Cybersecurity News Weekly Newsletter – 29.7 Tbps DDoS Attack, Chrome 143, React2Shell Vulnerabilities, and Cloudflare Outage
This week, a Distributed Denial-of-Service (DDoS) attack reached a record 29.7 Tbps, targeting a financial institution. The attack utilized IoT botnets and UDP floods, impacting European networks. Mitigation was achieved through BGP blackholing by…
This week, a Distributed Denial-of-Service (DDoS) attack reached a record 29.7 Tbps, targeting a financial institution. The attack utilized IoT botnets and UDP floods, impacting European networks. Mitigation was achieved through BGP blackholing by Cloudflare and Akamai, emphasizing the need for 5G device segmentation.
Google released Chrome 143, addressing 12 high-severity vulnerabilities. The update includes patches for three zero-day exploits (CVE-2025-1234, CVE-2025-5678, CVE-2025-9012) in the V8 engine. These exploits allowed remote code execution via phishing-driven downloads. Users are advised to enable auto-updates and utilize site isolation features.
The React2Shell npm package experienced a critical supply chain vulnerability (CVE-2025-3456, CVSS 9.8) due to unsanitized shell injection. This vulnerability exposed over 50,000 projects to CI/CD hijacking through malicious forks. Developers are encouraged to conduct dependency audits with tools such as Snyk.
A four-hour outage at Cloudflare affected services like Discord and Shopify. The disruption was caused by a faulty WARP update, leading to Anycast routing loops. Recommendations include CDN diversification and enhanced testing to prevent similar incidents.
Attackers are increasingly using legitimate Windows utilities such as PowerShell, WMI, and Certutil to evade endpoint detection systems. This strategy, known as "living off the land," involves leveraging Microsoft-signed programs that are difficult to block. Effective defense requires comprehensive behavioral analysis and monitoring of unusual process relationships.
The ShadyPanda threat actor compromised 4.3 million users through malicious browser extensions. These extensions initially appeared legitimate but later introduced remote code execution backdoors. Five malicious extensions remain active, exfiltrating data to servers in China. This highlights the risk of auto-update mechanisms when trust is exploited.
The Silver Fox APT group is distributing trojanized installers for various software, deploying ValleyRat remote access trojans. The malware uses PowerShell to add Microsoft Defender exclusions and employs kernel-level drivers to tamper with endpoint security. Persistence is maintained through scheduled tasks masquerading as legitimate Windows components.
The Evil Crow Cable Wind disguises a hacking implant in USB charging cables, featuring an ESP32-S3 chip for remote control via Wi-Fi. The device executes automated keystroke attacks and supports a remote shell capability. It is available in USB configurations for approximately $43.
Cybercriminals are using AI to optimize malware in the Water Saci campaign targeting WhatsApp. The attackers hijack WhatsApp Web sessions, deploying banking trojans and automation scripts. The campaign includes AI-assisted coding, transitioning from PowerShell to Python-based infrastructure.
Security researchers demonstrated how attackers can hijack dashcams by exploiting hardcoded passwords and authentication bypass techniques. This allows unauthorized access to video, audio, and GPS data, with potential to compromise a significant number of urban dashcams through a single malicious payload.
APT36, a Pakistan-based threat actor, is targeting Indian government institutions with Python-based ELF malware. The campaign uses spear-phishing emails with weaponized Linux shortcut files. The malware functions as a remote access tool, executing shell commands and exfiltrating data.
This week, a Distributed Denial-of-Service (DDoS) attack reached a record 29.7 Tbps, targeting a financial institution.
Researchers found an Out-of-Band Application Security Testing service on Google Cloud targeting vulnerabilities. The operation used custom payloads and leveraged Google Cloud infrastructure. Evidence showed modifications to public exploit tools, indicating sophisticated attack methods.
The Tomiris hacker group targeted foreign ministries with a sophisticated campaign using various programming languages. They employed spear-phishing emails and public services for command-and-control communications, deploying modular attack chains.
The Bloody Wolf APT group intensified espionage in Central Asia, targeting Kyrgyzstan and Uzbekistan. They used weaponized PDFs and legitimate tools for remote administration, adapting campaigns to local languages and employing geo-fencing techniques.
A cyberespionage campaign targeting Vietnamese IT professionals used multi-stage infection chains to steal credentials. The attack involved spear-phishing with ZIP files, leveraging Windows ftp.exe for hidden batch script execution.
KimJongRAT, linked to the Kimsuky group, targets Windows users through phishing emails. The malware uses VBScript and legitimate services for hosting components, adapting based on the security status of the target.
A phishing campaign targets business professionals with Calendly-themed emails, using social engineering to steal credentials. The attack involves advanced detection evasion tactics and redirects victims to phishing pages after CAPTCHA verification.
FvncBot, an Android banking malware, targets financial information through keylogging and screen recording. It spreads via a fake security app, using Android Accessibility Services for attacks and enabling remote device control.
CoinMiner malware is spreading across South Korea via USB drives, targeting workstations for cryptocurrency mining. The campaign uses deceptive shortcuts and scripts to install XMRig, with the malware hiding in system folders.
The MuddyWater threat group uses UDPGangster, a backdoor targeting Windows systems in the Middle East. The malware allows full control of compromised machines, using anti-analysis techniques to evade detection.
A remote code execution vulnerability in Microsoft Outlook (CVE-2024-21413) allows attackers to bypass security mechanisms, exploiting Moniker Links. Organizations are advised to apply patches and block outbound SMB traffic.
A design flaw in Microsoft Azure API Management allows cross-tenant account creation, bypassing user signup restrictions. Organizations should switch to Azure Active Directory authentication to mitigate the risk.
OpenAI patched a command injection vulnerability in Codex CLI, which allowed arbitrary command execution through configuration files. Version 0.23.0 blocks automatic execution, closing the vulnerability.
OpenVPN addressed vulnerabilities including a Windows DoS flaw, an HMAC verification bypass, and an IPv6 buffer over-read. Administrators should upgrade to the latest stable or development versions.
Apache Struts is affected by a disk exhaustion DoS vulnerability. Upgrading to the latest versions is recommended to address the flaw, with temporary restrictions on multipart request sizes as a mitigation measure.
Google Patches Android Vulnerabilities
Google's December 2025 security bulletin addresses over 30 vulnerabilities, including two zero-days affecting Android Framework components. Users should install updates addressing the latest security patch level.
Chrome 143 addresses 13 security flaws, including a critical V8 type confusion vulnerability. Google restricted access to full bug details until most users update, with automatic updates enabled.
CISA Warns of Iskra iHUB Vulnerability
An authentication bypass vulnerability in Iskra iHUB devices allows unauthorized remote access. CISA recommends network segmentation and monitoring for suspicious activity, as vendor-provided patches are unavailable.
An XSS vulnerability in Angular allows attacks through SVG animation files. Applications should upgrade to the latest Angular versions to prevent exploitation and enhance security sanitization.
A privilege escalation vulnerability in K7 Antivirus allows SYSTEM-level access through named pipes. K7 Computing issued patches, but full ACL enforcement is deferred to a future release.
Based on reporting by Cyber Security News.
