Breaking News – Cyber Threats (last 6h)
Generated: 2025-12-10 16:00 PST
- Google ads for shared ChatGPT, Grok guides push macOS infostealer malware
BleepingComputer • 2025-12-10 15:50 • www.bleepingcomputer.com
A new AMOS infostealer campaign is abusing Google search ads to lure users into Grok and ChatGPT conversations that appear to offer “helpful” instructions but ultimately lead to installing the AMOS info-stealing malware on macOS. […]
https://www.bleepingcomputer.com/news/security/google-ads-for-shared-chatgpt-grok-guides-push-macos-infostealer-malware/ - New DroidLock malware locks Android devices and demands a ransom
BleepingComputer • 2025-12-10 13:53 • www.bleepingcomputer.com
A new Android malware called DroidLock has emerged with capabilities to lock screens for ransom payments, erase data, access text messages, call logs, contacts, and audio data. […]
https://www.bleepingcomputer.com/news/security/new-droidlock-malware-locks-android-devices-and-demands-a-ransom/ - React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors
The Hacker News • 2025-12-10 12:19 • thehackernews.com
React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of previously undocumented malware families, according to new findings from Huntress.
This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel named CowTunnel, and a Go-based
https://thehackernews.com/2025/12/react2shell-exploitation-delivers.html - Microsoft Teams to warn of suspicious traffic with external domains
BleepingComputer • 2025-12-10 11:32 • www.bleepingcomputer.com
Microsoft is working on a new Teams security feature that will analyze suspicious traffic with external domains to help IT administrators tackle potential security threats. […]
https://www.bleepingcomputer.com/news/security/microsoft-teams-to-warn-of-suspicious-traffic-with-external-domains/ - .NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL
The Hacker News • 2025-12-10 11:21 • thehackernews.com
New research has uncovered exploitation primitives in the .NET Framework that could be leveraged against enterprise-grade applications to achieve remote code execution.
WatchTowr Labs, which has codenamed the “invalid cast vulnerability” SOAPwn, said the issue impacts Barracuda Service Center RMM, Ivanti Endpoint Manager (EPM), and Umbraco 8. But the number of affected vendors is likely to be
https://thehackernews.com/2025/12/net-soapwn-flaw-opens-door-for-file.html - Over 10,000 Docker Hub images found leaking credentials, auth keys
BleepingComputer • 2025-12-10 10:22 • www.bleepingcomputer.com
More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys. […]
https://www.bleepingcomputer.com/news/security/over-10-000-docker-hub-images-found-leaking-credentials-auth-keys/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
