
Hello all,
To my United States’ audience, welcome back after a long and hopefully uneventful weekend. I pray that it was good and restful. To all of us, welcome to December. The past week seemed to be a bit quieter, thankfully. However, there was still plenty of news to report on and some major things to be aware of and take appropriate action on.
Headline NEWS:
- ASUS warns of new critical auth bypass flaw in AiCloud routers. Nine vulnerabilities were plugged in unspecified AiCloud routers. At least one of these vulnerabilities could enable remote code execution on the router without authentication. If you use any ASUS router, you are advised by the company to update immediately to the latest version.
- CrowdStrike fires ‘suspicious insider’ who passed information to hackers. This story is unfortunately one that is growing. Threat actors are having an increasingly difficult time breaching networks in traditional ways due to better security practices. They’ve always attempted to recruit insiders to provide passwords or install malware, and some take them up on the promise of easy money, but new trends in evil have Threat Actors reaching out and threatening insiders with all sorts of evil. Some have sent potential insiders pictures of their homes, children, and more. This is escalating in very dangerous ways.
- Firefox patched a critical defect. Update to the latest version as soon as you’re able if you don’t have automatic updates enabled already. This defect in their WebAssembly (Wasm) engine can allow for memory corruption and subsequent arbitrary code execution.
In Ransomware, Malware, and Vulnerabilities News:
- JPMorgan, Citi, Morgan Stanley assess fallout from SitusAMC data breach. I suspect that this is a data breach that will have wide-ranging implications for hundreds of thousands of consumers. It was first detected on November 12 and became public knowledge on November 25 when notices started arriving to lenders serviced by SitusAMC. There are a lot more than the three mentioned in the headline. The amount and type of information that is likely now in a threat actor’s hands is quite broad. As reported by CSO magazine, “The company’s role in mortgage processing involves handling extensive personal information, including Social Security numbers, financial account details, and employment records, as found on loan applications.” This is a massive treasure trove that has just been pillaged.
In Other News Events of Note and Interest:
- The race to regulate AI has sparked a federal vs state showdown. Thankfully, Federal Law supersedes State Law. Unfortunately, in the case of AI, the Fed has been remiss in timely addressing proper governance of AI, so states have rightfully taken it upon themselves to pass a hodgepodge of laws to safeguard their citizens. Twenty-eight states already have around 100 laws that are attempting to regulate AI in areas of child safety, deepfakes, notifications, and similar. I vehemently disagree with those that say this is a state matter. You cannot operate in a global internet and somehow be expected to adhere to a patchwork quilt of laws that depend on which state your consumer is based in. The sheer amount of machination required to tool for the geopolitics and the ever-changing laws would be very innovation stifling, if not killing. A company’s most logical option would be to adopt the most restrictive policies so they don’t run afoul of the law. We need a unified national, overarching legal framework and standard for AI governance. And we need it yesterday.
Musings:
I ate, a lot, and then I needed a nap. Thankfully the world didn’t blow up while I was passed out this Thursday. Twenty-three days from Monday, if you celebrate Christmas, it is a do-over. Yum.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- ASUS warns of new critical auth bypass flaw in AiCloud routers
- CrowdStrike fires ‘suspicious insider’ who passed information to hackers
- Update Firefox to Patch CVE-2025-13016 Vulnerability Affecting 180 Million Users
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
- CISA orders feds to patch Oracle Identity Manager zero-day
- CISA: Spyware crews breaking into Signal, WhatsApp accounts
- House panel prepares to take up kids’ online safety bills
- AI fraud bill seeks to criminalize deepfakes of federal officials
- Myanmar state television broadcasts army crackdown on scam centers
- APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods
- GreyNoise launches free scanner to check if you’re part of a botnet
- US emergency alert systems down after cyberattack
- Vulnerabilities and Exploits
- We stopped roadmap work for a week and fixed 189 bugs
- New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request
- Atlassian’s DR simulation showed it lived in dependency hell
- Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update
- ToddyCat APT evolves to target Outlook archives and Microsoft 365 tokens
- How to know if your Asus router is one of thousands hacked by China-state hackers
- Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs
- HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials
- HashJack – First Known Indirect Prompt Injection
- Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet
- Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges
- NPM packages are infected with malware, again
- Shai-Hulud, The Second Coming – Ongoing npm supply chain attack
- Shai-Hulud Returns: Over 1K NPM Packages and 27K+ Github Repos infected via Fake Bun Runtime Within Hours
- Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets
- Wormable npm attack returns as 25,000 repos spill secrets
- GitLab discovers widespread npm supply chain attack
- This tiny Windows shortcut file is a bigger security threat than you think
- Anthropic’s new Claude Opus 4.5 model is focused on improving AI agents but still faces cybersecurity concerns
- Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper
- FBI: Cybercriminals stole $262M by impersonating bank support teams
- Bug in jury systems used by several US states exposed sensitive personal data
- Phishing, Malware, and similar
- Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials
- ClickFix attack uses fake Windows Update screen to push malware
- Microsoft cracks down on malicious meeting invites
- Malicious Blender model files deliver StealC infostealing malware
- Advanced Security Isn’t Stopping Old Phishing Tactics
- DPRK’s FlexibleFerret Tightens macOS Grip
- New ShadowV2 botnet malware used AWS outage as a test opportunity
- Amazon warns customers of holidays cyberattacks as FBI sees $300M in thefts
- Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks
- ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access
- JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers
- Lifetime access to WormGPT 4 costs just $220
- How NTLM is being abused in 2025 cyberattacks
- RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware
- WormGPT 4 and KawaiiGPT: New Dark LLMs Boost Cybercrime Automation
- New EtherHiding Attack Uses Web-Based Attacks to Deliver Malware and Rotate Payloads
- Breaches, Leaks, and Ransomware
- US banks scramble to assess data theft after hackers breach financial tech firm
- Wall Street on high alert after massive vendor cyberattack compromises Mortgage Data at JPMorgan, Citi and Morgan Stanley
- JPMorgan, Citi, Morgan Stanley assess fallout from SitusAMC data breach
- OpenAI discloses API customer data breach via Mixpanel vendor hack
- Code-formatters expose thousands of secrets from banks, govt, tech orgs
- Code beautifiers expose credentials from banks, govt, tech orgs
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert
- Gainsight CEO promises transparency as it responds to compromise of Salesforce integration
- Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
- 146,000 Impacted by Delta Dental of Virginia Data Breach
- Brsk confirms breach as bidding begins for 230K+ records
- Ransomware attack infiltrates village of Golf Manor’s internal computer network
- Iberia discloses customer data leak after vendor security breach
- Harvard University discloses data breach affecting alumni, donors
- Dartmouth College confirms data breach after Clop extortion attack
- Clop’s Oracle EBS rampage reaches Dartmouth College
- Mazda Says No Data Leakage or Operational Impact From Oracle Hack
- Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack
- Canon Says Subsidiary Impacted by Oracle EBS Hack
- OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide
- Georgia court filing organization warns of outages after ransomware allegations
- Multiple London councils’ IT systems disrupted by cyberattack
- Multiple London councils report disruption amid ongoing cyberattack
- Scottish council still reeling from 2023 ransomware attack
- Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist
- Akira Ransomware Uses SonicWall VPN Exploit to Exfiltrate Sensitive Data
Other News Events of Note and Interest
- Cool Tool: Copy and paste is basic, but this PowerToys feature makes it brilliant
- Retail chain accidentally sold iPad Airs for $17 – wants them back
- A Couple Of New DOS PCs Appear
- Google’s new ‘Aluminium OS’ project brings Android to PC: Here’s what we know
- Google experts tell the US DOJ selling its ad tech business would be impossible
- Google Just Made Its Sleek New Font Open Source
- Amazon Leo introduces Ultra antenna with 1 Gbps speeds, begins enterprise preview
- Cryptology association lost key needed to run its election
- The unpowered SSDs in your drawer are slowly losing your data
- WebGPU is now supported in major browsers
- The Math of Why You Can’t Focus at Work
- AI, LLM’s, and Skynet
- The race to regulate AI has sparked a federal vs state showdown
- Creativity is human
- AI teddy bear for kids responds with sexual content and advice about weapons
- What OpenAI Did When ChatGPT Users Lost Touch With Reality
- Introducing shopping research in ChatGPT
- Alibaba’s (BABA) Main AI App Qwen Draws 10 Million Downloads in Strong Debut
- Anthropic introduces cheaper, more powerful, more efficient Opus 4.5 model
- Google DeepMind Hires Former CTO of Boston Dynamics as the Company Pushes Deeper Into Robotics
- Google quietly confirms when it’s pulling the plug on Assistant
- Deloitte just got caught again citing fabricated and potentially AI-generated research—this time in a million-dollar report for a Canadian provincial government
- California prosecutors’ office used AI to file inaccurate motion in criminal case
- Bye, Copilot: Microsoft is making Copilot a hands-free experience on Windows
- Amazon Is Using Specialized AI Agents for Deep Bug Hunting
- Microsoft’s latest AI model works offline and controls your computer
- Boston Herald, other papers sue OpenAI, Microsoft
- Alibaba and ByteDance allegedly train Qwen and Doubao LLMs using Nvidia chips, despite export controls
- Microsoft
- Microsoft has open sourced the Zork trilogy of text games
- Microsoft: Windows updates make password login option invisible
- Microsoft Confirms Windows 11 24H2 Update Broken Multiple Core Features
- Microsoft: Windows 11 24H2 bug crashes Explorer and Start Menu
- Microsoft is testing a Windows 11 tweak that preloads File Explorer in the background to make it faster
- Microsoft is speeding up the Teams desktop client for Windows
- Microsoft Teams Update: Calls to Run in Separate Process
- Microsoft is bringing exciting features to Outlook, Teams, Edge, and Copilot
- Microsoft adds tables support to Windows Notepad
- Microsoft warns IT admins against using unsupported .NET runtimes on Windows
- Microsoft: Security keys may prompt for PIN after recent updates
- Microsoft to secure Entra ID sign-ins from script injection attacks
- Nearly 1 billion PCs remain on Windows 10 — Has Windows 11 adoption hit a wall?
- French antitrust watchdog dismisses complaint filed against Microsoft
- On-premises data gateway November 2025 release | Microsoft Fabric Blog
- Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update
- Microsoft unveils Fara-7B, a compact model for running AI-driven computer control locally
