CISA Warns Microsoft Windows Users—Log Out And Shut Down

CISA advises Microsoft Windows users to back up their data, log out, and fully shut down devices if they will be left unattended over the holidays. This reduces the risk of in-person or remote cyber threats and is especially important given the rise in online shopping scams and cyberattacks. Simple actions like powering down and backing up provide stronger protection during the holiday season.

https://www.forbes.com/sites/zakdoffman/2025/12/09/cisa-warns-microsoft-windows-users-log-out-and-shut-down/

The AMOS Infostealer Is Piggybacking ChatGPT’s Chat-sharing Feature

Cybercriminals are spreading the AMOS (Atomic MacOS Stealer) infostealer using convincing Google ads and ChatGPT’s chat-sharing feature. Victims are directed to a legitimate-looking chatgpt.com page showing a fake guide to installing the non-existent Atlas browser for macOS. The guide instructs users to run a terminal command, which downloads malware, steals passwords, browser, and wallet data, and installs a persistent backdoor. Users are advised to avoid running terminal commands from untrusted sources, use trusted security solutions, and seek expert advice if instructions seem suspicious.

https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/

‘Botnets in Physical Form’ Are Top Humanoid Robot Risk

Humanoid robots are becoming mainstream, prompting security concerns regarding potential botnets. With predictions of over 3 billion robots by 2060, experts warn of vulnerabilities, including exploits already identified in existing models. As these robots integrate into various sectors, the emergence of a new industry dedicated to their security is anticipated, emphasizing the need for robust protective measures against cyber threats.

https://www.theregister.com/2025/12/09/humanoid_robot_security/

GeminiJack: The Google Gemini Zero-Click Vulnerability Leaked Gmail, Calendar and Docs Data

GeminiJack: A discovered zero-click vulnerability in Google Gemini Enterprise allowed attackers to exfiltrate sensitive corporate data through shared documents, emails, or calendar invites without user interaction. This architectural flaw permits harmful content to instruct the AI to retrieve confidential information, which is then sent to the attacker via an external image request. The attack operates silently, bypassing traditional security measures. Google has since updated its systems to prevent such vulnerabilities, marking a shift in enterprise AI security considerations. Organizations must enhance monitoring and trust boundaries as AI tools evolve.

https://noma.security/blog/geminijack-google-gemini-zero-click-vulnerability/

Ransomware IAB Abuses EDR for Stealthy Malware Execution

Ransomware group Storm-0249 exploits EDR tools like SentinelOne to stealthily execute malware. Using social engineering, they trick users into running malicious commands that lead to DLL side-loading, making attacks appear as normal EDR processes, thus evading detection. Recommendations include behavior-based detection and stricter controls on execution of potentially harmful commands.

https://www.bleepingcomputer.com/news/security/ransomware-iab-abuses-edr-for-stealthy-malware-execution/

Malicious VSCode Extensions on Microsoft’s Registry Drop Infostealers

Two malicious extensions in Microsoft's Visual Studio Code Marketplace, named Bitcoin Black and Codo AI, infect developers' computers with malware that can steal credentials, screenshots, and cryptocurrency. Codo AI appears as an AI assistant, while Bitcoin Black masquerades as a color theme. Both can execute harmful scripts and have been flagged by antivirus engines. Microsoft has since confirmed their removal from the marketplace. Developers are advised to only install extensions from reputable sources.

https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-on-microsofts-registry-drop-infostealers/

Cloudflare Outage on December 5, 2025

Cloudflare experienced a service outage on December 5, 2025, from 08:47 to 09:12 UTC, affecting 28% of HTTP traffic due to internal changes while addressing a security vulnerability in React. The incident was not caused by a cyber attack. The issue arose from configuration changes that led to HTTP 500 errors, impacting customers using specific setups with the older FL1 proxy. Cloudflare is implementing measures to prevent future incidents, including enhanced rollout protocols and improved error handling. An apology was issued acknowledging the disruption caused.

https://blog.cloudflare.com/5-december-2025-outage/

Introducing Cybersecurity to the Most Connected Generation

MITRE introduces the ATT&CK framework to young audiences to raise cybersecurity awareness. Cyber experts emphasize the necessity for kids to understand online threats as they increasingly engage with digital platforms. Recent outreach includes presentations to students, illustrating the dangers posed by sophisticated adversaries. The aim is to spark interest in cybersecurity careers while equipping the next generation with knowledge to protect themselves. The ATT&CK framework serves as an accessible resource for understanding and discussing adversarial behaviors in cybersecurity.

https://www.mitre.org/news-insights/impact-story/introducing-cybersecurity-most-connected-generation

DDoS Attacks Are Massive and Here to Stay: Cloudflare

Cloudflare reports 8.3 million DDoS attacks in Q3 2025, a 40% YoY increase. The Aisuru botnet is highlighted as the main threat, causing record attacks, including a peak of 29.7 Tb/s. DDoS attacks are now frequent and sophisticated, challenging traditional defenses. Industries like telecom and AI are heavily targeted. China, Turkey, and Germany are the top affected countries, with rising attacks linked to geopolitical tensions.

https://www.sdxcentral.com/news/ddos-attacks-are-massive-and-here-to-stay-cloudflare/

Are Credit Cards Safe?

Credit cards provide protections such as limited liability for unauthorized charges, fraud monitoring, and dispute resolution for questionable transactions. Security features include alerts, encryption, virtual cards, two-factor authentication, and EMV chips. Some cards offer purchase protection and chargebacks for items that are damaged or not received. Overall, credit cards usually offer more safety features than debit cards, helping cardholders prevent fraud and protect their information.

https://www.chase.com/personal/credit-cards/education/basics/credit-card-safety-features

How Phishers Hide Banking Scams Behind Free Cloudflare Pages

Phishing scams are increasingly using free hosting services like Cloudflare Pages to create fake banking and insurance login portals, aiming to capture sensitive information such as usernames, passwords, and answers to security questions. These scams often redirect through compromised legitimate sites, utilizing Telegram for data exfiltration, making them difficult to detect and shut down. Victims encounter authentic-looking pages and are misled into providing personal data, while attackers benefit from rapid setup and evasion of traditional security measures. To avoid such attacks, users should scrutinize URLs, avoid clicking links from unexpected emails, and verify requests for sensitive information.

https://www.malwarebytes.com/blog/news/2025/12/how-phishers-hide-banking-scams-behind-free-cloudflare-pages

Google Chrome Adds New Security Layer for Gemini AI Agentic Browsing

Google Chrome introduces ‘User Alignment Critic', a new security layer for Gemini AI agentic browsing, enhancing protection against unsafe actions and data exposure. This system uses an isolated LLM to vet agent actions, restricts access to trusted sites, prompts user confirmation for sensitive tasks, and detects prompt injection attempts, showcasing a robust defense compared to competitors.

https://www.bleepingcomputer.com/news/security/google-chrome-adds-new-security-layer-for-gemini-ai-agentic-browsing/

FinCEN Says Ransomware Gangs Extorted Over $2.1B From 2022 to 2024

FinCEN reports ransomware gangs extorted over $2.1 billion from 2022 to 2024, peaking in 2023 with 1,512 incidents and $1.1 billion in payments. A decline in 2024 saw 1,476 incidents and $734 million in payments, attributed to law enforcement actions against gangs like BlackCat and LockBit. The manufacturing, financial services, and healthcare sectors were most affected, with these industries suffering significant losses. Over 267 ransomware families were identified, with Akira being the most reported. Majority of payments were made in Bitcoin (97%).

https://www.bleepingcomputer.com/news/security/fincen-says-ransomware-gangs-extorted-over-21b-from-2022-to-2024/

Scroll to Top