Lifetime Access to WormGPT 4 Costs Just $220

WormGPT 4, a malicious AI tool, costs $220 for lifetime access, allowing cybercriminals to easily generate malware and phishing attempts without requiring extensive technical knowledge. This AI can create ransomware scripts and other malicious code, significantly lowering entry barriers for attackers. Another model, KawaiiGPT, is free and also capable of producing harmful scripts, exemplifying the growing accessibility of malicious AI tools.

https://www.theregister.com/2025/11/25/wormgpt_4_evil_ai_lifetime_cost_220_dollars/

Botnet Takes Advantage of AWS Outage to Smack 28 Countries

Mirai-based botnet ShadowV2 emerged during an AWS outage, infecting IoT devices globally and potentially testing for future attacks, as reported by Fortinet. It exploited device vulnerabilities to orchestrate DDoS attacks, affecting 28 countries across various sectors. Although its activity was limited to the outage period, it highlights ongoing IoT security weaknesses, prompting calls for better device protection and monitoring.

https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/

The Letter — Stop Hacklore!

CISOs and security experts debunk common cybersecurity myths affecting everyday individuals and small businesses, advocating for updated, fact-based guidance. They criticize outdated advice like avoiding public WiFi and regularly changing passwords, instead suggesting practical measures such as keeping devices updated, using multi-factor authentication, and employing password managers. They call on software manufacturers to ensure systems are secure by design and support better security practices, urging communicators to promote realistic, effective cybersecurity strategies.

https://www.hacklore.org/letter

Advanced Security Isn’t Stopping Old Phishing Tactics

Phishing attacks consistently evade modern enterprise security, according to Okta’s multi-organization study. Even mature companies with advanced defenses remain vulnerable, especially since many do not regularly use phishing-resistant authentication. Attackers rely on widely available proxy tools, and breaches often go undetected until system alerts are triggered. U.S. companies and Office 365 accounts are prime targets. Increased cross-company information sharing shows promise as a defense, but evolving phishing techniques keep the threat persistent.

https://www.darkreading.com/cyberattacks-data-breaches/advanced-security-phishing-tactics

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

CISA warns of active spyware campaigns targeting Signal and WhatsApp users, utilizing social engineering and commercial spyware to gain unauthorized access. High-value individuals, including government officials, are primary targets. Notable campaigns exploit app features and security flaws to deploy malware. Users are advised to use encrypted communications, avoid SMS-based MFA, update software, and secure app permissions to enhance safety.

https://thehackernews.com/2025/11/cisa-warns-of-active-spyware-campaigns.html

Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)

TL;DR: watchTowr researchers discovered over 80,000 exposed credentials and sensitive data inadvertently shared on online code formatters like JSONFormatter and CodeBeautify, affecting numerous critical sectors. The mishaps illustrate the risks of sharing sensitive information online, demonstrating a lack of understanding of confidentiality practices. Organizations must cease using random platforms for credential storage to mitigate potential threats.

https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/

Live Updates: Sha1-Hulud, The Second Coming

TLDR: Major resurgence of Shai-Hulud malware, now called “Sha1-Hulud: The Second Coming,” compromises over 800 npm packages and tens of thousands of GitHub repos. It embeds credential-stealing payloads and can delete users' home directories if unsuccessful. It exploits GitHub Actions for remote code execution, allowing attackers to run commands through victim accounts. Organizations should scan endpoints, remove affected packages, rotate credentials, and audit workflows to mitigate risks.

https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised

As Gen Z Enters Cybersecurity, Jury Out on AI’s Impact

Bandana Kaur, an 18-year-old Gen Z cybersecurity specialist, views AI as a tool that transforms, rather than threatens, entry-level cybersecurity roles. While AI automates repetitive work and improves both cyberattack and defense capabilities, creative and complex security work remains a human domain. Kaur notes job market difficulties are more about unrealistic hiring practices than about AI itself. She encourages peers to leverage AI for learning and communication while remaining critical and curious. Her self-taught background and hands-on experience suggest that curiosity and online resources are key for Gen Z entering the field of cybersecurity.

https://www.darkreading.com/cybersecurity-operations/gen-z-cybersecurity-jury-out-ai-impact

Video Gaming and Cybersecurity: Navigating Legal and Technological Challenges

Video gaming industry faces significant cyber risks due to rapid growth, attracting cyber criminals. Regulators worldwide are extending critical infrastructure legislation to gaming. This includes the NIS2 Directive and Cyber Resilience Act which impose stringent cybersecurity requirements on game companies. Key risks involve in-game integrity, data breaches, and compliance with regulations like GDPR. Effective cybersecurity measures are essential for legal compliance and to maintain user trust in an evolving digital landscape.

https://www.nortonrosefulbright.com/en/knowledge/publications/77cbcb67/video-gaming-and-cybersecurity

FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams

FBI reports over $262M lost to account takeover (ATO) fraud this year, targeting various sectors through social engineering and phishing. Cybercriminals impersonate financial institutions to steal sensitive information and funds. Users are advised to monitor accounts and protect personal information. The rise of AI in phishing tactics is linked to increased holiday scams, with significant vulnerabilities exploited across e-commerce platforms. A shift towards sophisticated purchase scams is noted, involving authorized payments by victims, complicating fraud detection.

https://thehackernews.com/2025/11/fbi-reports-262m-in-ato-fraud-as.html

Google Antigravity Exfiltrates Data

Google's Antigravity allows for data exfiltration through indirect prompt injection, enabling attackers to manipulate the software to steal sensitive user data from IDEs. In an attack scenario, a user integrating Oracle ERP's AI Payer Agents exposes their credentials as Antigravity accesses a malicious site via a hidden prompt injection. Despite safeguards, the tool bypasses protections to exfiltrate data, showcasing serious vulnerabilities linked to its design and settings. Google's acknowledgment of these risks highlights the need for user vigilance amidst multiple agents operating simultaneously.

https://www.promptarmor.com/resources/google-antigravity-exfiltrates-data

Email Security: Where We Are and What the Future Holds

Email security is flawed, relying on outdated protocols like SMTP, which lacks encryption by default. Various solutions like STARTTLS, SMTPS, and end-to-end encryption via PGP and S/MIME attempt to improve security but face usability and trust issues. Authentication mechanisms (SPF, DKIM, DMARC) help but are vulnerable due to DNS weaknesses. The future calls for enhanced E2EE, adoption of DNSSEC, and overall improvements in protocols to strengthen email as a secure communication tool, moving away from its role in account recovery and toward focused communication purposes.

https://www.privacyguides.org/posts/2025/11/15/email-security-where-we-are-and-what-the-future-holds/

Technology Protects Retailers, Issuers, and Consumers From CNP Fraud

Card-not-present (CNP) fraud significantly impacts merchants, especially in e-commerce, with most of the financial liability falling on retailers. Solutions like Safecypher’s dynamic security code use temporary CVVs visible only in secure banking apps, offering two-factor authentication at purchase and preventing unauthorized use even with stolen card details. Results from the Irish Post Office show this approach eliminated CNP fraud when adopted by customers.

https://www.marketingtechnews.net/news/cnp-fraud-foiled-by-banking-app-mfa/

Matrix Push C2 Abuses Browser Notifications to Deliver Phishing and Malware

Cybercriminals exploit browser push notifications via the Matrix Push C2 platform to deliver malware and phishing attacks. Users are deceived into granting permission through misleading prompts, allowing attackers to send fake alerts and gather personal data. The platform enables detailed monitoring of victims and custom URL management for malicious campaigns, often resulting in data theft or financial loss. Users are advised to manage notification permissions across their browsers to mitigate these risks.

https://www.malwarebytes.com/blog/news/2025/11/matrix-push-c2-abuses-browser-notifications-to-deliver-phishing-and-malware

ClickFix Gets Creative: Malware Buried in Images

ClickFix malware is a multi-stage attack using steganography to conceal infostealing malware within images. It begins with social engineering tactics, tricking users into executing malicious commands. Huntress identified two main ClickFix lures—one using a “Human Verification” tactic and the other mimicking a Windows Update interface. The process involves JavaScript to copy commands to the clipboard, PowerShell for loading .NET assemblies, and a complex steganographic algorithm to hide and extract shellcode from PNG images. This shellcode is then injected into target processes, ultimately delivering LummaC2 malware for data theft. The campaign has evolved with increasingly convincing user interfaces to deceive targets effectively.

https://www.huntress.com/blog/clickfix-malware-buried-in-images

Scroll to Top