惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
P
Privacy & Cybersecurity Law Blog
Cloudbric
Cloudbric
云风的 BLOG
云风的 BLOG
S
Secure Thoughts
Stack Overflow Blog
Stack Overflow Blog
G
Google Developers Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
S
SegmentFault 最新的问题
博客园 - Franky
T
Tenable Blog
T
The Blog of Author Tim Ferriss
博客园 - 三生石上(FineUI控件)
V
V2EX
Recent Commits to openclaw:main
Recent Commits to openclaw:main
T
Troy Hunt's Blog
罗磊的独立博客
WordPress大学
WordPress大学
SecWiki News
SecWiki News
The Cloudflare Blog
S
Securelist
小众软件
小众软件
Schneier on Security
Schneier on Security
Hacker News - Newest:
Hacker News - Newest: "LLM"
博客园 - 叶小钗
Google Online Security Blog
Google Online Security Blog
Forbes - Security
Forbes - Security
阮一峰的网络日志
阮一峰的网络日志
量子位
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
W
WeLiveSecurity
A
Arctic Wolf
大猫的无限游戏
大猫的无限游戏
The Last Watchdog
The Last Watchdog
C
Cybersecurity and Infrastructure Security Agency CISA
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
博客园 - 司徒正美
Vercel News
Vercel News
H
Help Net Security
Y
Y Combinator Blog
PCI Perspectives
PCI Perspectives
L
LINUX DO - 最新话题
H
Hackread – Cybersecurity News, Data Breaches, AI and More

The Register - Security: Research

www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US Perplexity Comet browser hole was exploitable via cal invite DEF CON hackers 'fed up with government,' Jake Braun says DEF CON hackers 'fed up with government,' Jake Braun says Ransomware payments cratered in 2025 – attacks did not Ransomware payments cratered in 2025 – attacks did not Claude's collaboration tools allowed remote code execution AI takes a swing at online anonymity Fake 'interview' repos lure Next.js devs into running secret-stealing malware Threat intelligence supply chain is full of weak links AI agents abound, unbound by rules or safety disclosures RAT disguised as an RMM costs crims $300 a month Android malware taps Gemini to navigate infected devices Posting AI caricatures on social media is bad for security Payroll pirates conned the help desk, stole employee’s pay Microsoft boffins show LLM safety can be trained away For the price of Netflix, crooks can rent AI crime ops For the price of Netflix, crooks can rent AI crime ops Fast Pair, loose security: Bluetooth accessories open to silent hijack Fast Pair flaw exposes Bluetooth devices to hijacking A simple CodeBuild flaw put every AWS environment at risk A simple CodeBuild flaw put every AWS environment at risk DeadLock ransomware uses smart contracts to evade defenders Python libraries in AI/ML models can be poisoned w metadata OpenAI patches déjà vu prompt injection vuln in ChatGPT Fake Windows BSODs check in at Europe's hotels to con staff into running malware Hotel staff tricked into installing malware by bogus BSODs Your car’s web browser may be on the road to cyber ruin China's Ink Dragon hides out in European government networks Browser 'privacy' extensions have eye on your AI, log all your chats NCSC finds cyber deception tools work, if deployed right 10K Docker images spray live cloud creds across the internet 'Botnets in physical form' are top humanoid robot risk 'Botnets in physical form' are top humanoid robot risk Novel clickjacking attack relies on CSS and SVG 'Exploitation is imminent' of max-severity React bug Swiss government bans SaaS and cloud for sensitive info Scattered Lapsus$ Hunters stress testing Zendesk weak spots HashJack attack shows AI browsers can be fooled with '#' New ClickFix attacks use fake Windows Updates to swipe creds Years-old bugs in open source took out major clouds at risk LLM-generated malware improving, but not operational (yet) 3.5B WhatsApp users' info scooped through enumeration flaw 3.5B WhatsApp users' info scooped through enumeration flaw 50k more ASUS routers pwned by evolving Beijing-linked op Overconfidence is the new zero-day as teams stumble through cyber simulations LLM side-channel attack could allow snoops to guess topic Landfall spyware used in 0-day attacks on Samsung phones MIT Sloan shelves paper about AI-driven ransomware Security hole slams Chromium browsers - no fix yet OpenAI Atlas Browser tripped up by malformed URLs Devs of VS Code extensions are leaking secrets en masse Chatbots that butter you up make you worse at conflict Tile trackers leak unencrypted Bluetooth data, say boffins Beijing's RedNovember hacked critical US, global orgs Lazarus RAT code resurfaces in North Korean IT-worker scams Suspected Chinese spies broke into 'numerous' enterprises Deepfaked calls hit 44% of businesses in last year: Gartner Kaspersky: RevengeHotels returns with AI-coded malware Ruh-roh. DDR5 memory vulnerable to new Rowhammer attack HybridPetya ransomware dodges UEFI Secure Boot
Apache warns of 10.0-rated flaw in Tika metadata toolkit
Brandon Vigliarolo and Simon Sharwood · 2025-12-08 · via The Register - Security: Research

INFOSEC IN BRIEF The Apache Foundation last week warned of a 10.0-rated flaw in its Tika toolkit.

Tika detects and extracts metadata from over 1,000 different file formats. Last August, Apache reported CVE-2025-54988, an 8.4 rated flaw that it warned allows an attacker to carry out XML External Entity injection via a crafted XFA file inside a PDF.

Apache fixed that flaw but last Friday announced a related, and worse, problem known as CVE-2025-66516.

As Apache explained, the entry point for CVE-2025-54988 was Tika’s tika-parser-pdf-module, but the vulnerability and its fix were in another piece of code called tika-core. “Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable,” the organization advised.

The org’s new advisory also admits that its original report “failed to mention that in the 1.x Tika releases, the PDFParser was in the org.apache.tika:tika-parsers module.”

Tika’s developers have tidied things up in recent releases, and now users get to revisit this mess too.

New kind of ‘DDOS’ erupts from the Americas

France-based cloud OVH is adding 2-3Tbps of DDOS protection capacity weekly, to head off a rising tide of attacks from across the Atlantic.

“Since Sep'25, we have seen new kind of DDoS coming from US and South America (Brazil, Chile, Argentina, Mexico, Columbia),” OVH CEO Octave Klaba reported last week. “The size is around 15-16Tbps coming thought Miami, FL Dallas, TX and Los Angeles, CA.”

OVH is adding the extra DDOS protection capacity to deal with the threat. Klaba said OVH aims to deploy 100Tbps of DDOS-deflectors, ASAP, to defend its operations.

Cyber Deterrence and Response Act resurfaces

Not content to wait for the White House to develop a plan to deter America's enemies from attacking US critical infrastructure, one Republican representative has introduced his own bill to establish a way to fight off foreign hackers.

Rep. August Pfluger (R-TX) last week introduced The Cyber Deterrence and Response Act, which proposes to grant the National Cyber Director formal authority to identify and sanction threat actors.

The bill would do this by establishing "the first government-wide process for cyber attribution," according to Pfluger's office. The process would include defining evidentiary standards and verification methods. A press release describing the bill explains that the method would align various agencies under a single set of rules to help ensure accurate attribution. The bill also includes provisions to allow contributions from private companies. It also mandates threat sharing with international allies.

"We must ensure the Trump administration and all future administrations have a strong framework to hold bad actors accountable and safeguard our national security," Pfluger said. "Protecting America's critical infrastructure from malicious cyberattacks is essential, and this bill does exactly that."

This isn't the first time US lawmakers have proposed an identically-named bill with similar objectives – attempts to pass similar bills took place in 2018, 2019, and 2022. All stalled in committee.

It's also worth pointing out that National Cyber Director Sean Cairncross is working on his own measures to help the federal government identify and deter foreign hackers, as we reported last month, and Cairncross' objectives seem to go even further, suggesting the US might start hacking back.

NIST wants YOU to secure your IoT devices

Manage a lot of IoT tech? Then listen up: the National Institute of Standards and Technology's Cybersecurity Center of Excellence has just published three new IoT onboarding publications to help secure that sensitive kit.

Internet of Things devices are a security nightmare, often built without regard for their potential to be an ingress point for attacks, and NIST thinks its trio of new publications can help prevent such problems.

The first document covers secure provisioning of IoT devices on their own network layer with unique local credentials, the second looks at why device network layer onboarding is important and why you should do it, and the third goes through device network layer onboarding processes themselves and addresses IoT device lifecycle management.

Predator spyware maker still going strong

Intellexa, makers of the Predator commercial spyware used to target people around the globe, have been sanctioned by the United States and forced out of Europe, but that's not really slowing the firm down, says Google.

A report from the Chocolate Factory's Threat Intelligence Group published last week concluded that Intellexa has "adapted, evaded restrictions, and continues selling digital weapons to the highest bidders."

Predator functions similarly to Pegasus spyware. Users are often nation-states and install the software on targets’ devices. It's dangerous, too: Of the 70 zero-day vulnerabilities discovered by Google threat hunters since 2021, Intellexa is responsible for 15 unique ones.

Intellexa's operations aren't completely airtight. Some of its secrets were leaked to Amnesty International, which recently published a profile of the company based on documents it acquired and verified.

Regardless of whether there's a mole among Predator's people, Amnesty, like Google, says the spyware and its maker "poses an ongoing threat to civil society" and sanctions haven't been effective.

DoJ takes down another crypto fraud website

Bad actors continue to build platforms that mimic legitimate trading sites and suckering folks into handing over their digicash, with the DoJ busting another one last week.

The Justice Department's Scam Center Task Force seized Tickmilleas.com, which sports a name similar to the legitimate Tickmill asset trading website. Tickmill is not available in the US, and the scam site apparently used the name as bait to draw victims.

Believed to be affiliated with Chinese organized criminal gangs and Burma-based scam centers, Tickmilleas.com functioned similarly to other so-called pig-butchering scams in which fraudsters trick victims into investing in fake cryptocurrency trading platforms. Promises of big returns and fake account balances trick users into depositing cash on the platform, which the scammers walk off with, leaving victims with little to no recourse.

In this case, Tickmilleas.com also published fraudulent apps on Google Play and Apple’s App Store, which have been removed, the DOJ says.

The seizure comes less than three weeks after the DoJ stood up the Scam Center Task Force, which continues to go after scam centers that are proliferating in Asia and elsewhere in the world. ®