A newly disclosed unauthenticated information leak in MongoDB is being actively exploited, according to Wiz. Organizations should prioritize detection and mitigation, as attackers can extract sensitive information without credentials. Wiz provides guidance to identify exposure and harden affected deployments.
Source: Wiz
Malicious NPM package ‘Lotusbail’ with 56,000 downloads steals WhatsApp credentials
Researchers uncovered a compromised WhatsApp Web API library on NPM that hid its activity, exfiltrated user credentials/data, and installed a backdoor. The package, ‘Lotusbail’—a fork of ‘Baileys’—was available for roughly six months, amassing over 56,000 downloads before discovery. This is a stark reminder to vet open-source dependencies and monitor for suspicious post-install behavior.
Source: Security Affairs
Critical LangChain Core flaw (CVE-2025-68664) enables prompt injection and data exposure
A CVSS 9.3 vulnerability in langchain-core allows attackers to manipulate LLM responses via prompt injection and potentially steal secrets. Because LangChain is widely embedded in LLM apps and toolchains, the blast radius includes production workloads that bind models to sensitive data or actions. Development teams should review usage and update promptly.
Source: Security Affairs
Hacker leaks 2.3M Wired.com records, claims 40M-user Condé Nast breach
A threat actor known as “Lovely” published what they allege are 2.3 million Wired.com user records and further claimed access impacting 40 million Condé Nast users. Verification of the broader claim remains unclear, but media and publishing accounts may face heightened phishing and credential-stuffing risk.
Source: HackRead
Samsung confirms critical January update for most Galaxy users
Samsung says a critical update is coming in January for the majority of Galaxy devices. Enterprises managing large Android fleets and BYOD programs should plan for timely testing and deployment to reduce exposure windows.
Source: Forbes Security
Meet the team that hunts government spyware targeting journalists and activists
Access Now’s Digital Security Helpline has spent years assisting dissidents and reporters who are targeted with government-grade spyware. The profile outlines how the team investigates compromises and supports at-risk communities—a reminder that mercenary surveillance remains an active, global threat vector.
Source: TechCrunch Security
The top security predictions for 2026: part two of an industry roundup
GovTech’s annual synthesis compiles forecasts from leading vendors, publications, and experts on what’s next in cyber. The second installment highlights emerging risks and priorities that security leaders can use to stress-test roadmaps for the year ahead.
Source: GovTech
You May Also Be Interested In...
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory
Apple’s iPhone Upgrade—Hundreds Of Millions Of Users Must Act Now
Week in review: WatchGuard Firebox firewalls attacked, infosec enthusiasts targeted with fake PoCs