CISA added CVE-2025-55182 (CVSS 10.0) affecting React Server Components to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild attacks. The bug enables remote code execution, making internet-facing apps built with vulnerable RSC implementations high-risk. Organizations should prioritize patching, review dependency chains, and inspect apps for suspicious component payloads.
Source: TheHackerNews
Chinese State Hackers Deploy “BRICKSTORM” Backdoor Against VMware Environments
CISA, NSA, and Canada’s Cyber Centre warn that PRC-linked operators are using BRICKSTORM, a stealthy Go-based backdoor, to persist within VMware-centric infrastructures. The campaign focuses on long-term espionage inside government and IT networks, underscoring the need to harden virtualization management planes and monitor for abnormal processes and lateral movement.
Source: HackRead
Mass Campaign Targets Palo Alto GlobalProtect Portals and SonicWall SonicOS APIs
Since December 2, attackers from more than 7,000 IPs tied to German host 3xK GmbH have attempted logins on GlobalProtect portals and scanned SonicWall SonicOS API endpoints. The dual push against two popular edge technologies suggests broad reconnaissance and credential-stuffing activity; enforce MFA, tighten rate limits, and scrutinize API exposure.
Source: Security Affairs
“Shanya” Packer-as-a-Service Fuels Ransomware and EDR Evasion
Sophos details “Shanya,” a packer-as-a-service offering that helps adversaries obfuscate payloads and degrade endpoint detection. With features aimed at hindering analysis and detection, the service is being adopted across modern attacks, raising the bar for defenders to detect packed binaries, anomalous child processes, and memory-resident payloads.
Source: Sophos
Intellexa’s Predator Spyware Delivered via Zero-Click Malicious Ads
Investigation finds Intellexa abused zero-click exploits embedded in malicious advertisements to silently install Predator spyware. Once infected, targets were surveilled with sustained remote access, highlighting the growing weaponization of ad tech supply chains and the importance of hardened browsers, OS patching, and strict ad/script controls.
Source: CyberNews
“IDEsaster”: 30+ Flaws in AI-Powered IDEs Enable Data Exfiltration and RCE
Researchers disclosed over 30 vulnerabilities across AI-enhanced IDEs where prompt injection primitives combine with built-in features to leak secrets and trigger code execution. The findings show developer tooling itself can be a supply-chain risk; update affected plugins, restrict IDE permissions, and sanitize AI-driven automations.
Source: TheHackerNews
New LOLBAS-Style Trick: Abusing cliconfg.dll via rundll32
Hexacorn documents an obscure way to execute code by invoking cliconfg.dll’s dialog initialization through rundll32, leveraging legacy localization/test features. This sideloading technique broadens the Windows living-off-the-land arsenal; defenders should baseline rundll32 usage and watch for unusual DLL exports and parameters.
Source: Hexacorn
You May Also Be Interested In...
Barts Health NHS Confirms Cl0p Ransomware Behind Data Breach
Death to one-time text codes: Passkeys are the new hotness in MFA
The State of the 2025 Cyber Workforce: Skills Gaps, AI Opportunity and Economic Strain