Author: Robert Timlick

  • ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

    ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

    This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from.
    From shifting infrastructures to clever social hooks, the week’s activity shows just how fluid the threat landscape has become.
    Here’s the full rundown of what
  • The Case for Dynamic AI-SaaS Security as Copilots Scale

    The Case for Dynamic AI-SaaS Security as Copilots Scale

    Within the past year, artificial intelligence copilots and agents have quietly permeated the SaaS applications businesses use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow now come with built-in AI assistants or agent-like features. Virtually every major SaaS vendor has rushed to embed AI into their offerings.
    The result is an explosion of AI capabilities across
  • Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

    Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

    The North Korean threat actor known as Kimsuky has been linked to a new campaign that distributes a new variant of Android malware called DocSwap via QR codes hosted on phishing sites mimicking Seoul-based logistics firm CJ Logistics (formerly CJ Korea Express).
    “The threat actor leveraged QR codes and notification pop-ups to lure victims into installing and executing the malware on their mobile
  • CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

    CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
    The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), has been described as an “embedded malicious code vulnerability” introduced by means of a supply chain compromise
  • Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances

    Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances

    Cisco has alerted users of a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
    The networking equipment major said it became aware of the intrusion campaign on December 10, 2025, and that it
  • SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances

    SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances

    SonicWall has rolled out fixes to address a security flaw in Secure Mobile Access (SMA) 100 series appliances that it said has been actively exploited in the wild.
    The vulnerability, tracked as CVE-2025-40602 (CVSS score: 6.6), concerns a case of local privilege escalation that arises as a result of insufficient authorization in the appliance management console (AMC).
    It affects the following
  • APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign

    APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign

    The Russian state-sponsored threat actor known as APT28 has been attributed to what has been described as a “sustained” credential-harvesting campaign targeting users of UKR[.]net, a webmail and news service popular in Ukraine.
    The activity, observed by Recorded Future’s Insikt Group between June 2024 and April 2025, builds upon prior findings from the cybersecurity company in May 2024 that
  • Fix SOC Blind Spots: See Threats to Your Industry & Country in Real Time

    Fix SOC Blind Spots: See Threats to Your Industry & Country in Real Time

    Modern security teams often feel like they’re driving through fog with failing headlights. Threats accelerate, alerts multiply, and SOCs struggle to understand which dangers matter right now for their business. Breaking out of reactive defense is no longer optional. It’s the difference between preventing incidents and cleaning up after them.
    Below is the path from reactive firefighting to a
  • GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads

    GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads

    A new campaign named GhostPoster has leveraged logo files associated with 17 Mozilla Firefox browser add-ons to embed malicious JavaScript code designed to hijack affiliate links, inject tracking code, and commit click and ad fraud.
    The extensions have been collectively downloaded over 50,000 times, according to Koi Security, which discovered the campaign. The add-ons are no longer available.
  • Public shares ICE concerns following Home Depot arrest

    Public shares ICE concerns following Home Depot arrest

    THE DALLES — Concerned community members showed up in droves to The Dalles City Council meeting on Dec. 8, nearly overflowing the council chamber. Many attendees, either representing or supporting the city’s robust Latino community, expressed heartache and anxiety over…