Researchers detail a persistent nine‑month RondoDox campaign now leveraging the critical React2Shell flaw (CVE-2025-55182, CVSS 10.0) as an initial access vector. The botnet targets IoT devices and web applications—particularly vulnerable Next.js servers—to drop malware and cryptominers. Security teams should urgently patch affected React/Next.js components and audit exposed server endpoints for indicators of compromise.
Source: The Hacker News
IBM Patches Critical API Connect Auth Bypass (CVE-2025-13915)
IBM disclosed and addressed a critical authentication bypass in API Connect (CVE-2025-13915, CVSS 9.8) that could allow remote access to managed APIs. Given API Connect’s central role in creating and securing APIs, organizations should apply the vendor’s fixes immediately and review access logs for anomalous activity.
Source: Security Affairs
Coordinated Holiday Campaign Slammed Adobe ColdFusion Servers
GreyNoise observed thousands of requests during the Christmas 2025 period targeting roughly a dozen Adobe ColdFusion vulnerabilities. The activity underscores ongoing mass exploitation against legacy and poorly maintained ColdFusion instances; patching, restricting admin interfaces, and monitoring for exploitation attempts are advised.
Source: SecurityWeek
Trust Wallet Confirms Second Shai‑Hulud Supply‑Chain Attack; $8.5M Stolen
Trust Wallet says a second Shai‑Hulud supply‑chain incident likely compromised its Chrome extension, leading to the theft of about $8.5 million in crypto assets. The case highlights persistent risks in software supply chains and browser extension ecosystems; users should rotate keys, update from verified sources, and review recent transactions.
Source: Security Affairs
Attackers Abuse Google Cloud Application Integration to Send Convincing Phish
Threat actors are impersonating Google‑generated notifications by abusing Google Cloud’s Application Integration service to send emails from legitimate Google infrastructure. The campaign’s use of trusted domains and multi‑stage delivery can bypass basic sender checks, reinforcing the need for robust content analysis, user training, and conditional access controls.
Source: The Hacker News
CISA KEV Grew 20% in 2025, With 245 New Exploited Bugs—24 Tied to Ransomware
CISA added 245 vulnerabilities to its Known Exploited Vulnerabilities catalog in 2025, bringing the total to 1,484 and marking a notable acceleration over prior years. Twenty-four of the additions are linked to ransomware operations, providing a clear, prioritized patching roadmap for defenders heading into 2026.
Source: Cyble
European Space Agency Confirms Breach of External Servers, Possible 200GB Exfil
The European Space Agency confirmed attackers breached external servers, with up to 200GB potentially stolen, including credentials and source code. The incident raises downstream risk for partners and projects relying on ESA code or access; immediate credential resets and dependency reviews are prudent.
Source: CyberNews
You May Also Be Interested In...
How AI made scams more convincing in 2025 (Malwarebytes)Researchers expose another malicious browser extension campaign affecting millions (CyberNews)
Covenant Health Data Breach Impacts 478,000 Individuals (SecurityWeek)