Shadowserver scans show more than 115,000 internet‑facing WatchGuard Firebox firewalls potentially exposed to CVE‑2025‑14733, an unauthenticated remote code execution bug that attackers are currently exploiting. Organizations should urgently patch Fireware OS, limit public exposure of management interfaces, and monitor for anomalous VPN/iked activity.
Source: Help Net Security
Attackers abuse Google Cloud to send phishing from a trusted google.com address
A campaign impersonating Google‑generated notifications leveraged Google Cloud Application Integration to send 9,394 phishing emails to roughly 3,200 customers in 14 days from noreply-application-integration@google.com. Because the messages originated from Google infrastructure, they bypassed typical sender checks; defenders should tighten workflow automation allowlists, apply bannering and content controls, and train users to verify “routine” alerts.
Source: Check Point Blog
Malicious npm package with 56,000 downloads steals WhatsApp data and accounts
A trojanized WhatsApp Web API package on npm offered legitimate functionality while covertly intercepting messages, harvesting credentials, and linking the attacker’s device to victims’ accounts. The incident underscores ongoing software supply chain risk; teams should inventory and pin dependencies, scan packages pre‑adoption, and revoke tokens/rotate credentials if exposed.
Source: SecurityWeek
Critical n8n workflow automation flaw enables RCE across exposed instances (CVE‑2025‑68613)
A CVSS 9.9 vulnerability in n8n’s expression evaluation can lead to arbitrary code execution in certain configurations, potentially impacting thousands of self‑hosted deployments. Patch immediately to the fixed release, restrict network access to the UI and webhooks, and rotate any secrets handled by impacted workflows.
Source: The Hacker News
DDoS disrupts France’s La Poste postal and banking services days before Christmas
La Poste confirmed a DDoS attack caused widespread outages across its websites and mobile apps, delaying package deliveries and blocking online payments during a peak shopping period. The incident highlights the need for layered DDoS protection, traffic engineering playbooks, and payment failover strategies for critical consumer services.
Source: SecurityWeek
INTERPOL/Europol operation nets 574 arrests, recovers $3M across Africa
Operation Sentinel, a month‑long crackdown spanning 19 countries, targeted business email compromise, digital extortion, and ransomware operations, leading to hundreds of arrests and device seizures. The results reflect growing international pressure on cybercriminal networks and reinforce the value of cross‑border evidence sharing for BEC and fraud investigations.
Source: SecurityWeek
Darknet “DIG AI” assistant accelerates cybercrime with uncensored capabilities
Researchers report the rapid rise of DIG AI, an uncensored darknet assistant enabling criminals and organized groups to perform advanced data processing and operational support for malicious activity. Usage surged through Q4, lowering barriers for less‑skilled actors; defenders should anticipate AI‑enabled reconnaissance, phishing, and tooling, and enhance detection around anomalous automation.
Source: Help Net Security
You May Also Be Interested In...
Potential attacks threaten over tens of thousands of Fortinet devices
UK Government Acknowledges It Is Investigating Cyber Incident After Media Reports
Around 1,000 systems compromised in ransomware attack on Romanian water agency