Security
Headlines
HeadlinesLatestCVEs

Source

Malwarebytes

December Patch Tuesday fixes three zero-days, including one that hijacks Windows devices

The update patches three zero-days and introduces a new PowerShell warning meant to help you avoid accidentally running unsafe code from the web.

Malwarebytes
#vulnerability#web#windows#microsoft#git#rce#auth#zero_day
GhostFrame phishing kit fuels widespread attacks against millions

GhostFrame uses dynamic subdomains and hidden iframes to help attackers slip past basic security tools.

Prompt injection is a problem that may never be fixed, warns NCSC

The NCSC warns that prompt injection is unlikely to be mitigated in the same way SQL injection was. How do they compare?

EU fines X $140m, tied to verification rules that make impostor scams easier

The core problem persists: anyone can still buy a 'verified' checkmark from X, so don't take their authenticity for granted.

Deepfakes, AI resumes, and the growing threat of fake applicants

Attackers are blending automation, impersonation, and social engineering to get inside organizations. Here’s how to spot the signs.

How phishers hide banking scams behind free Cloudflare Pages

We found a campaign that hosts fake login pages on Cloudflare Pages and sends the stolen info straight to Telegram.

Scammers harvesting Facebook photos to stage fake kidnappings, warns FBI

Family photos pulled from social media are being used as "proof-of-life" in virtual kidnapping scams, the FBI warns.

A week in security (December 1 – December 7)

A list of topics we covered in the week of December 1 to December 7 of 2025

Leaks show Intellexa burning zero-days to keep Predator spyware running

A fresh investigation uncovers how Predator spyware still reaches victims through high-priced, newly bought zero-days.

How scammers use fake insurance texts to steal your identity

We follow the trail of a simple insurance text scam to show how it can spiral into full-blown identity theft.