-
Over 87,000 MongoDB instances are at risk from a critical memory leak called MongoBleed. Following the chaos at Ubisoft, see how this zero-password flaw works and how to protect your data.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
This week in cybersecurity from the editors at Cybercrime Magazine
Sausalito, Calif. – Dec. 29, 2025–Read the full story in The Independent
As 2025 winds down, business leaders and executives will feel it has been a particularly expensive year as the cost of employment shot up, inflation of raw materials impacted supply chains and both oil and tariff shocks hit in the first half of the year, writes Karl Matchett, business and money editor at The Independent, the widely popular British online newspaper founded in 1986.
But perhaps the biggest cost of all was one borne by companies hit by cyberattacks.
One damning government report suggests that close to half of British businesses and three in 10 charities claimed to have suffered a type of cybersecurity breach or attack in the past year. These include anything from a phishing attack to a full-blown digital shutdown costing hundreds of millions of pounds.
Marks and Spencer. Adidas. Co-op Group. Heathrow airport. Harrods. And, of course, Jaguar Land Rover (JLR). Each has suffered publicly confirmed cyber hacks. These attacks were not limited to companies either: the German parliament also suffered a breach and, in October, the UK government saw the Foreign Office hacked.
What did the hacks cost? Cybersecurity Ventures, a noted source of data and research in the cybersecurity sphere, says the entire (cybercrime) “industry” was worth around $10.5 trillion (£7.8 trillion) this year alone. In country terms, this would make it the third-biggest economy in the world after only the US and China.
Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:
- SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
- NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
- HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
- VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
- M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
- BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
- PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
- PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
- RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.
Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
The post How 2025 Became The Year Of The Cyberattack For British Businesses appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A common theme ran through it all in 2025. Attackers moved faster than fixes. Access meant for work, updates, or support kept getting abused. And damage did not
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A former employee of South Korean e-commerce giant Coupang attempted to destroy evidence of a massive data theft by throwing his MacBook Air into a river, investigators revealed this week. The desperate act failed spectacularly, with forensic experts recovering the device and using its serial number to connect it to the accused perpetrator’s iCloud account. […]
The post Hacker Dumped MacBook in River in Attempt to Destroy Digital Evidence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have uncovered a massive coordinated exploitation campaign where threat actors launched over 2.5 million malicious requests against vulnerable systems during the Christmas 2025 holiday period. The campaign represents a sophisticated, multi-faceted initial access broker operation targeting Adobe ColdFusion servers alongside 46 additional technology stacks across nearly 800 vulnerabilities. The primary attack wave focused […]
The post Hackers Launch 2.5 Million+ Malicious Requests Targeting Adobe ColdFusion Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Researchers reveal CVE-2025-54322, a critical unpatched flaw in XSpeeder networking gear found by AI agents. 70,000 industrial and branch devices are exposed.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A severe unauthenticated remote code execution vulnerability has been discovered in XSpeeder networking devices, potentially affecting more than 70,000 publicly accessible hosts worldwide. Tracked as CVE-2025-54322, the flaw allows attackers to gain root-level access without any authentication credentials. CVE ID Vulnerability Type Severity Affected Systems Authentication Required CVE-2025-54322 Unauthenticated Root RCE Critical ~70,000+ XSpeeder SXZOS […]
The post Critical Zero-Day RCE Flaw in Networking Devices Exposes Over 70,000 Hosts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Air Force leaders axe major China-focused organizational efforts
The service continues to unravel its “reoptimization for Great Power Competition” strategy.
December 2, 2025 | Thomas NovellyMost of the Air Force’s biggest programs will now be overseen by a 4-star under the deputy SecDef
The centralization of the ICBM, B-21, F-47, and Air Force One programs appears at odds with the Pentagon’s professed acquisition approach, one expert said.
November 20, 2025 | Thomas NovellyCongress supports bare minimum on Navy’s F/A-XX, while fully backing Air Force’s F-47
Appropriators and other lawmakers have pushed for the Navy’s next-gen fighter, but the latest NDAA offers only enough to keep the nascent program warm.
December 9, 2025 | Thomas NovellyNearly 300 days after purge, Pentagon taps new Air Force vice chief, JAG
Air Mobility commander nominated to be vice chief; Oklahoma Air National Guard commander to be top judge advocate general.
December 16, 2025 | Thomas NovellyUSAF plan to fly C-5, C-17s even longer elicits concern
Service says it needs to hedge against delays to planned Next-Generation Airlift plane.
November 25, 2025 | Thomas NovellyAllvin’s surprise exit signals pivot for Air Force, not Hegseth pressure: sources
Former Air Combat Commander Gen. Wilsbach tops the list of potential replacements.
August 21, 2025 | Audrey DeckerThe Air Force wants to put private AI data centers on its bases, raising security, land-use fears
The service will offer upwards of 3,000 acres across five U.S. bases to qualified developers.
October 24, 2025 | Thomas NovellyHegseth fired the Air Force’s top lawyer. The JAG who took on the job is stepping away.
It’s been eight months since the service had a Senate-confirmed leader in the role.
October 23, 2025 | Thomas NovellyAFSOC exercise brings concept created for great-power conflict to the Caribbean
Last month, U.S. forces “seized” a St. Croix airport in a demonstration of the Agile Combat Employment maneuver scheme.
September 18, 2025 | Thomas NovellyReturning the Air Force to its expeditionary roots
]]>
Agility and innovation helped win WWII. They will be essential for the next conflict.
September 17, 2025 | Lt. Gen. David A. Harris¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have disclosed critical vulnerabilities in Airoha-based Bluetooth headphones that enable attackers to compromise connected smartphones through chained exploits. The three vulnerabilities CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702 affect dozens of popular headphone models from Sony, Marshall, Jabra, Bose, and other manufacturers. The vulnerabilities center on missing authentication mechanisms and exposed debugging functionality in Airoha’s custom […]
The post New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have disclosed details of what has been described as a “sustained and targeted” spear-phishing campaign that has published over two dozen packages to the npm registry to facilitate credential theft. The activity, which involved uploading 27 npm packages from six different npm aliases, has primarily targeted sales and commercial personnel at critical
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


