CISA added a critical Broadcom VMware vCenter Server flaw to its Known Exploited Vulnerabilities catalog, citing evidence of in-the-wild attacks. Tracked as CVE-2024-37079 (CVSS 9.8), the heap overflow bug enables unauthenticated remote code execution; patches have been available since June 2024. Enterprises should urgently apply updates and restrict network access to vCenter management interfaces.
Source: The Hacker News
New ‘Osiris’ ransomware uses BYOVD to kill security tools
Researchers observed a new ransomware strain, Osiris, in a November 2025 incident against a major Southeast Asian food service operator. The attackers abused a Bring Your Own Vulnerable Driver (BYOVD) technique via the POORTRY driver to disable security tools before encryption, underscoring the growing trend of kernel-level defenses being targeted. Organizations should enforce driver blocklists and enable features like HVCI/Memory Integrity.
Source: Security Affairs
Sandworm’s ‘DynoWiper’ fails to disrupt Poland’s power sector
Poland said it thwarted what officials called the largest cyberattack against its power system in late December 2025, attributing the operation to Russia’s Sandworm group. The campaign reportedly deployed a new wiper, dubbed DynoWiper, but did not achieve disruption. The attempt highlights continuing OT/ICS targeting and the need for network segmentation, monitoring, and incident response drills across critical infrastructure.
Source: The Hacker News
Nike probes potential breach as ‘WorldLeaks’ threatens data dump
Nike is investigating a possible security incident after the WorldLeaks cybercrime group claimed to have exfiltrated company data. While details remain limited, the group has threatened to leak the information, raising concerns about exposure of sensitive corporate and customer records. Security teams should prepare for downstream brand impersonation and credential stuffing attempts following any data leak.
Source: SecurityWeek
Microsoft handed BitLocker recovery keys to FBI under warrant
Microsoft complied with a legal request to provide BitLocker recovery keys to the FBI, sparking debate about cloud-escrowed encryption keys and lawful access. The case underscores that recovery keys stored in consumer accounts or enterprise tenants can be obtained through legal process. Organizations should review key escrow policies and consider tenant-controlled key management and strict access controls.
Source: The Verge
48 million Gmail usernames and passwords reportedly leaked from infostealer logs
An estimated 48 million Gmail credentials have surfaced online, reportedly aggregated from existing infostealer logs. Even if many are recycled or old, the cache poses a major credential stuffing risk across consumer and enterprise services. Users should change passwords, enable 2FA or passkeys, and avoid reuse across accounts.
Source: Forbes
Multi-stage phishing campaign drops Amnesia RAT and ransomware
Fortinet researchers detail a multi-stage phishing operation targeting users in Russia, starting with seemingly routine business documents. The chain leads to installation of Amnesia RAT for remote control, followed by ransomware deployment. The campaign reinforces the need for layered email defenses, macro restrictions, and behavioral detection of post-compromise activity.
Source: The Hacker News
You May Also Be Interested In...