Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

29/12/2025 0 Comments 0 tags

In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud,

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

29/12/2025 0 Comments 0 tags

A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances identified across the world. The vulnerability in question is

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

27/12/2025 0 Comments 0 tags

A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described

Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code

26/12/2025 0 Comments 0 tags

Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a “security incident” that led to the loss of approximately

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

26/12/2025 0 Comments 0 tags

A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its signature

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

26/12/2025 0 Comments 0 tags

A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large language model (LLM) responses through

ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories

25/12/2025 0 Comments 0 tags

It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking everyday tools, trusted apps, and

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

25/12/2025 0 Comments 0 tags

The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

25/12/2025 0 Comments 0 tags

Fortinet on Wednesday said it observed “recent abuse” of a five-year-old security flaw in FortiOS SSL VPN in the wild under certain configurations. The vulnerability in question is CVE-2020-12812 (CVSS

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

25/12/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of