UK Launches Hybrid Fighting Force to Secure Undersea Cables

UK enhances undersea cable defenses with autonomous vessels and warships due to rising Russian surveillance. The Atlantic Bastion program aims to secure vital underwater infrastructure against threats, utilizing AI and advanced technologies. The initiative, supported by major defense firms, may create thousands of jobs, addressing national connectivity vulnerabilities.

https://www.theregister.com/2025/12/08/uk_subsea_cables_defense/

Apple Sends New Round of Cyber Threat Notifications to Users in 84 Countries

Apple and Google issued cyber threat notifications to users across 84 countries, warning about potential spyware targeting. Apple noted over 150 countries informed in total, while Google highlighted specific threats from Intellexa spyware affecting hundreds of accounts in nations like Pakistan and Egypt. This move seeks to enhance user protection and may prompt investigations into spyware activities.

https://www.reuters.com/technology/apple-sent-new-round-cyber-threat-notifications-users-84-countries-2025-12-05/

Cybersecurity Moves From “Perimeter Defence” to “AI-Era Resilience Engineering”

Cybersecurity has shifted from perimeter defense to resilience engineering due to AI-driven attacks and new threats like deepfakes. Firewalls alone are insufficient as average data breach costs rise to £2.9 million. 43% of UK businesses faced cyber breaches recently, highlighting the urgency for companies to invest in advanced threat detection systems to counter AI-enabled cybercrime.

https://www.techerati.com/features-hub/cybersecurity-moves-from-perimeter-defence-to-ai-era-resilience-engineering/

Novel Clickjacking Attack Relies on CSS and SVG

Security researcher Lyra Rebane has developed a novel clickjacking attack utilizing CSS and SVG, which poses risks by bypassing the web's same-origin policy. This attack enables manipulation of user interface elements without JavaScript. Rebane's technique was explored in her BSides presentation and is based on SVG filters, allowing for complex attack chains. While it hasn't been fixed, defenders may use the Intersection Observer API to detect such vulnerabilities. The attack exemplifies the evolving nature of web security threats.

https://www.theregister.com/2025/12/05/css_svg_clickjacking/

New Prompt Injection Attack Vectors Through MCP Sampling

Palo Alto Networks' Unit 42 article discusses security risks associated with the Model Context Protocol (MCP) in coding applications. MCP enables large language models (LLMs) to connect with external services, but without safeguards, malicious servers can exploit it for various attacks. Key risks identified include resource theft, conversation hijacking, and covert tool invocation. The article presents proof-of-concept attacks demonstrating these vulnerabilities and emphasizes the need for effective prevention strategies. Additionally, it outlines MCP's structure and operational flow, detailing how sampling allows servers to request LLM responses. Overall, this creates potential attack vectors that necessitate robust security measures.

https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/

UK Cops to Scale Facial Recognition Despite Privacy Backlash

UK plans to expand police facial recognition despite civil rights concerns, proposing a legal framework for broader biometric use. Critics warn of increased surveillance and loss of privacy, citing concerns over how many innocent people were scanned. Home Office argues for clearer lawful deployment guidelines, while opposition groups fear this initiates a path towards authoritarian surveillance.

https://www.theregister.com/2025/12/05/uk_cops_facial_recognition/

The Hidden Cascade: Why Law Firm Breaches Destroy More Than Data

Law firms face significant cyberattack risks, with 20% targeted in the past year and average breach costs exceeding $5 million. Attackers are increasingly sophisticated, using tactics that can undermine client privilege and expose sensitive data, especially relating to M&A deals. Current security assessments overlook law firms, leaving businesses vulnerable. The article advocates treating these firms like high-risk technology vendors, proposing specific security measures to mitigate risks associated with data breaches in professional services.

https://www.recordedfuture.com/blog/the-hidden-cascade

New Wave of VPN Login Attempts Targets Palo Alto GlobalProtect Portals

New attacks targeting Palo Alto GlobalProtect VPN portals began on December 2, involving 7,000 IPs from German company 3xK GmbH. Initial brute-force attempts on GlobalProtect led to scanning SonicWall API endpoints. GreyNoise reports the attacker used previous fingerprints, generating millions of HTTP sessions. Both activities are attributed to the same actor, posing credential-based threats but not exploiting software vulnerabilities. Palo Alto recommends enforcing Multi-Factor Authentication (MFA) for protection.

https://www.bleepingcomputer.com/news/security/new-wave-of-vpn-login-attempts-targets-palo-alto-globalprotect-portals/

AI Chatbots Can Be Wooed Into Crimes With Poetry

AI chatbots can be manipulated into generating harmful content, including hate speech and instructions for weapons, through poetic prompts. A study found that using riddles or stylish variations in requests bypasses safety features, allowing chatbots to output forbidden information around 62% of the time. The findings highlight vulnerabilities in AI systems that need urgent addressing, as even minor stylistic changes can lead to harmful results. This raises significant concerns about AI safety protocols and design flaws.

https://www.theverge.com/report/838167/ai-chatbots-can-be-wooed-into-crimes-with-poetry

How I Reverse Engineered a Billion-Dollar Legal AI Tool and Found 100k+ Confidential Files

TLDR: Alex Schapiro discovered a serious security vulnerability in Filevine, a billion-dollar legal AI tool, on October 27, 2025, allowing full admin access to confidential law firm files without authentication. He responsibly disclosed the issue, which could have exposed sensitive data like HIPAA-protected documents. Filevine quickly acknowledged and resolved the problem, demonstrating effective security disclosure practices.

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k

Cloudflare Blames Today’s Outage on Emergency React2Shell Patch

Cloudflare's recent outage was caused by emergency mitigations for a critical vulnerability (CVE-2025-55182) in React Server Components, allowing unauthorized remote code execution. The incident affected about 28% of Cloudflare's HTTP traffic but was not due to a cyber attack. The flaw is being actively exploited by hacking groups, primarily linked to China.

https://www.bleepingcomputer.com/news/security/cloudflare-blames-todays-outage-on-emergency-react2shell-patch/

Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet With up to 4 Million Infected Hosts

TLDR: Cloudflare reports a record 29.7 Tbps DDoS attack from the AISURU botnet, lasting 69 seconds and involving 1-4 million infected hosts. The botnet targets telecoms, gaming, and financial sectors. In 2025, Cloudflare mitigated 36.2 million DDoS attacks, indicating a surge in size and complexity of attacks, especially against AI companies and the automotive industry.

https://thehackernews.com/2025/12/record-297-tbps-ddos-attack-linked-to.html

Silver Fox’s Russian Ruse: ValleyRAT Hits China Via Fake Microsoft Teams Attack

Silver Fox, a Chinese APT group, is misrepresenting itself as a Russian threat actor through a fake Microsoft Teams SEO poisoning campaign targeting organizations in China. Utilizing “ValleyRAT” malware, it conducts state-sponsored espionage and financial fraud. The attack employs false flags, like Cyrillic characters, to mislead attribution, while aiming for sensitive intelligence and financial gains. Organizations, especially those with Chinese operations, need to fortify their defenses by enabling logging and monitoring to counter these evolving threats.

https://reliaquest.com/blog/threat-spotlight-silver-foxs-russian-ruse-fake-microsoft-teams-attack

French NGO Reporters Without Borders Targeted by Calisto in Recent Campaign

Sekoia’s TDR team uncovered spear-phishing campaigns by the Russian-linked group Calisto in May-June 2025, targeting Reporters Without Borders and others. Calisto, associated with Russian intelligence, focused on organizations linked to Ukraine and the West. Their phishing tactics involved fake trusted contacts, missing attachments, or non-working files to trick victims into requesting follow-up documents containing malicious links or decoy PDFs. The phishing kits employed advanced techniques like Adversary-in-the-Middle, intercepting credentials, and 2FA. Calisto’s campaigns make extensive use of compromised websites, redirectors, and numerous custom domains for phishing and credential harvesting. NGOs aiding Ukraine and associated researchers remain high-risk targets.

https://blog.sekoia.io/ngo-reporters-without-borders-targeted-by-calisto-in-recent-campaign/

Scroll to Top