Cyber Security Week in Review: December 5, 2025
In brief: Critical React2Shell exploited by Chinese hackers, Microsoft silently patches Windows LNK flaw, and more.
In brief: Critical React2Shell exploited by Chinese hackers, Microsoft silently patches Windows LNK flaw, and more.
The latest activity targeted at least two organizations, including Reporters Without Borders (RSF).
The campaign relied on spearphishing emails that delivered PDFs containing links to malicious installers hosted on free file-sharing services.
The campaign ultimately deploys the ValleyRat remote-access tool onto the compromised systems.
Threat actor recruits real engineers willing to act as a figurehead for remote work, offering 20–35% of the salary while DPRK agents secretly perform the job.
The extensions attempt to steal GitHub, npm, and OpenVSX credentials, as well as cryptocurrency wallet data.
This is the first time when Gamaredon was observed conducting destructive attacks rather than traditional espionage operations.
The issue came to light when numerous users reported that Google Play Protect abruptly began blocking SmartTube and flagging it as unsafe.
The operation run in four phases that gradually transformed benign add-ons into powerful spyware.
The malware is delivered via dropper apps spread through social engineering lures.
Showing elements 371 - 380