Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/
https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/
Krebs on Security
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
A prolific cybercriminal group that calls itself "Scattered LAPSUS$ Hunters" made headlines regularly this year by stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for "Rey," the moniker…
U.S. CodeRED Emergency Alert System Down After Ransomware Attack
https://thecyberexpress.com/us-codered-emergency-alert-system-cyberattack/
https://thecyberexpress.com/us-codered-emergency-alert-system-cyberattack/
The Cyber Express
U.S. Emergency Alert System Down After Ransomware Attack
The CodeRED emergency alert system has been disrupted by a cyberattack, and the INC ransomware group is claiming responsibility.
New legislation targets scammers that use AI to deceive
https://cyberscoop.com/new-legislation-targets-scammers-that-use-ai-to-deceive/
https://cyberscoop.com/new-legislation-targets-scammers-that-use-ai-to-deceive/
CyberScoop
New legislation targets scammers that use AI to deceive
Following a rash of AI-assisted impersonations of U.S. officials, the bill would raise the financial and criminal penalties around using the technology to defraud.
Congress calls on Anthropic CEO to testify on Chinese Claude espionage campaign
https://cyberscoop.com/house-homeland-asks-anthropic-ceo-to-testfy-on-chinese-espionage-campaign/
https://cyberscoop.com/house-homeland-asks-anthropic-ceo-to-testfy-on-chinese-espionage-campaign/
CyberScoop
Congress calls on Anthropic CEO to testify on Chinese Claude espionage campaign
The House Homeland Security Committee asked Dario Amodei to answer questions about the implications of the attack and how policymakers and AI companies can respond.
Crisis24 shuts down emergency notification system in wake of ransomware attack
https://cyberscoop.com/crisis24-onsolve-codered-emergency-system-ransomware/
https://cyberscoop.com/crisis24-onsolve-codered-emergency-system-ransomware/
CyberScoop
Crisis24 shuts down emergency notification system in wake of ransomware attack
OnSolve CodeRED was damaged by the attack and has been nonoperational since earlier this month. Dozens of agencies and their respective users have been impacted by the outage and data theft.
GitLab Patch: Fixes CI/CD Credential Theft & Unauthenticated DoS Attacks
https://securityonline.info/gitlab-patch-fixes-ci-cd-credential-theft-unauthenticated-dos-attacks/
https://securityonline.info/gitlab-patch-fixes-ci-cd-credential-theft-unauthenticated-dos-attacks/
Daily CyberSecurity
GitLab Patch: Fixes CI/CD Credential Theft & Unauthenticated DoS Attacks
Critical GitLab updates (18.6.1/18.5.3) fix severe CI/CD credential theft (CVE-2024-9183) & unauthenticated DoS flaws. Upgrade immediately.
Holiday Heist: 200,000 Fake Shops & Amazon Clones Target Black Friday
https://securityonline.info/holiday-heist-200000-fake-shops-amazon-clones-target-black-friday/
https://securityonline.info/holiday-heist-200000-fake-shops-amazon-clones-target-black-friday/
Daily CyberSecurity
Holiday Heist: 200,000 Fake Shops & Amazon Clones Target Black Friday
CloudSEK exposes a massive network of Amazon clones and 200k fake .shop domains targeting Black Friday shoppers. Learn how to spot these holiday scams.
Angular Alert: Protocol-Relative URLs Leak XSRF Tokens (CVE-2025-66035)
https://securityonline.info/angular-alert-protocol-relative-urls-leak-xsrf-tokens-cve-2025-66035/
https://securityonline.info/angular-alert-protocol-relative-urls-leak-xsrf-tokens-cve-2025-66035/
Daily CyberSecurity
Angular Alert: Protocol-Relative URLs Leak XSRF Tokens (CVE-2025-66035)
CVE-2025-66035: Angular protocol-relative URLs leak XSRF tokens, bypassing CSRF protection. Update to v19.2.16, v20.3.14, or v21.0.1 now.
UNMASKED: Massive Leak Exposes Iran’s ‘Department 40’ Cyber-Terror Unit
https://securityonline.info/unmasked-massive-leak-exposes-irans-department-40-cyber-terror-unit/
https://securityonline.info/unmasked-massive-leak-exposes-irans-department-40-cyber-terror-unit/
Daily CyberSecurity
UNMASKED: Massive Leak Exposes Iran's 'Department 40' Cyber-Terror Unit
A massive leak exposes Iran's Department 40 (APT35). Discover how IRGC hackers build target packages for assassination squads and drone strikes.
Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
https://securityonline.info/zero-day-warning-unpatched-twonky-server-flaws-expose-media-to-total-takeover/
https://securityonline.info/zero-day-warning-unpatched-twonky-server-flaws-expose-media-to-total-takeover/
Daily CyberSecurity
Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
Critical alert: Twonky Server suffers unpatched flaws (CVE-2025-13315/16) allowing full takeover. Vendor has no fix; isolate your server immediately.
Hidden Danger in 3D: Malicious Blender Files Unleash StealC V2 Infostealer
https://securityonline.info/hidden-danger-in-3d-malicious-blender-files-unleash-stealc-v2-infostealer/
https://securityonline.info/hidden-danger-in-3d-malicious-blender-files-unleash-stealc-v2-infostealer/
Daily CyberSecurity
Hidden Danger in 3D: Malicious Blender Files Unleash StealC V2 Infostealer
Alert: Malicious Blender files are delivering StealC V2 infostealer. 3D artists downloading from free sites are at risk. Disable auto-run scripts now.
Fragging Your Data: Fake ‘Battlefield 6’ Cracks & Trainers Spread Infostealers
https://securityonline.info/fragging-your-data-fake-battlefield-6-cracks-trainers-spread-infostealers/
https://securityonline.info/fragging-your-data-fake-battlefield-6-cracks-trainers-spread-infostealers/
Daily CyberSecurity
Fragging Your Data: Fake 'Battlefield 6' Cracks & Trainers Spread Infostealers
Cybercriminals are using fake Battlefield 6 cracks and trainers to deploy infostealers. Avoid "InsaneRamZes" & "RUNE" torrents to protect your data.
Water Gamayun Weaponizes “MSC EvilTwin” Zero-Day for Stealthy Backdoor Attacks
https://securityonline.info/water-gamayun-weaponizes-msc-eviltwin-zero-day-for-stealthy-backdoor-attacks/
https://securityonline.info/water-gamayun-weaponizes-msc-eviltwin-zero-day-for-stealthy-backdoor-attacks/
Daily CyberSecurity
Water Gamayun Weaponizes "MSC EvilTwin" Zero-Day for Stealthy Backdoor Attacks
Zscaler reveals Water Gamayun exploiting the MSC EvilTwin zero-day (CVE-2025-26633) via fake hiring lures to deploy stealthy backdoors.
❤1
Critical Ray AI Flaw Exposes Devs via Safari & Firefox (CVE-2025-62593)
https://securityonline.info/critical-ray-ai-flaw-exposes-devs-via-safari-firefox-cve-2025-62593/
https://securityonline.info/critical-ray-ai-flaw-exposes-devs-via-safari-firefox-cve-2025-62593/
Daily CyberSecurity
Critical Ray AI Flaw Exposes Devs via Safari & Firefox (CVE-2025-62593)
Critical Ray AI flaw (CVE-2025-62593) allows RCE via DNS rebinding on Safari & Firefox. Chrome is immune. Update to Ray v2.52.0 immediately.
Hidden Theft: ‘Crypto Copilot’ Chrome Extension Drains Solana Wallets on X
https://securityonline.info/hidden-theft-crypto-copilot-chrome-extension-drains-solana-wallets-on-x/
https://securityonline.info/hidden-theft-crypto-copilot-chrome-extension-drains-solana-wallets-on-x/
Daily CyberSecurity
Hidden Theft: 'Crypto Copilot' Chrome Extension Drains Solana Wallets on X
The malicious 'Crypto Copilot' Chrome extension drains Solana funds from traders on X by injecting hidden transfers. Remove this malware immediately.
Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057)
https://securityonline.info/security-alert-apache-skywalking-stored-xss-vulnerability-cve-2025-54057/
https://securityonline.info/security-alert-apache-skywalking-stored-xss-vulnerability-cve-2025-54057/
Daily CyberSecurity
Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057)
Apache SkyWalking patches a Stored XSS flaw (CVE-2025-54057) affecting versions 10.2.0 and older. Upgrade to v10.3.0 to secure your APM dashboards.
Asahi Group Cyberattack: Data of 2 Million Customers and Employees Potentially Exposed
https://thecyberexpress.com/asahi-group-cyberattack-exposes-records/
https://thecyberexpress.com/asahi-group-cyberattack-exposes-records/
The Cyber Express
Asahi Group Cyberattack Exposes 2 Million Records
Following the Asahi Group cyberattack, the company spent two months containing and restoring essential systems.
OpenAI Confirms Mixpanel Breach Impacting API User Data
https://thecyberexpress.com/openai-mixpanel-security-incident/
https://thecyberexpress.com/openai-mixpanel-security-incident/
The Cyber Express
OpenAI Mixpanel Security Incident Exposes Limited User Data
The OpenAI Mixpanel security incident originated on November 9, 2025, when Mixpanel detected an intrusion into a section of its systems.