
Hello all,
Christmas has passed, and the New Year is just around the corner. Based on what I’ve seen, It seems that threat actors and pen testers may have taken a bit of time off. There was significantly less news of vulnerabilities and exploits to report on this week. And even though there was less, there was some, so let’s get to cyber security news.
Headline NEWS:
- Mongobleed is the name given to a critical defect found in the Mongo Database. Update to the latest version to fix this information leakage flaw. If you’re unable to update at this time, then you need to turn off Zlib compression until you’re able to do so. Don’t wait, as Proof of Concept (PoC) exploit code is out in the wild already.
- SonicWall issued a warning to all clients last week to immediately patch their SMA 1000 series devices. This week’s report is that zero-day attacks have been heavily impacting these devices. If you haven’t patched yours yet, do so immediately.
- WatchGuard issued a warning to all clients last week to immediately patch their Firebox firewalls. This week ShadowServer found more than 115,000 vulnerable WatchGuard Firewalls still unpatched on the internet. I don’t get it. If you own an edge device, why are you not subscribed to the vendor’s notices and applying patches as quickly as possible for items this severe? Then again, it is nearly 2026; why is automatic patching not ubiquitous?
In Ransomware, Malware, and Vulnerabilities News:
- FBI, INTERPOL, and US DOJ all achieved some nice wins to close out this year, with fake ID generators being shut down, decryption of ransomware strains and arrests of perpetrators, hundreds of arrests of scammers, arrests in a huge ATM exploitation, seizure of a domain behind bank account takeovers, and the shutdown of a massive stolen password platform. Score a few for the good guys!
In Other News Events of Note and Interest:
- Map reveals which Internet providers are fastest is an article by The Hill that links to the FCC’s newly updated interactive internet speed by map-location chart. It allows you to input your address, and it then shows you what broadband providers service that location, and the maximum offered speed. Thanks to Frontier Fiber coming to my area last year, I was personally able to move from 250/20 to 500/500, and if I want to pay a bit more, I could move up to 7000/7000. It is an excellent resource for yourself and for clients.
Musings:
We made it! The last full week of 2025 has concluded. If your enterprise escaped this year unscathed by cyber criminals, consider yourselves blessed and highly favored. For far too many it was one where they experienced tremendous stress, mentally, emotionally, physically, and financially, enduring havoc and disaster due to success of the unrelenting assaults of the vile, evil, inhuman, soulless, scum that prey on the livelihood of others for their own financial gain, or even worse, mere entertainment. There is a toasty spot reserved in Hades for them. To the defenders, whether you had to deal with a cleanup or not, I say well done good and faithful warrior. You are the line in the sand between darkness and light, good and evil. It is through your dedicated efforts and sacrifices that our companies and clients are able to enter another year. With 2026 just mere days away, I encourage you with the words of Winston Churchill, “…never give in, never give in, never, never, never, never-in nothing, great or small, large or petty — never give in except to convictions of honor and good sense. Never yield to force; never yield to the apparently overwhelming might of the enemy.” And in my words…

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression
- Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive DataSonicWall Edge Access Devices Hit by Zero-Day Attacks
- Critical RCE flaw impacts over 115,000 WatchGuard firewalls
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- NIST warns of NTP inaccuracy after blackouts across Colorado
- FBI Seizes Fake ID Template Domains Operating from Bangladesh
- Interpol-led action decrypts 6 ransomware strains, arrests hundreds
- INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty
- Ukrainian hacker admits affiliate role in Nefilim ransomware gang
- US DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme
- US DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware
- US shutters phisherfolk’s $14.6M password-hoarding platform
- Most American banks’ security options are terrible; here’s how I still stay safe
- Pen testers accused of ‘blackmail’ over Eurostar AI flaws
- Vulnerabilities and Exploits
- CISA flags ASUS Live Update CVE, but the attack is years old
- CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
- Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances
- Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours
- PoC Exploit Released HPE OneView Vulnerability that Enables Remote Code Execution
- Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls
- When adversaries bring their own virtual machine for persistence
- Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits
- Hackers Weaponize SVG Files and Office Documents to Target Windows Users
- New GhostLocker Tool that Uses Windows AppLocker to Neutralize and Control EDR
- Over 1,800 North Korean applicants flood Amazon — suspected illicit applicants blocked by the company since April 2024
- Redirection For Contact Form 7 WordPress Plugin Vulnerability
- Sleeping Bouncer Vulnerability Impacts Motherboards from Gigabyte, MSI, ASRock and ASUS
- PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel’s POSIX CPU Timers Implementation
- Microsoft Brokering File System Vulnerability Let Attackers Escalate Privileges
- Windows Imaging Component Vulnerability Can Lead to RCE Attacks Under Complex Attack Scenarios
- TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
- SSH server Dropbear allows privilege escalation
- Critical Langchain Vulnerability Let attackers Exfiltrate Sensitive Secrets from AI systems
- PSA: PSN Accounts Can Be Hacked Even With 2FA, Passkey Enabled – PlayStation LifeStyle
- Phishing, Malware, and similar
- Fake MAS Windows activation domain used to spread PowerShell malware
- What is ‘Quishing’? Scanning a restaurant menu could lead to being hacked
- WhatsApp users targeted in new GhostPairing scam giving hackers full account access without breaking passwords or encryption safeguards
- Malicious npm package steals WhatsApp accounts and messages
- NPM Package With 56K Downloads Caught Stealing WhatsApp Messages
- MacSync Stealer variant bypasses Apple malware protections
- New MacSync malware dropper evades macOS Gatekeeper checks
- Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites
- Breaches, Leaks, and Ransomware
- Amazon confirms years-long Russian cyberattack against AWS customers’ devices
- 1,000 systems pwned in Romanian Waters ransomware attack
- Ministers confirm breach at UK Foreign Office
- LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
- Trust Wallet confirms extension hack led to $7 million crypto theft
- Aflac hack may have exposed data of 22.6M people, company says
- 21K Nissan customers’ data stolen in Red Hat raid
- Nissan says thousands of customers exposed in Red Hat breach
- Pornhub tells users to expect sextortion emails after data exposure
- France’s national post office hit by suspected cyber-attack
- French postal service brought down by cyber attack
- Pro-Russian hacking group claims cyberattack on France’s postal service
- University of Phoenix data breach impacts nearly 3.5 million individuals
- LOSFA sends out letter to students warning of ‘data security incident’ involving information
- NHS England tech provider reveals data breach – DXS International hit by ransomware
Other News Events of Note and Interest
- Cool Tool: LibreOffice 26.2 Gets Rid Of The “Community” Edition Branding
- Cool Tool: I monitor my whole home lab from this one dashboard
- 12 Predictions for 2026
- The World’s Strangest Computer Is Alive and It Blurs the Line Between Brains and Machines
- Internet slow? Map reveals which provider is fastest at every US address
- Wi-Fi 8 will bring reliability rather than greater speed
- DoD expands login options beyond CAC
- UNIX V4 tape successfully recovered
- The HTML Elements Time Forgot
- South Korea to require facial recognition for new mobile numbers
- Virginia enacts social media time limits for minors starting Jan. 1
- Europe gets serious about cutting US digital umbilical cord
- Google Gemini is getting an AI video detector
- Google joins attacks on Britain over free speech online
- Google ‘rolling out’ option to change Gmail addresses
- The Amiga’s filesystem is now on Linux and Mac, thanks to an emulated driver
- Apple lands third in Cloudflare’s 2025 Internet Services rankings
- Docker Hardened Images now open source and available for free
- What are passkeys really? The simple explanation – for anyone tired of passwords
- I tried the fastest public DNS you’ve never heard of — and it’s more powerful than Cloudflare
- Yahoo Mail’s New Approach to UX: Making the Inbox Feel Calm Again
- Search pioneer AltaVista’s star shone bright with a clean and minimal UI 30 years ago
- ServiceNow’s $7.75 billion cash deal for Armis illustrates shifting strategies
- AI, LLM’s, and Skynet
- 2025 LLM Year in Review
- AI Is Exposing a Security Gap Companies Aren’t Staffed for: Researcher
- Sam Altman on OpenAI’s Plan to Win, AI Personalization, Infrastructure Math, and The Inevitable IPO
- How to master ChatGPT basics in under an hour – with my favorite free resources
- AI trading agents formed price-fixing cartels when put in simulated markets
- Microsoft
- Steam’s new Windows client is now fully 64‑bit
- New Microsoft 365 Tool Simplifies Tenant-to-Tenant Migrations
- Microsoft Teams Phone PSTN Users Surges to 26 Million Users
- Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026
- Microsoft says Windows 11 File Explorer will soon use less RAM when you search files
- Now Admins Can Block External Users in Microsoft Teams From Defender Portal
- A key component in Windows 11 is getting a huge performance boost soon
- Word and PowerPoint get automatic, on-device Alt Text on Copilot+ PCs
