ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories

The beginning of 2026 reveals a landscape of subtle and targeted cyber threats, with hackers evolving their tactics even during holidays. Key incidents include malware scams, exploitation campaigns, and backdoored devices, highlighting the increasing sophistication of cyber adversaries. #KMSAuto #ColdFusionExploitation…

Read More
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers

Cybersecurity experts have revealed a nine-month-long campaign targeting IoT devices and web apps, involving the exploitation of React2Shell vulnerability to build the RondoDox botnet. The campaign progressed through advanced phases, including malware deployment and infection persistence tactics, emphasizing the importance of timely updates and network segmentation. #React2Shell #RondoDox #IoTThreats #NextjsVulnerability…

Read More
BioNet-Asia Targeted in Gentlemen Ransomware Attack

BioNet-Asia has allegedly fallen victim to The Gentlemen ransomware group, which infiltrated their network using advanced evasion techniques to steal sensitive data before encryption. This incident highlights the growing threat of sophisticated cyberattacks targeting healthcare and biotechnology sectors. #TheGentlemen #BioNetAsia #Ransomware #Cyberattack #HealthcareSecurity…

Read More
Poland Calls for EU Investigation of TikTok Over AI-Generated Disinformation Campaign

Poland has formally asked the European Commission to investigate TikTok for failing to properly moderate AI-generated disinformation promoting “Polexit” and threatening democratic stability. The case emphasizes concerns over synthetic media manipulation and TikTok’s obligations under the Digital Services Act. #Polexit #DigitalServicesAct…

Read More
8 Cybersecurity Acquisitions Surpassed  Billion Mark in 2025

In 2025, the cybersecurity industry experienced a record-breaking year with over 420 M&A deals totaling more than $84 billion, including eight deals exceeding $1 billion. Major acquisitions by companies like Google, Palo Alto Networks, and ServiceNow indicate significant consolidation and expansion in the cybersecurity sector. #Wiz #CyberArk #PaloAltoNetworks #ServiceNow #Veeam…

Read More
RondoDoX Botnet Weaponizes React2Shell | CloudSEK

CloudSEK recovered nine months of exposed RondoDoX/Rondo botnet C2 logs that document a three‑phase campaign evolving from reconnaissance and web‑app exploitation to large‑scale IoT botnet deployment and a December 2025 Next.js Server Actions RCE wave. The activity included automated command-injection and deserialization attacks, mass binary downloads (e.g., /nuts/poop) from C2s such as 51.81.104.115 and 5.255.121.141, and repeated exploitation of internet‑facing routers and Next.js servers #Rondo #NextJS

Read More
Deep Dive into Arkanix Stealer and Its Infrastructure – DeXpose

Arkanix Stealer is an actively developed credential‑theft malware family distributed via Discord and forums that exists in both Python and a paid C++ “Premium” edition and uses VMProtect obfuscation, AMSI/ETW bypasses, anti‑VM/debugging checks, ChromElevator process hollowing to defeat App‑Bound Encryption, and HTTP POST exfiltration to arkanix[.]pw. The operators host a gated control panel and expose infrastructure mistakes that reveal origin IPs used for C2 and hosting. #ArkanixStealer #ChromElevator

Read More
ServiceNow to acquire cyber firm Armis in .75 billion deal

ServiceNow is acquiring cybersecurity firm Armis for $7.75 billion to enhance its AI-native cybersecurity and vulnerability response capabilities. This strategic deal reflects ServiceNow’s efforts to stay competitive amid major acquisitions in the cybersecurity industry by companies like Google and Palo Alto Networks. #Armis #ServiceNow #Wiz #CyberArkSoftware #Moveworks…

Read More
Cybersecurity News | Daily Recap [19 Dec 2025]

Daily Recap, major breaches impacted 27,000 University of Sydney records and about 113,000 VA patients, while UK NHS‑linked providers and other government intrusions highlighted a broad cross‑sector threat landscape. The roundup also notes ransomware takedowns like E‑Note, critical exploits from WatchGuard and Cisco AsyncOS, and campaigns such as Kimsuky’s DocSwap Android malware and North Korea–linked crypto theft, plus policy and industry responses shaping defenses. #Kimsuky #DocSwap #NKCryptoTheft #ENote #WatchGuard #CiscoAsyncOS

Read More
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock

This article discusses a UEFI firmware vulnerability in motherboards from ASUS, Gigabyte, MSI, and ASRock that allows DMA attacks, potentially exposing system memory. The issue impacts security protections during early boot and affects systems running certain games like Valorant, with updates from vendors and Riot Games addressing the problem. #UEFIvulnerability #DMAattack #Valorant #Vanguard

Read More
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

A security vulnerability affects certain motherboard models from vendors like ASRock, ASUS, GIGABYTE, and MSI, allowing DMA attacks during the early boot phase due to a failure in configuring IOMMU properly. Patch updates are crucial to fix these issues and prevent potential memory access breaches by malicious peripherals. #ASRock #ASUS #GIGABYTE…

Read More