Cybersecurity News | Daily Recap [31 Dec 2025]

Daily Recap, critical patch notices hit IBM API Connect with an authentication bypass that could expose protected services, and a critical SmarterMail flaw (CVE-2025-52691) enabling unauthenticated RCE on vulnerable servers, with CISA ordering patches for the MongoBleed flaw following observed intrusions that affected Oracle EBS deployments including Korean Air and the University of Phoenix. The European Space Agency confirmed a breach of external servers, Disney agreed to pay $10 million to settle child data privacy claims related to YouTube content, two ALPHV/BlackCat ransomware operators pleaded guilty, and new info-stealers and malvertising campaigns—ErrTraffic, Lumma, Vidar, Cerberus, and Zoom Stealer—illustrate ongoing threat activity, alongside Intellexa Predator sanctions being reversed. #IBMAPIConnect #CVE2025_52691 #MongoBleed #OracleEBS #KoreanAir #UniversityofPhoenix #EuropeanSpaceAgency #Disney #ALPHV #BlackCat #ErrTraffic #Lumma #Vidar #Cerberus #ZoomStealer #Intellexa #Predator

Read More
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

The U.S. Department of the Treasury has removed three individuals linked to the Intellexa Consortium from the sanctions list, raising questions about the reasons for their removal. The Predator spyware, associated with these individuals, continues to pose significant security risks and has been used against civil society globally. #Intellexa #PredatorSpyware…

Read More
ENISA Threat Landscape 2025

The ENISA Threat Landscape 2025 report provides a comprehensive analysis of the European cyber threat environment between July 2024 and June 2025, highlighting phishing as the primary intrusion vector and the increasing sophistication of ransomware, state-aligned cyberespionage, and hacktivist activities. It emphasizes emerging trends such as the targeting of mobile devices, supply chain compromises, and the convergence of tactics among threat groups. #ENISAThreatLandscape2025 #Phishing #Ransomware #StateAlignedThreats #Hacktivism #SupplyChainAttacks

Read More
Academic Ambush: How the Forum Troll APT Hijacks Scholars’ Systems via Fake Plagiarism Reports

A cyber espionage group called “Forum Troll” has shifted its focus from corporate networks to targeting Russian political scientists and economists through sophisticated phishing campaigns. This campaign featured personalized social engineering and utilized known commercial red-teaming tools to infiltrate high-profile individuals. #ForumTroll #RussianAcademics…

Read More
Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports

Operation ForumTroll conducted targeted phishing against Russian academics in October 2025 using a spoofed e-library domain to deliver a PowerShell-based downloader and an OLLVM-obfuscated DLL loader. The final payload deployed the commercial Tuoni framework and used COM Hijacking for persistence, with C2 infrastructure on fastly.net. #ForumTroll #Tuoni

Read More
New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Operation ForumTroll is a sophisticated phishing campaign targeting individuals in Russia, utilizing zero-day Chrome vulnerabilities to deliver backdoors and spyware. The campaign features personalized emails and uses strategically aged domains to avoid detection, with ongoing threats observed since 2022. #OperationForumTroll #LeetAgent #Dante #Tuoni…

Read More
New 0 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

A new Android remote access trojan called Cellik offers extensive surveillance and control features, including real-time screen streaming, keylogging, and data theft. It is sold on the dark web for $150 per month, enabling cybercriminals to bundle malicious payloads into legitimate apps and conduct advanced attacks. #Cellik #AndroidRAT #DarkWebThreats…

Read More

Parked and lookalike domains are increasingly weaponized via “direct search” parking and complex traffic distribution systems (TDS) to funnel real users to scams, scareware, spyware, and malware while presenting benign pages to scanners. The report details three distinct domain portfolio actors and examples of delivered threats, including infections by Tedy and typosquats targeting Scotiabank users. #Tedy #Scotiabank

Read More
Frogblight threatens you with a court case: a new Android banker targets Turkish users

Frogblight is a newly discovered Android banking Trojan targeting mainly users in Turkey that was first disguised as a government court-case app and later appeared as a fake Chrome browser. The malware captures banking credentials via WebView JavaScript injection, collects SMS, app and filesystem data, communicates with C2 servers over REST and WebSocket, and shows signs of active development and possible MaaS distribution. #Frogblight #Turkey

Read More
NexusRoute: Attempting to Disrupt an Indian Government Ministry – CYFIRMA

The NexusRoute campaign is a large-scale, professionally maintained Android malware and phishing operation that impersonates Indian Government services (mParivahan / e-Challan), distributes malicious APKs via GitHub repositories/GitHub Pages, and operates mass phishing domains to steal UPI, card, and banking credentials. Technical analysis shows a native-backed multi-stage RAT with dynamic code loading, SMS interception, persistence via BroadcastReceivers and foreground services, Socket.IO C2 at 154.61.80.242, and OSINT links to a commercial Android obfuscation/surveillance tooling ecosystem. #NexusRoute #mParivahan

Read More