Breaking News – Cyber Threats (last 6h)
Generated: 2025-12-18 02:00 PST
- Positive trends related to public IP ranges from the year 2025, (Thu, Dec 18th)
SANS ISC Diary (full) • 2025-12-18 00:27 • isc.sans.eduSince the end of the year is quickly approaching, it is undoubtedly a good time to look back at what the past twelve months have brought to us… And given that the entire cyber security profession is about protecting various systems from “bad things†(and we've all correspondingly seen more than our share of the “badâ€), I thought that it might be pleasant to look at a few positive background trends that have accompanied us throughout the year, without us necessarily noticingâ€&…
https://isc.sans.edu/diary/rss/32584 - Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
The Hacker News • 2025-12-17 23:43 • thehackernews.com
The North Korean threat actor known as Kimsuky has been linked to a new campaign that distributes a new variant of Android malware called DocSwap via QR codes hosted on phishing sites mimicking Seoul-based logistics firm CJ Logistics (formerly CJ Korea Express).
“The threat actor leveraged QR codes and notification pop-ups to lure victims into installing and executing the malware on their mobile
https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html - CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
The Hacker News • 2025-12-17 21:01 • thehackernews.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), has been described as an “embedded malicious code vulnerability” introduced by means of a supply chain compromise
https://thehackernews.com/2025/12/cisa-flags-critical-asus-live-update.html - Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
The Hacker News • 2025-12-17 20:10 • thehackernews.com
Cisco has alerted users to a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
The networking equipment major said it became aware of the intrusion campaign on December 10, 2025, and that it
https://thehackernews.com/2025/12/cisco-warns-of-active-attacks.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
