Sha1-Hulud 2.0 Supply Chain Attack: 25K+ Npm Repos Exposed

Extreme TLDR:
New Shai-Hulud 2.0 attack targets npm packages, affecting 25K+ repos and stealing secrets, with ~700 compromised packages identified. Immediate investigation and remediation recommended for npm environments. Attackers exploit lifecycle scripts for credential theft, leading to widespread credential exfiltration and propagation. Security teams advised to replace compromised packages, rotate credentials, and audit CI/CD environments.

https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack

Fake Calendar Invites Are Spreading. Here’s How to Remove Them and Prevent More

Fake calendar invites are on the rise, often linked to phishing scams that users struggle to delete due to synchronization across devices. To remove these, disable auto-adding events in settings for Outlook, Gmail, and mobile calendars, block senders, and report spam. Precautions include avoiding interaction with unknown invites, limiting calendar permissions, and using anti-malware tools. Always verify billing issues through official channels.

https://www.malwarebytes.com/blog/news/2025/11/fake-calendar-invites-are-spreading-heres-how-to-remove-them-and-prevent-more

WhatsApp API Flaw Let Researchers Scrape 3.5 Billion Accounts

WhatsApp's contact-discovery API had a flaw allowing researchers to scrape 3.5 billion accounts due to lack of rate limiting, enabling high-volume queries. This study highlighted vulnerabilities in API security across platforms. Researchers gathered extensive user data, including profiles, revealing large-scale abuse potential. WhatsApp subsequently implemented protections to prevent further exploitation.

https://www.bleepingcomputer.com/news/security/whatsapp-api-flaw-let-researchers-scrape-35-billion-accounts/

Understanding Cloud Persistence: How Attackers Maintain Access Using Google Cloud Functions

Extreme TLDR: Attackers use Google Cloud Functions and service accounts to maintain access in cloud environments. They automate recovery of deleted accounts through logging and Pub/Sub events, leveraging these features for persistent access despite clean-up efforts.

https://whiteknightlabs.com/2025/11/11/understanding-cloud-persistence-how-attackers-maintain-access-using-google-cloud-functions/

How Consumers See Card Threats

Many card users lack recent security awareness, with a J.D. Power survey revealing that a third haven't taken protective measures in 90 days. 24% faced fraud, mainly Gen Z (41%) and financially strapped consumers (40%). Only 45% reported prompts from issuers for security actions. As fraud losses may total $403.88 billion globally over the next decade, institutions stress consumer responsibility in fraud prevention.

https://www.paymentsdive.com/news/consumers-want-more-card-fraud-protection-survey/806174/

Kevin Boone: The Privacy Nightmare of Browser Fingerprinting

Summary: Browser fingerprinting compromises online privacy by creating unique identifiers from browser information, making tracking harder to evade than traditional cookies. While steps like using VPNs and popular browsers can mitigate risks, effective resistance is challenging and often inconvenient. Legal clarity on fingerprinting is lacking, and stronger legislation is needed to address its privacy threats. Overall, fingerprinting remains a significant concern, contributing to intrusive advertising practices.

https://kevinboone.me/fingerprinting.html

Sturnus: Mobile Banking Malware Bypassing WhatsApp, Telegram and Signal Encryption

Sturnus is a newly identified Android banking trojan capable of bypassing encrypted messaging apps like WhatsApp, Telegram, and Signal. It monitors communications by capturing screen content, harvests banking credentials via fake login screens, and allows extensive remote control of infected devices, including real-time screen viewing and activity injections. Currently in a pre-deployment phase, it primarily targets users in Southern and Central Europe, focusing on high-value applications. The malware's architecture incorporates advanced evasion techniques, including code obfuscation and complex communication protocols, posing significant threats to financial security and privacy.

https://www.threatfabric.com/blogs/sturnus-banking-trojan-bypassing-whatsapp-telegram-and-signal

‘MatrixPush’ C2 Tool Hijacks Browser Notifications

A recent cyber threat, “Matrix Push,” uses browser notifications for phishing attacks, exploiting legitimate API requests. Infections happen through social engineering, allowing attackers to send deceptive alerts disguised as genuine notifications. To combat these threats, stronger browser protections, user vigilance, and security tools are essential.

https://www.darkreading.com/threat-intelligence/matrix-push-c2-tool-hijacks-browser-notifications-phishing

CVE-2025-50165: Windows Graphics Component Flaw

CVE-2025-50165 is a critical remote code execution flaw in the Windows Graphics Component, specifically in windowscodecs.dll. It allows an attacker to exploit Windows systems via a malicious JPEG image embedded in standard documents. The vulnerability affects recent versions of Windows, including Server 2025 and Windows 11 24H2, but was patched by Microsoft in August 2025. Users are advised to apply the updates immediately. Zscaler ThreatLabz has also released protection for this vulnerability.

https://www.zscaler.com/blogs/security-research/cve-2025-50165-critical-flaw-windows-graphics-component

Concerned About Identity Theft? This May Be the First Sign You’re in Trouble

TLDR: Small unauthorized charges on bank statements, termed “phantom payments,” may indicate identity theft. Regularly review your transactions monthly; be wary of unfamiliar merchants. Protect your information and report suspicious activity to your bank and credit agencies if theft is suspected.

https://www.fool.com/retirement/2025/11/20/concerned-about-identity-theft-this-may-be-the-fir/

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

Hackers are actively exploiting a critical vulnerability (CVE-2025-11001) in 7-Zip, allowing remote code execution via symbolic links in ZIP files. This flaw, identified by NHS England Digital, affects versions prior to 25.00. A proof-of-concept exploit exists, prompting users to update immediately for protection.

https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html

Russian Bulletproof Hosting Provider Sanctioned Over Ransomware Ties

US, UK, Australia sanction Russian bulletproof hosting provider Media Land for supporting ransomware and cybercrime. The provider offers services to criminals, enabling phishing and DDoS attacks. Sanctions freeze assets and target related executives. Joint guidance issued to mitigate risks posed by bulletproof hosting providers.

https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletproof-hosting-provider-media-land-over-ransomware-ties/

Can a Global, Decentralized System Save CVE Data?

The NVD has struggled to keep up with the growing volume of CVE vulnerability disclosures, leading to backlogs and delays in data enrichment due to limited funding and staffing. Centralized management by U.S. entities such as NIST and MITRE creates a single point of failure, as a 2024 funding crisis highlighted. Security experts like Jerry Gamblin propose a decentralized system in which regional and industry leaders share responsibility and introduce redundancy, such as through the EUVD. The idea calls for globally standardized, uniquely identified records and broad industry participation, but remains an early-stage concept seeking engagement and feedback from the broader security community.

https://www.darkreading.com/cybersecurity-operations/can-global-decentralized-system-save-cve-data

Cloudflare Outage on November 18, 2025

On November 18, 2025, Cloudflare experienced a significant outage affecting core network traffic after a database permission change caused a feature file to double in size, leading to system failures. Initial suspicions of a DDoS attack were disproved as the issue was traced to bad configurations propagated throughout the network. The outage, which resulted in numerous HTTP 5xx error codes and impacted various services, was resolved by reverting to a stable configuration and restarting core proxies. Cloudflare acknowledged the unacceptable nature of the incident and committed to implementing measures to prevent future occurrences.

https://blog.cloudflare.com/18-november-2025-outage/

Scroll to Top