US cybersecurity officials say state-backed groups and cyber-mercenaries are using commercial spyware and RATs to compromise high-value mobile users, bypassing end-to-end encryption by taking device-level control. Techniques include spoofed apps and even zero-click exploits. Enterprises should lock down mobile fleets, enforce OS/app updates, restrict sideloading, and monitor for MDM bypass and abnormal messaging app behavior.
Source: The Register
New ‘Shai-Hulud’ npm supply-chain attack infects 640 packages
A fresh wave of the self-replicating npm worm has compromised at least 640 packages, with a destructive twist that wipes home directories if it cannot spread further. The campaign abuses preinstall hooks to exfiltrate secrets and propagate via developer tokens, rapidly impacting thousands of repositories. Teams should lock dependencies, audit CI/CD secrets, rotate tokens, and enforce 2FA and provenance for packages.
Source: SecurityWeek
Fluent Bit flaws expose cloud environments to RCE and data tampering
Five newly assigned, “trivial-to-exploit” vulnerabilities in the widely deployed Fluent Bit telemetry agent (15B+ instances) allow auth bypass, path traversal, DoS, and remote code execution. Because Fluent Bit underpins logging in major clouds and AI labs, the bugs pose systemic risk to service availability and telemetry integrity until patches and hardening are applied.
Source: The Register
ShadowPad malware exploits patched WSUS bug for full system access
Threat actors are abusing a recently fixed Windows Server Update Services vulnerability (CVE-2025-59287) to gain initial access, use PowerCat for shells, and deploy the ShadowPad backdoor. Targeting WSUS-enabled servers, the attack leverages trusted update infrastructure to establish persistence and command-and-control.
Source: The Hacker News
FCC scraps post–Salt Typhoon telecom cyber rules amid ongoing espionage risk
The FCC has repealed cybersecurity rules introduced after the China-linked Salt Typhoon campaign, rolling back measures meant to keep state-backed operators out of US networks. The reversal could shift more security burden onto carriers and their suppliers, increasing scrutiny on network monitoring and supply-chain controls.
Source: The Register
Third-party breach at SitusAMC triggers data exposure concerns for major banks
JPMorgan, Citi, and Morgan Stanley are assessing potential exposure after attackers stole confidential client data from real-estate finance firm SitusAMC. The FBI is investigating; the incident underscores how vendor compromises can cascade to core financial institutions and their customers.
Source: TechCrunch
CISA orders rapid patching of actively exploited Oracle Identity Manager flaw
US agencies must mitigate an Oracle Identity Manager authentication bypass (CVE-2025-61757) by December 12 following evidence of in-the-wild abuse, possibly predating Oracle’s fix. The KEV-listed bug poses serious identity-tier risk, potentially enabling SSO compromise and lateral movement if left unaddressed.
Source: The Register
You May Also Be Interested In...
Is Your Android TV Streaming Box Part of a Botnet? (KrebsOnSecurity)
Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims (SecurityWeek)
Maximum severity Grafana vulnerability fixed (SC Media)