IBM disclosed a CVSS 9.8 authentication bypass in API Connect that could let attackers gain remote access to applications and gateways. Organizations should patch immediately, review access logs for anomalous sessions, rotate credentials and tokens, and limit management interfaces to trusted networks.
Source: Security Affairs
Coordinated attacks hammer Adobe ColdFusion over the holidays
GreyNoise observed thousands of requests targeting a dozen ColdFusion vulnerabilities during the Christmas 2025 period. If you run ColdFusion, prioritize patching, restrict/admin-gate CFIDE and administrative endpoints, and deploy WAF rules to blunt exploit spray-and-pray campaigns.
Source: SecurityWeek
Millions at risk as malicious browser extensions steal meeting data
China-linked group DarkSpectre used 18 rogue extensions across Chrome, Firefox, and Edge to siphon corporate meeting information from 2.2 million users in a “Zoom Stealer” campaign. Enterprises should audit and lock down extension usage, remove suspicious add-ons, and enforce browser policies via MDM.
Source: SC Media
European Space Agency confirms cyberattack on external servers
ESA disclosed that a small number of external servers holding unclassified collaborative engineering data were compromised; attackers claim exfiltration of ~200 GB, including credentials and source code. While systems were not classified, stolen credentials and code could enable follow-on intrusions if not contained.
Source: SC Media
Sedgwick subsidiary serving U.S. federal agencies hit by cyber incident
Claims administration giant Sedgwick confirmed a cybersecurity incident at a subsidiary that contracts with several sensitive federal agencies. Incident scope and data exposure remain under investigation; third-party risk teams should seek impact statements and monitor for downstream exposure.
Source: The Record
Krebs: ‘Kimwolf’ botnet exposes dangerous assumptions about LAN security
A months-long exploitation wave tied to the “Kimwolf” botnet undermines long-held beliefs about the safety of networks behind consumer and SMB routers. The advisory urges immediate hardening of internal networks, segmentation, and east–west monitoring, as perimeter NAT alone no longer provides meaningful protection.
Source: KrebsOnSecurity
APT36 targets Indian government and universities with LNK-based spying campaign
Pakistan-linked Transparent Tribe (APT36) is using weaponized Windows shortcut (LNK) files to compromise Indian government bodies, military-linked organizations, and universities. The long-running espionage actor continues to refine delivery and persistence; defenders should block LNK execution from email and enforce script control policies.
Source: The Record
You May Also Be Interested In...
RondoDox Botnet Exploiting React2Shell Vulnerability
US Among Most Exposed to MongoBleed Intrusions
Treasury Lifts Sanctions for Intellexa-Linked Execs