Check Point data reveals a 60% increase in ransomware attacks, with North America and Europe being the primary targets. The rise in enterprise Gen AI use has also exposed sensitive data. In 2025, ransomware attacks stood out for their volume, scale, and damage. The December 2025 Global Cyber Attack Statistics …
Read More »Hackers to exploit critical Fortinet FortiSIEM flaw in attacks
A critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code is now being abused in attacks. Security researcher Zach Hanley from Horizon3.ai reported vulnerability CVE-2025-64155, which combines two issues that enable arbitrary writes with admin permissions and privilege escalation to root access. “An improper neutralization of special elements used …
Read More »CastleLoader Malware To Attack US Government Agencies and Critical Infra
A dangerous malware loader dubbed CastleLoader poses a serious risk to US government agencies and critical infrastructure. First detected in early 2025, it has been used to gain initial access in coordinated attacks on federal agencies, IT firms, logistics companies, and essential infrastructure in North America and Europe. Security researchers …
Read More »Instagram data leak reveals sensitive info of 17.5M accounts
A major security breach has affected about 17.5 million Instagram accounts, revealing private information now found on the dark web. The recent incident reported by Malwarebytes has raised severe concerns about user privacy and account security. The breach involves significant personal information that poses risks to users. Affected data includes …
Read More »Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
Hackers reportedly used a compromised SonicWall VPN appliance to gain access and deploy a VMware ESXi exploit, possibly created as early as February 2024. Huntress, a cybersecurity firm, detected activity in December 2025 and halted it before it escalated into a ransomware attack. The attack likely took advantage of three …
Read More »BlueDelta Target Sophos VPN, Google, Microsoft OWA to Steal Credentials
BlueDelta conducted a complex credential-harvesting operation targeting critical infrastructure and research institutions in 2025, as revealed by an investigation from Recorded Future’s Insikt Group. The campaigns leveraged legitimate PDF documents as bait, including publications from the Gulf Research Center titled “Strategic and Political Implications for Israel and Iran: The Day …
Read More »BTRC NEIR face 2.4 million bot traffic in a minute
BTRC’s National equipment identity register (NEIR) Citizen Portal is under attack by 2.4 million bot traffic in a minute. The attackers have been carrying out this attack intermittently since Friday morning. Aminul Bari Shuvro, Chief Solution Officer of Synesis IT (responsible for NEIR) said that forty thousand bot traffic hit …
Read More »2025: Top cybersecurity and cyberattack stories
The cybersecurity landscape in 2025 saw an increase in the scale and sophistication of cyber threats. Nation-states, organized crime, and hybrid groups blurred the lines between espionage and financial crime, while supply chain weaknesses and social engineering became major attack methods. Massive data theft targeting cloud platforms like Salesforce exposed …
Read More »RondoDox botnet uses React2Shell flaw to breach Next.js servers
The RondoDox botnet is using the serious React2Shell vulnerability (CVE-2025-55182) to infect unprotected Next.js servers with malware and cryptominers. RondoDox, a large-scale botnet first reported by Fortinet in July 2025, targets various n-day vulnerabilities in global attacks. In November, VulnCheck discovered new variants of RondoDox that exploit the critical remote …
Read More »Korean Air thousands of employees’ personal info leaked
Employee data at Korean Air, South Korea’s largest airline, was leaked following a cyberattack on a partner firm that provides in-flight meals and onboard services, industry sources reported on Monday. According to the sources, Korean Air issued an internal notice earlier in the day informing employees that KC&D, the airline’s …
Read More »
InfoSecBulletin Cybersecurity for mankind