Intel Encyclopedia
33 subscribers
3.15K links
Daily Cybersecurity feeds
Download Telegram
Vulnerabilities & Exploits

Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide



Summary:
Torrance, United States / California, December 12th, 2025, CyberNewsWire In December 2025, CVE-2025-55182 (React2Shell), a vulnerability in React Server Components (RSC) that enables remote code execution (RCE), was publicly disclosed. Shortly after publication, multiple security vendors reported scanning activity and suspected exploitation attempts, and CISA has since added the flaw to its Known Exploited Vulnerabilities […]
The post Critical React2Shell Vulnerability (CVE-2025-55182)...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-12-12 15:41 | Author: CyberNewswire

#react2shell #vulnerabilities__exploits #critical

https://gbhackers.com/critical-react2shell-vulnerability-cve-2025-55182-analysis-surge-in-attacks-targeting-rsc-enabled-services-worldwide/
Threat Intelligence

New JSCEAL Infostealer Malware Targets Windows Systems to Steal Login Credentials



Summary:
A sophisticated information-stealing tool known as JSCEAL has evolved significantly in recent months, deploying advanced anti-analysis techniques and hardened command-and-control infrastructure to target users of cryptocurrency applications on Windows systems. Security researchers from Cato CTRL discovered the enhanced malware variant during an active campaign that began in August 2025, marking a substantial shift in the […]
The post New JSCEAL Infostealer Malware Targets Windows Systems...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-12-12 13:10 | Author: Mayura Kathir

#threat_intelligence #infostealer #jsceal

https://gbhackers.com/jsceal-infostealer-malware/
General Cyber News

MITRE Unveils 2025’s Top 25 Most Dangerous Software Weaknesses



Summary:
MITRE has released its annual Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list for 2025, identifying the most critical vulnerabilities affecting software development worldwide. The comprehensive analysis draws from over 39,080 CVE records, providing security professionals and developers with actionable intelligence to strengthen their defenses. MITRE 2025 list reveals significant shifts in the vulnerability […]
The post MITRE Unveils 2025’s Top 25 Most...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-12-12 12:56 | Author: Divya

#unveils #general_cyber_news #mitre

https://gbhackers.com/mitre-unveils-2025s-top-25-most-dangerous-software-weaknesses/
Threat Intelligence

Research Findings on the Fate of Data Stolen in Phishing Attacks



Summary:
New research from Kaspersky has mapped the complete lifecycle of data stolen during phishing attacks, revealing a sophisticated “shadow market conveyor belt” where victim information is instantly commoditized. The analysis traces the digital trail from the initial click on a fraudulent link to the eventual sale of credentials on dark web markets, highlighting how automated […]
The post Research Findings on the Fate of Data Stolen in Phishing Attacks appeared first on GBHackers...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-12-12 12:28 | Author: Mayura Kathir

#findings #threat_intelligence #research

https://gbhackers.com/phishing-attacks/
Vulnerabilities & Exploits

Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priority



Summary:
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 40 open-source tools redefining how security teams secure the stack Open source security software has become a key way for teams to get flexibility, transparency, and capability without licensing costs. The free tools in this roundup address problems security teams deal with, from managing large environments to catching misconfigurations and understanding how new technologies change threat...



Source: Help Net Security
Published: 2025-12-14 09:00 | Author: Help Net Security

#week #review #vulnerabilities__exploits

https://www.helpnetsecurity.com/2025/12/14/week-in-review-40-open-source-tools-securing-the-stack-invisible-it-to-be-the-next-workplace-priority/
Vulnerabilities & Exploits

ImmuniWeb enhances AI vulnerability testing and compliance reporting



Summary:
ImmuniWeb has unveiled a major update to its ImmuniWeb AI Platform, based on ongoing research as well as valuable feedback from customers and partners in over 50 countries. This cumulative Q4 update builds on the Q3 update announced in early October. Most Q4 improvements focus on security testing for AI-specific vulnerabilities and weaknesses in web and mobile applications, as well as enhanced testing and reporting for regulatory and compliance purposes. The update also combines detection...



Source: Help Net Security
Published: 2025-12-12 13:45 | Author: Industry News

#enhances #immuniweb #vulnerabilities__exploits

https://www.helpnetsecurity.com/2025/12/12/immuniweb-ai-platform-update/
General Cyber News

Swissbit adds HID Seos to iShield Key 2



Summary:
Swissbit is expanding its portfolio of multi-application security keys with the launch of the iShield Key 2, introducing a new variant featuring HID Seos, one of the most widely used credential technologies for physical access control. Following the addition of MIFARE DESFire EV3, Swissbit now supports another major global standard, offering customers a single token that unifies phishing-resistant digital authentication and secure physical access. HID Seos is deployed in numerous access systems...



Source: Help Net Security
Published: 2025-12-12 08:50 | Author: Industry News

#adds #general_cyber_news #swissbit

https://www.helpnetsecurity.com/2025/12/12/swissbit-hid-seos/
Network Security

Firewalla Orange brings zero trust anywhere



Summary:
Firewalla announced Firewalla Orange, a portable multi-gigabit cybersecurity firewall and Wi-Fi 7 router designed to reset expectations for how networks should be protected. Firewalla Orange delivers more than 2 gigabits of packet processing performance and brings enterprise grade zero trust security to both stationary and mobile environments in a form factor small enough to fit in a jacket pocket. Firewalla Orange challenges the idea that serious network protection must stay bolted to a desk...



Source: Help Net Security
Published: 2025-12-12 08:40 | Author: Industry News

#orange #network_security #firewalla

https://www.helpnetsecurity.com/2025/12/12/firewalla-orange/
Data Security & Privacy

What 35 years of privacy law say about the state of data protection



Summary:
Privacy laws have expanded around the world, and security leaders now work within a crowded field of requirements. New research shows that these laws provide stronger rights and duties, but the protections do not always translate into reductions in harm. The study looks at thirty five years of privacy history, from the rise of early data protection efforts to the current landscape of AI driven risk, cross border transfers, and uneven enforcement. The researchers from … More →
The...



Source: Help Net Security
Published: 2025-12-12 07:00 | Author: Anamarija Pogorelec

#years #data_security__privacy #what

https://www.helpnetsecurity.com/2025/12/12/global-privacy-enforcement-trends-research/
Data Security & Privacy

LLM privacy policies keep getting longer, denser, and nearly impossible to decode



Summary:
People expect privacy policies to explain what happens to their data. What users get instead is a growing wall of text that feels harder to read each year. In a new study, researchers reviewed privacy policies for LLMs and traced how they changed. Policies keep getting longer Researchers looked at privacy policies from 11 providers and tracked 74 versions over several years. The average policy reached about 3,346 words, which is about 53 percent longer … More →
The post LLM privacy...



Source: Help Net Security
Published: 2025-12-12 06:30 | Author: Sinisa Markovic

#data_security__privacy #policies #privacy

https://www.helpnetsecurity.com/2025/12/12/llms-privacy-policies-study/
Threat Intelligence

Ransomware keeps widening its reach



Summary:
Ransomware keeps shifting into new territory, pulling in victims from sectors and regions that once saw fewer attacks. The latest Global Threat Briefing for H2 2025 from CyberCube shows incidents spreading in ways that make it harder for security leaders to predict where threats will rise next. Researchers evaluated incident patterns, sector level exposure and signals drawn from threat actor behavior. Their aim was to map where ransomware is spreading, which organizations sit in higher …...



Source: Help Net Security
Published: 2025-12-12 06:00 | Author: Anamarija Pogorelec

#threat_intelligence #keeps #ransomware

https://www.helpnetsecurity.com/2025/12/12/global-ransomware-trends-2025/
General Cyber News

Uneven regulatory demands expose gaps in mobile security



Summary:
Mobile networks carry a great deal of the world’s digital activity, which makes operators a frequent target for attacks. A study released by the GSMA shows that operators spend between $15 and $19 billion a year on core cybersecurity functions. Spending could reach more than $40 billion by 2030. These figures do not include expenses tied to resilience, training, or governance. Rising attack volumes test mobile network security Security teams face attack volumes that exceed … More...



Source: Help Net Security
Published: 2025-12-12 05:30 | Author: Anamarija Pogorelec

#regulatory #general_cyber_news #uneven

https://www.helpnetsecurity.com/2025/12/12/gsma-mobile-network-security-pressures-report/
General Cyber News

New infosec products of the week: December 12, 2025



Summary:
Here’s a look at the most interesting products from the past week, featuring releases from Apptega, Backslash Security, BigID, Black Kite, Bugcrowd, NinjaOne, Nudge Security, and Veza. Apptega Policy Manager streamlines policy creation and compliance oversight Apptega revealed its Policy Manager module, expanding the company’s platform to automate the creation, review, and oversight of custom business policies. With this enhancement, Apptega enables partners and in-house security and compliance...



Source: Help Net Security
Published: 2025-12-12 05:00 | Author: Anamarija Pogorelec

#infosec #products #general_cyber_news

https://www.helpnetsecurity.com/2025/12/12/new-infosec-products-of-the-week-december-12-2025/
General Cyber News

I stopped using Google and Apple’s password managers, here’s what I use instead



Summary:
It's time to move to a proper password manager.



Source: How-To Geek - Cybersecurity
Published: 2025-12-12 14:01 | Author: Patrick Campanale

#stopped #using #general_cyber_news

https://www.howtogeek.com/why-you-shouldnt-use-google-or-apples-password-managers/
General Cyber News

What New Changes Are Coming to FedRAMP in 2026?



Summary:
One thing is certain: every year, the cybersecurity threat environment will evolve. AI tools, advances in computing, the growth of high-powered data centers that can be weaponized, compromised IoT networks, and all of the traditional vectors grow and change. As such, the tools and frameworks we use to resist these attacks will also need to […]



Source: Ignyte
Published: 2025-12-12 22:40 | Author: Max Aulakh

#what #general_cyber_news #changes

https://www.ignyteplatform.com/blog/fedramp/new-changes-fedramp-2026/
General Cyber News

Wireshark 4.6.2 Released, (Sun, Dec 14th)



Summary:
Wireshark release 4.6.2 fixes 2 vulnerabilities and 5 bugs.



Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-12-14 16:07

#released #wireshark #general_cyber_news

https://isc.sans.edu/diary/rss/32568
General Cyber News

ClickFix Attacks Still Using the Finger, (Sat, Dec 13th)



Summary:
Introduction



Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-12-13 19:35

#clickfix #attacks #general_cyber_news

https://isc.sans.edu/diary/rss/32566
General Cyber News

Abusing DLLs EntryPoint for the Fun, (Fri, Dec 12th)



Summary:
In the Microsoft Windows ecosystem, DLLs (Dynamic Load Libraries) are PE files like regular programs. One of the main differences is that they export functions that can be called by programs that load them. By example, to call RegOpenKeyExA(), the program must first load the ADVAPI32.dll. A PE files has a lot of headers (metadata) that contain useful information used by the loader to prepare the execution in memory. One of them is the EntryPoint, it contains the (relative virtual) address where...



Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-12-12 05:08

#abusing #general_cyber_news #dlls

https://isc.sans.edu/diary/rss/32562
General Cyber News

ISC Stormcast For Friday, December 12th, 2025 https://isc.sans.edu/podcastdetail/9736, (Fri, Dec 12th)



Summary:
No Description



Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-12-12 02:00

#stormcast #friday #general_cyber_news

https://isc.sans.edu/diary/rss/32560
General Cyber News

LW ROUNDTABLE Part 2: Mandates surge, guardrails lag — intel from the messy middle



Summary:
Regulators made their move in 2025.
Disclosure deadlines arrived. AI rules took shape. Liability rose up the chain of command. But for security teams on the ground, the distance between policy and practice only grew wider.
Part two of a … (more…)
The post LW ROUNDTABLE Part 2: Mandates surge, guardrails lag — intel from the messy middle first appeared on The Last Watchdog.



Source: The Last Watchdog
Published: 2025-12-12 19:06 | Author: bacohido

#part #general_cyber_news #roundtable

https://www.lastwatchdog.com/lw-roundtable-part-2-mandates-surge-guardrails-lag-intel-from-the-messy-middle/