Breaking News – Cyber Threats (last 6h)
Generated: 2025-12-19 12:00 PST
- Nigeria arrests dev of Microsoft 365 'Raccoon0365' phishing platform
BleepingComputer • 2025-12-19 11:05 • www.bleepingcomputer.com
The Nigerian police have arrested three individuals linked to targeted Microsoft 365 cyberattacks via Raccoon0365 phishing-as-a-service. […]
https://www.bleepingcomputer.com/news/security/nigeria-arrests-dev-of-microsoft-365-raccoon0365-phishing-platform/ - Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers
The Hacker News • 2025-12-19 09:54 • thehackernews.com
A suspected Russia-aligned group has been attributed to a phishing campaign that employs device code authentication workflows to steal victims’ Microsoft 365 credentials and conduct account takeover attacks.
The activity, ongoing since September 2025, is being tracked by Proofpoint under the moniker UNK_AcademicFlare.
The attacks involve using compromised email addresses belonging to government
https://thehackernews.com/2025/12/russia-linked-hackers-use-microsoft-365.html - Microsoft 365 accounts targeted in wave of OAuth phishing attacks
BleepingComputer • 2025-12-19 09:19 • www.bleepingcomputer.com
Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism. […]
https://www.bleepingcomputer.com/news/security/microsoft-365-accounts-targeted-in-wave-of-oauth-phishing-attacks/ - New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
BleepingComputer • 2025-12-19 07:54 • www.bleepingcomputer.com
The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections. […]
https://www.bleepingcomputer.com/news/security/new-uefi-flaw-enables-pre-boot-attacks-on-motherboards-from-gigabyte-msi-asus-asrock/ - Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
The Hacker News • 2025-12-19 07:34 • thehackernews.com
Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as CountLoader.
The campaign “uses CountLoader as the initial tool in a multistage attack for access, evasion, and delivery of additional malware families,” Cyderes Howler Cell Threat Intelligence
https://thehackernews.com/2025/12/cracked-software-and-youtube-videos.html - Dismantling Defenses: Trump 2.0 Cyber Year in Review
KrebsOnSecurity • 2025-12-19 07:14 • krebsonsecurity.com
The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum of technology challenges, from cybersecurity and privacy to countering disinformation, fraud and corruption. These shifts, along with the president’s efforts to restrict free speech and freedom of the press, have come at such a rapid clip that many readers probably aren’t even aware of them all.
https://krebsonsecurity.com/2025/12/dismantling-defenses-trump-2-0-cyber-year-in-review/ - Over 25,000 FortiCloud SSO devices exposed to remote attacks
BleepingComputer • 2025-12-19 07:00 • www.bleepingcomputer.com
Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. […]
https://www.bleepingcomputer.com/news/security/over-25-000-forticloud-sso-devices-exposed-to-remote-attacks/ - Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
BleepingComputer • 2025-12-19 06:30 • www.bleepingcomputer.com
Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface monitoring platform developed by AI SPERA, is now officially integrated into Palo Alto Networks’ Cortex XSOAR. […]
https://www.bleepingcomputer.com/news/security/criminal-ip-and-palo-alto-networks-cortex-xsoar-integrate-to-bring-ai-driven-exposure-intelligence-to-automated-incident-response/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
