose activities decreased over the same period," Palo Alto Networks Unit 42 said. "Ashen Lepus continued with its campaign even after the October 2025 Gaza ceasefire, deploying newly developed malware variants and engaging in hands-on activity within victim environments." It's being assessed that the group may be operating from outside Gaza, citing continued activity throughout the conflict.

‎️‍🔥 Trending CVEs

Hackers act fast. They can use new bugs within hours. One missed update can cause a big breach. Here are this week’s most serious security flaws. Check them, fix what matters first, and stay protected.

This week’s list includes — CVE-2025-43529, CVE-2025-14174 (Apple), CVE-2025-14174 (Google Chrome), CVE-2025-55183, CVE-2025-55184, CVE-2025-67779 (React), CVE-2025-8110 (Gogs), CVE-2025-62221 (Microsoft Windows), CVE-2025-59718, CVE-2025-59719 (Fortinet), CVE-2025-10573 (Ivanti Endpoint Manager), CVE-2025-42880, CVE-2025-55754, CVE-2025-42928 (SAP), CVE-2025-9612, CVE-2025-9613, CVE-2025-9614 (PCI Express Integrity and Data Encryption protocol), CVE-2025-27019, CVE-2025-27020 (Infinera MTC-9), CVE-2025-65883 (Genexis Platinum P4410 router), CVE-2025-64126, CVE-2025-64127, CVE-2025-64128 (Zenitel TCIV-3+), CVE-2025-66570 (cpp-httplib), CVE-2025-63216 (Itel DAB Gateway), CVE-2025-63224 (Itel DAB Encoder) CVE-2025-13390 (WP Directory Kit plugin), CVE-2025-65108 (md-to-pdf), CVE-2025-58083 (General Industrial Controls Lynx+ Gateway), CVE-2025-66489 (Cal.com), CVE-2025-12195, CVE-2025-12196, CVE-2025-11838, CVE-2025-12026 (WatchGuard), CVE-2025-64113 (Emby Server), CVE-2025-66567 (ruby-saml), CVE-2025-24857 (Universal Boot Loader), CVE-2025-13607 (D-Link DCS-F5614-L1, Sparsh Securitech, Securus CCTV), CVE-2025-13184 (TOTOLINK AX1800), CVE-2025-65106 (LangChain), CVE-2025-67635 (Jenkins), CVE-2025-12716, CVE-2025-8405, CVE-2025-12029, CVE-2025-12562 (GitLab CE/EE), and CVE-2025-64775 (Apache Struts 2).

📰 Around the Cyber World

  • U.K. Fines LastPass for 2022 Breach — The U.K. Information Commissioner's Office (ICO) fined LastPass's British subsidiary £1.2 million ($1.6 million) for a data breach in 2022 that enabled attackers to access personal information belonging to its customers, including their encrypted password vaults. The hackers compromised a company-issued MacBook Pro of a software developer based in Europe to access the corporate development environment and related technical documentation, and exfiltrate a little over a dozen repositories. It's unclear how the MacBook was infected. Subsequently, the threat actors gained access to one of the DevOps engineers' PCs by exploiting CVE-2020-5741, a vulnerability in Plex Media Server, installed a keylogger used to steal the engineer's master password, and breached the cloud storage environment. The ICO said LastPass failed to implement sufficiently robust technical and security measures. "LastPass customers had a right to expect the personal information they entrusted to the company would be kept safe and secure," John Edwards, U.K. Information Commissioner, said. "However, the company fell short of this expectation, resulting in the proportionate fine being announced today."
  • APT-C-60 Targets Japan with SpyGlace — The threat actor known as APT-C-60 has been linked to continued cyber attacks targeting Japan to deliver SpyGlace using spear-phishing emails impersonating job seekers. The attacks were observed between June and August 2025, per JPCERT/CC. "In the previous attacks, victims were directed to download a VHDX file from Google Drive," the agency said. "However, in the latest attacks, the malicious VHDX file was directly attached to the email. When the recipient clicks the LNK file contained within the VHDX, a malicious script is executed via Git, which is a legitimate file." The attacks leverage GitHub to download the main malware components, marking a shift from Bitbucket.
  • ConsentFix, a New Twist on ClickFix — Cybersecurity researchers have discovered a new variation of the ClickFix attack. Called ConsentFix, the new technique relies on tricking users into copy-pasting text that contains their OAuth material into an attacker-controlled web page. Push Security said it spotted the technique in attacks targeting Microsoft business accounts. In these attacks, targets are funneled through Google Search to compromised but reputable websites injected with a fake Cloudflare Turnstile challenge that instructs them to sign in to their accounts and paste the URL. Once the targets log in, they are redirected to a localhost URL containing the OAuth authorization code for their Microsoft account. The phishing process ends when the victims paste the URL back into the original page, granting the threat actors unauthorized access. The attack "sees the victim tricked into logging into Azure CLI, by generating an OAuth authorization code — visible in a localhost URL — and then pasting that URL, including the code, into the phishing page," the security company said. "The attack happens entirely inside the browser context, removing one of the key detection opportunities for ClickFix attacks because it doesn't touch the endpoint." The technique is a variation of an attack used by Russian state-sponsored hackers earlier this year that deceived victims into sending their OAuth authorization code via Signal or WhatsApp to the hackers.
  • 2025 CWE Top 25 Most Dangerous Software Weaknesses — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with the MITRE Corporation, released the 2025 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses, identifying the most critical vulnerabilities that adversaries exploit to compromise systems, steal data, or disrupt services. It was compiled from 39,080 CVEs published this year. Topping the list is cross-site scripting, followed by SQL Injection, Cross-Site Request Forgery (CSRF), missing authorization, and out-of-bounds write.
  • Salt Typhoon Spies Reportedly Attended Cisco Training Scheme — Two of Salt Typhoon's members, Yu Yang and Qiu Daibing, have been identified as participants of the 2012 Cisco Networking Academy Cup. Both Yu and Qiu are co-owners of Beijing Huanyu Tianqiong, one of the Chinese companies that the U.S. government and its allies allege as being fronts for Salt Typhoon activity. Yu is also tied to another Salt Typhoon-connected company, Sichuan Zhixin Ruijie. SentinelOne found that Yu and Qiu represented Southwest Petroleum University in Cisco's academy cup in China. Yu's team was placed second in the Sichuan region, while Qiu's team took the first prize and later claimed the third spot nationally, despite the university being considered as a poorly-regarded academic institution. "The episode suggests that offensive capabilities against foreign IT products likely emerge when companies begin supplying local training and that there is a potential risk of such education initiatives inadvertently boosting foreign offensive research," security researcher Dakota Cary said. The episode stresses the need for demonstrating technical competencies when hiring technical professionals and that offensive teams may benefit from putting their own employees through similar training initiatives like Huawei's ICT academy.
  • Freedom Chat Flaws Detailed — A pair of security flaws has been disclosed in Freedom Chat that could have allowed a bad actor to guess registered users' phone numbers (similar to the recent WhatsApp flaw) and expose user-set PINs to others on the app. The issues, discovered by Eric Daigle, have since been addressed by the privacy-focused messaging app as of December 7, 2025. In an update pushed out to Apple and Google's app stores, the company said: "A critical reset: A recent backend update inadvertently exposed user PINs in a system response. No messages were ever at risk, and because Freedom Chat does not support linked devices, your conversations were never accessible; however, we’ve reset all user PINs to ensure your account stays secure. Your privacy remains our top priority."
  • Unofficial Patch for New Windows RasMan 0-Day Released — Free unofficial patches have been made available for a new Windows zero-day vulnerability that allows unprivileged attackers to crash the Remote Access Connection Manager (RasMan) service. ACROS Security's 0patch service said it discovered a new denial-of-service (DoS) flaw while looking into CVE-2025-59230, a Windows RasMan privilege escalation vulnerability exploited in attacks that was patched in October. The new flaw has not been assigned a CVE identifier, and there is no evidence of it having been abused in the wild. It affects all Windows versions, including Windows 7 through Windows 11 and Windows Server 2008 R2 through Server 2025.
  • Ukrainian National Charged for Cyber Attacks on Critical Infra — U.S. prosecutors have charged a Ukrainian national for her role in cyberattacks targeting critical infrastructure worldwide, including U.S. water systems, election systems, and nuclear facilities, on behalf of Russian state-backed hacktivist groups. Victoria Eduardovna Dubranova (aka Vika, Tory, and SovaSonya), 33, was allegedly part of two pro-Kremlin hacktivist groups named NoName057(16) and CyberArmyofRussia_Reborn (CARR), the latter of which was founded, funded, and directed by Russia's military intelligence service GRU. NoName057(16), a hacktivist group active since March 2022, has over 1,500 DDoS attacks against organizations in Ukraine and NATO countries. If found guilty, Dubranova faces up to 32 years in prison. She was extradited to the U.S. earlier this year. The U.S. Justice Department said the groups tampered with U.S. public water systems and caused an ammonia leak at a U.S. meat processing factory. Dubranova pleaded not guilty in a U.S. court last week. The U.S. government is also offering rewards for additional information on other members of the two groups. Prosecutors said administrators of the two collectives, dissatisfied with the level of support and funding from the GRU, went on to form Z-Pentest in September 2024 to conduct hack-and-leak operations and defacement attacks. "Pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. These attacks use minimally secured, internet-facing virtual network computing (VNC) connections to infiltrate (or gain access to) OT control devices within critical infrastructure systems," U.S. and other allies said in a joint advisory. "Pro-Russia hacktivist groups – Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector 16, and affiliated groups – are capitalizing on the widespread prevalence of accessible VNC devices to execute attacks against critical infrastructure entities, resulting in varying degrees of impact, including physical damage." These groups are known for their opportunistic attacks, typically leveraging unsophisticated tradecraft like known security flaws, reconnaissance tools, and common password-guessing techniques to access networks and conduct SCADA intrusions. While their ability to consistently cause significant impact is limited, they also tend to work together to amplify each other's posts to reach a broader audience on platforms like Telegram and X. X's Safety team said it cooperated with U.S. authorities to suspend NoName057(16)'s account ("@NoName05716") for facilitating criminal conduct.
  • APT36 Targets Indian Government Entities with Linux Malware — A new phishing campaign orchestrated by APT36 (aka Transparent Tribe) has been observed delivering tailored malware specifically crafted to compromise Linux-based BOSS operating environments prevalent in Indian government networks. "The intrusion begins with spear-phishing emails designed to lure recipients into opening weaponized Linux shortcut files," CYFIRMA said. "Once executed, these files silently download and run malicious components in the background while presenting benign content to the user, thereby facilitating stealthy initial access and follow-on exploitation." The attack culminates with the deployment of a Python-based Remote Administration Tool (RAT) that can collect system information, contact an external server, and run commands, granting the attackers remote control over infected hosts. "The group’s current activity reflects a broader trend in state-aligned espionage operations: the adoption of adaptive, context-aware delivery mechanisms designed to blend seamlessly into the target's technology landscape," the company said.
  • Vietnamese IT and HR Firms Targeted by Operation Hanoi Thief — A threat cluster referred to as Operation Hanoi Thief has targeted Vietnamese IT departments and HR recruiters using fake resumes distributed as ZIP files in phishing emails to deliver malware called LOTUSHARVEST. The ZIP file contains a Windows shortcut (LNK) file that, when opened, executes a "pseudo-polyglot" payload present in the archive that serves as the lure and as well as the container for a batch script that displays a decoy PDF and uses DLL side-loading to load the LOTUSHARVEST DLL. The malware runs various anti-analysis checks and proceeds to harvest data from web browsers such as Google Chrome and Microsoft Edge. The activity has been attributed with medium confidence to a threat cluster of Chinese origin.
  • Microsoft Adds New PowerShell Security Feature — With PowerShell 5.1, Microsoft has added a new feature to warn users when they're about to execute web content. The warning will alert users when executing the Invoke-WebRequest command without additional special parameters. "This prompt warns that scripts in the page could run during parsing and advises using the safer -UseBasicParsing parameter to avoid any script execution," Microsoft said. "Users must choose to continue or cancel the operation. This change helps protect against malicious web content by requiring user consent before potentially risky actions." The company also said it's rolling out a new Baseline Security Mode in Office, SharePoint, Exchange, Teams, and Entra that can automatically configure apps with minimum security requirements. The centralized experience began rolling out in phases last month and will be completed by March next year. "It provides admins with a dashboard to assess and improve security posture using impact reports and risk-based recommendations, with no immediate user impact," Microsoft said. "Admins can view the tenant's current security posture compared to Microsoft’s recommended minimum security bar."
  • U.S. to Require Foreign Travelers to Share 5-Year Social Media History — The U.S. government will soon require all foreign travelers to provide five years' worth of social media history prior to their entry. This includes details about social media accounts, email addresses, and phone numbers used over the past five years. The new requirement will be applied to foreigners from all countries, including those who are eligible to visit the U.S. for 90 days without a visa. "We want to make sure we're not letting the wrong people enter our country," U.S. President Donald Trump said.
  • New AitM Phishing Campaign Targets Microsoft 365 and Okta Users — An active adversary-in-the-middle (AitM) phishing campaign is targeting organizations that use Microsoft 365 and Okta for their single sign-on (SSO), with the main goal of hijacking the legitimate SSO flow and bypassing multi-factor authentication (MFA) methods that are not phishing-resistant. "When a victim uses Okta as their identity provider (IdP), the phishing page hijacks the SSO authentication flow to bring the victim to a second-stage phishing page, which acts as a proxy to the organization's legitimate Okta tenant and captures the victim’s credentials and session tokens," Datadog said.
  • Phishing Campaign Uses Fake Calendly Invites to Spoof Major Brands — A large-scale phishing campaign has Calendly-themed phishing lures entered around a fake job opportunity to steal Google Workspace and Facebook business account credentials. These emails purport to originate from brands like Louis Vuitton, Unilever, Lego, and Disney, among others. "Only after the victim has responded to an initial email was the phishing link delivered under the guise of a Calendly link to book time for a call," Push Security said. "Clicking the link takes the victim to an authentic-looking page impersonating a Calendly landing page. From there, users are prompted to complete a CAPTCHA check and continue to sign in with their Google account, which causes their credentials to be stolen using an AitM phishing page. A similar variant has also been observed tricking victims into entering their Facebook account credentials on bogus pages, while another targets both Google and Facebook credentials using Browser-in-the-Browser (BitB) techniques that display fake pop-up windows featuring legitimate URLs to steal account credentials. The fact that the campaign is focused on compromising accounts responsible for managing digital ads on behalf of businesses shows that the threat actors are looking to launch malvertising campaigns for other kinds of attacks, including ClickFix. This is not the first time job-related lures have been used to steal account information. In October 2025, phishing emails impersonating Google Careers were used to phish credentials. In tandem, Push Security said it also observed a malvertising campaign in which users who searched for "Google Ads" on Google Search were served a malicious sponsored ad that's designed to capture their credentials.
  • Calendar Subscriptions for Phishing and Malware Delivery — Threat actors have been found leveraging digital calendar subscription infrastructure to deliver malicious content. "The security risk arises from third-party calendar subscriptions hosted on expired or hijacked domains, which can be exploited for large-scale social engineering," Bitsight said. "Once a subscription is established, they can deliver calendar files that may contain harmful content, such as URLs or attachments, turning a helpful tool into an unexpected attack vector." The attack takes advantage of the fact that these third-party servers can add events directly to users' schedules. The cybersecurity company said it discovered more than 390 abandoned domains related to iCalendar synchronization (sync) requests for subscribed calendars, potentially putting about four million iOS and macOS devices at risk. All the identified domains have been sinkholed.
  • The Gentlemen Ransomware Uses BYOVD Technique in Attacks — A nascent ransomware group called The Gentlemen has employed tactics common to advanced e-crime groups, such as Group Policy Objects (GPO) manipulation and Bring Your Own Vulnerable Driver (BYOVD), as part of double extortion attacks aimed at manufacturing, construction, healthcare, and insurance sectors across 17 countries. "Since its emergence, Gentlemen has been evaluated as one of the most active emerging ransomware groups in 2025, having attacked multiple regions and industries in a relatively short period," AhnLab said. The group emerged around July 2025, with PRODAFT noting in mid-October that Phantom Mantis (ArmCorp), led by LARVA-368 (hastalamuerte), tested Qilin (Pestilent Mantis), Embargo (Primeval Mantis), LockBit (Tenacious Mantis), Medusa (Venomous Mantis), and BlackLock (Incredible Mantis), before building their own ransomware-as-a-service (RaaS): The Gentlemen.

🎥 Cybersecurity Webinars

  • Defining the New Layers of Cloud Defense with Zero Trust and AI: This webinar shows how Zero Trust and AI help stop modern, fileless attacks. Zscaler experts explain new tactics like “living off the land” and fileless reassembly, and how proactive visibility and secure developer environments keep organizations ahead of emerging threats.
  • Speed vs. Security: How to Patch Faster Without Opening New Doors to Attackers: This session explores how to balance speed and security when using community patching tools like Chocolatey and Winget. Gene Moody, Field CTO at Action1, examines real risks in open repositories—outdated packages, weak signatures, and unverified code—and shows how to set clear guardrails that keep patching fast but safe. Attendees will learn when to trust community sources, how to detect version drift, and how to run controlled rollouts without slowing operations.

🔧 Cybersecurity Tools

  • Strix: A small open-source tool that helps developers build command-line interfaces (CLIs) more easily. It focuses on keeping setup simple and commands clear, so you can create tools that behave the same way every time. Instead of dealing with complex frameworks, you can use Strix to define commands, handle arguments, and manage output in a few straightforward steps.
  • Heisenberg: It is a simple, open-source tool that looks at the software your projects depend on and checks how healthy and safe those parts are. It reads information about packages from public sources and “software bills of materials” (SBOMs) to find security problems or bad signals in your dependency chain and can produce reports for one package or many at once. The idea is to help teams spot risky or vulnerable components early, especially as they change, so you can understand supply chain risks without a complex setup.

Disclaimer: These tools are for learning and research only. They haven’t been fully tested for security. If used the wrong way, they could cause harm. Check the code first, test only in safe places, and follow all rules and laws.

Conclusion

We listed a lot of fixes today, but reading about them doesn't secure your device—installing them does. The attackers are moving fast, so don't leave these updates for 'later.' Take five minutes right now to check your systems, restart if you need to, and head into the weekend knowing you are one step ahead of the bad guys.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/12/weekly-recap-apple-0-days-winrar.html