Researchers have discovered two critical local privilege escalation vulnerabilities—CVE-2025-6018 and CVE-2025-6019—that allow attackers to gain root access on major Linux distributions. These flaws can be chained, letting unprivileged users escalate privileges, impacting the security posture of countless systems worldwide and underscoring the urgent need for immediate patching and monitoring for exploitation.
Source: Security Affairs
Massive 16 Billion Credential Exposure—Not New, Still Dangerous
Researchers report a staggering 16 billion login credentials recently found online, likely harvested over time by infostealers and compiled from multiple breaches. While many are previously leaked, this “mother of all breaches” is a stark warning about password reuse and the continued risk to enterprises and individuals from credential stuffing attacks.
Source: Bleeping Computer
Cloudflare Blocks Largest-Ever DDoS Attack at 7.3 Tbps
Cloudflare reports successfully mitigating a record-breaking distributed denial-of-service (DDoS) attack peaking at 7.3 terabits per second, delivering 37.4 terabytes in under a minute. The attack, which targeted a hosting provider, highlights the rising scale of DDoS threats against infrastructure providers and the necessity for robust distributed defense mechanisms.
Source: TheHackerNews
China-linked Salt Typhoon Group Breaches Viasat Satellite Networks
The Salt Typhoon APT, attributed to China, has successfully hacked into the networks of global satellite communications firm Viasat. This breach, part of a wider campaign targeting the telecoms sector, underlines the strategic value of satellite networks in cyber-espionage and the persistent vulnerability of critical infrastructure to state-backed actors.
Source: Bleeping Computer
Krispy Kreme Discloses Breach Impacting Over 160,000 Individuals
Krispy Kreme has confirmed that its November 2024 ransomware attack led to the breach of sensitive personal and financial data belonging to more than 160,000 people. The incident took months to investigate and demonstrates ongoing risks of data theft, identity fraud, and the need for continuous security improvements in consumer-facing enterprises.
Source: SecurityWeek
AI-Powered Coding Assistants Introduce Software Supply Chain Risks
The growing reliance on AI-based coding tools like GitHub Copilot and ChatGPT streamlines development but poses new software supply chain risks. Research highlights that “hallucinated” code suggestions may prompt developers to import non-existent—or even malicious—dependencies, increasingly opening the door to supply chain compromise.
Source: Checkpoint Blog
Banana Squad Campaign Drops Data-Stealers via Fake GitHub Repositories
Security researchers have uncovered a campaign—dubbed "Banana Squad"—using more than 67 trojanized GitHub repositories to distribute data-stealing malware disguised as Python-based hacking tools. The operation targets both developers and gamers, underlining the escalating abuse of open-source platforms for malware distribution and supply chain infiltration.
Source: TheHackerNews
You May Also Be Interested In...
China-linked group Salt Typhoon breached satellite firm Viasat
Cloudflare Tunnels Abused in New Malware Campaign
CISOs flag gaps in GenAI strategy, skills, and infrastructure