A high‑severity MongoDB Server flaw (CVE-2025-14847) that leaks uninitialized heap memory over the network is under active exploitation, with proofs of concept circulating over the holidays. CISA has added the bug to its Known Exploited Vulnerabilities catalog; admins should patch immediately and consider disabling zlib network compression where feasible to reduce exposure.
Source: The Register
Mustang Panda uses signed kernel-mode rootkit to deploy ToneShell backdoor
China-linked Mustang Panda was caught abusing a signed Windows driver that embeds user-mode shellcode to install a new ToneShell backdoor variant. The kernel-level component helps the espionage actor evade defenses and persist on targeted systems, with campaigns observed against government entities across Asia.
Source: SecurityWeek
Shai-Hulud supply chain attack tied to $8.5M Trust Wallet heist
Investigators link the Shai‑Hulud npm/GitHub supply chain worm to an $8.5 million theft affecting 2,520 crypto wallets. Stolen GitHub secrets enabled attackers to publish a backdoored extension, underscoring the urgency of rotating credentials, tightening CI/CD permissions, and monitoring developer pipelines for anomalous automation activity.
Source: SecurityWeek
EmEditor supply chain compromise delivered infostealer via official download link
The widely used Windows text/code editor EmEditor suffered a supply chain intrusion in which its homepage download button was tampered with for days, pushing information‑stealing malware. Organizations should verify installer hashes, audit endpoints for post‑infection indicators, and reissue any credentials that may have been exposed.
Source: SC Media
Radio signals can ‘reach’ air-gapped embedded devices, new study warns
Researchers show that even embedded systems without radios or sensors can receive wireless commands once an attacker gains code execution, effectively breaking the assumptions behind air gaps. The work highlights side-channel risks and the need for electromagnetic hardening, rigorous firmware integrity controls, and physical security.
Source: Help Net Security
European Space Agency confirms breach after hacker offers data for sale
The European Space Agency says external science servers were compromised, following claims by a hacker attempting to sell stolen data. While the investigation continues, the incident underscores third‑party and research infrastructure exposure risks across high‑value science and space ecosystems.
Source: SecurityWeek
Ransomware responders plead guilty to using ALPHV in attacks on U.S. organizations
Two Americans employed at incident response firms admitted to moonlighting as ALPHV/BlackCat affiliates in ransomware hits against U.S. businesses, facing up to 20 years in prison. The case spotlights insider risk and ethical conflicts in the response ecosystem, reinforcing the need for strong vetting and auditing of third‑party access.
Source: The Record
You May Also Be Interested In…
Legacy IAM was built for humans — and AI agents now outnumber them 82 to 1
CSA issues alert on critical SmarterMail RCE bug (CVE-2025-52691)
Google‑featured Chrome extensions were secretly spying on AI chats