• Skamania Co. conference Jan. 10

    Free news: A conference on authoritarianism will be held Saturday, Jan. 10 at Rock Creek Hegewald Center, 710 Rock Creek Drive. A reception begins at 9 a.m., and the program at 10 a.m.

    Read More

  • CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

    The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691, carries a CVSS score of 10.0. It relates to a case of arbitrary file upload that could enable code…

    Read More

  • Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

    The threat actor known as Silver Fox has turned its focus to India, using income tax-themed lures in phishing campaigns to distribute a modular remote access trojan called ValleyRAT (aka Winos 4.0). “This sophisticated attack leverages a complex kill chain involving DLL hijacking and the modular Valley RAT to ensure persistence,” CloudSEK researchers Prajwal Awasthi…

    Read More

  • Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

    The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia. The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by…

    Read More

  • ⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More

    Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A common theme ran through it all in 2025. Attackers moved faster than fixes.…

    Read More

  • MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

    A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances identified across the world. The vulnerability in question is CVE-2025-14847 (CVSS score: 8.7), which allows an unauthenticated attacker to remotely leak sensitive data from the MongoDB server memory. It has been codenamed MongoBleed. “A…

    Read More

  • New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

    A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described as a case of improper handling of length parameter inconsistency, which arises when a program fails to appropriately tackle scenarios where a length field is…

    Read More

  • White Salmon City Council finalizes 2026 budget, legislative priorities and commemorates Jason Hartmann

    WHITE SALMON — City councilors wrapped up end-of-year business on Dec. 17, ratifying the 2026 budget, setting their legislative priorities for Olympia’s upcoming short session and celebrating Councilor Jason Hartmann at his final meeting.

    Read More

  • Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code

    Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a “security incident” that led to the loss of approximately $7 million. The issue, the multi‑chain, non‑custodial cryptocurrency wallet service said, impacts version 2.68. The extension has about one million users, according to the Chrome…

    Read More

  • Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

    A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large language model (LLM) responses through prompt injection. LangChain Core (i.e., langchain-core) is a core Python package that’s part of the LangChain ecosystem, providing the core interfaces and model-agnostic abstractions for…

    Read More