Skip to content

  • Home
  • Tools
    • IOC Defang/Refang Tool
    • Universal Encoder Decoder
    • File Hash Calculator
    • Password Crack Time Simulator
    • Multi-URL IOC Checker
  • CyberSecurity News
  • Latest Cyber Attack
  • Vulnerabilities
  • Threat Advisories
  • MITRE ATT&CK
    • Collection
    • Command and Control
    • Credential Access
    • Defense Evasion
    • Discovery
    • Execution
    • Exfiltration
    • Impact
    • Initial Access
    • Lateral Movement
    • Persistence
    • Privilege Escalation
    • Reconnaissance
    • Resource Development
  • Ransomware
  • Malware
  • Cyber Kill Chain

  • Home
  • Tools
    • IOC Defang/Refang Tool
    • Universal Encoder Decoder
    • File Hash Calculator
    • Password Crack Time Simulator
    • Multi-URL IOC Checker
  • CyberSecurity News
  • Latest Cyber Attack
  • Vulnerabilities
  • Threat Advisories
  • MITRE ATT&CK
    • Collection
    • Command and Control
    • Credential Access
    • Defense Evasion
    • Discovery
    • Execution
    • Exfiltration
    • Impact
    • Initial Access
    • Lateral Movement
    • Persistence
    • Privilege Escalation
    • Reconnaissance
    • Resource Development
  • Ransomware
  • Malware
  • Cyber Kill Chain

December 2025

CVE-2025-68665: LangChain JS Serialization Injection via Trusted lc Object Spoofing

  • Threat Advisories
AegironDecember 24, 2025December 24, 20258 mins0
Overview CVE ID: CVE-2025-68665Product: LangChain (JavaScript / TypeScript ecosystem)Affected Area: Object serialization and deserialization (toJSON() and JSON.stringify())CVSS…
continue reading..

CVE-2025-68664: When User Input Masquerades as Trusted LangChain Objects

  • Threat Advisories
AegironDecember 24, 2025December 24, 20259 mins0
Overview CVE ID: CVE-2025-68664Affected Product: LangChainVulnerability Type: Serialization Injection / Trust Boundary Bypass Affected Versions: CVSS v3.1…
continue reading..

CVE-2025-68667: Unauthenticated Attackers Can Force Matrix Servers to Sign Fake Membership Events

  • Threat Advisories
AegironDecember 24, 2025December 24, 202510 mins0
Executive Summary CVE-2025-68667 is a high-risk security vulnerability affecting Continuwuity, a Matrix homeserver written in Rust. The…
continue reading..

GhostLocker : Windows AppLocker weaponized to neutralize and control EDR

  • Latest Cyber Attack
CyberDefenderDecember 24, 2025December 24, 20255 mins0
GhostLocker is a new tool/technique revealed by researchers that shows how attackers can misuse Windows AppLocker —…
continue reading..

CVE-2025-68669: Critical Remote Code Execution via Malicious Mermaid Diagrams in 5ire

  • Threat Advisories
AegironDecember 24, 2025December 24, 202510 mins0
Quick overview CVE ID: CVE-2025-68669Vulnerability name: 5ire Markdown / Mermaid Remote Code ExecutionSeverity: CriticalCVSS score: 9.6Risk level:…
continue reading..

CVE-2025-68696: High-Risk Server-Side Request Forgery in httparty Ruby Library

  • Threat Advisories
AegironDecember 24, 2025December 24, 20258 mins0
Overview (At a Glance) What This Vulnerability Means This vulnerability allows an attacker to trick a server…
continue reading..

Insider-Enabled SIM Swapping: Threat Model, IOCs, and Defensive Controls

  • Latest Cyber Attack
CyberDefenderDecember 24, 2025December 24, 20255 mins0
1. Executive Summary Criminal groups are increasingly recruiting organizational insiders via darknet forums to enable SIM swapping…
continue reading..

JSCEAL Campaign Evolution – Technical Analysis

  • Latest Cyber Attack
CyberDefenderDecember 24, 2025December 24, 20256 mins0
Reporting Period: August 2025Threat Type: JavaScript-based malware delivery with multi-stage C2Primary Vector: Paid social media advertisingTarget Profile:…
continue reading..

Malicious Crypto Miners Hide in Plain Sight

  • Malware
CyberDefenderDecember 24, 2025December 24, 20255 mins0
Miner malware (also called cryptomining malware or cryptojacking malware) is malicious software that secretly uses your device’s…
continue reading..

WinRing0 : No Exploit Required and Kernel Takeover

  • Malware
CyberDefenderDecember 24, 2025December 24, 20255 mins0
WinRing0 is not inherently malware. It is a legitimate Windows kernel-mode driver (WinRing0x64.sys / WinRing0.sys) originally designed…
continue reading..
  • 1
  • …
  • 16
  • 17
  • 18
  • 19
  • 20
  • …
  • 41

Recent Posts

  • Ransomware Group ‘Gentlemen’ Industrializes EDR Evasion with Kernel-Le…
    Jun 22, 2026
  • SmartApeSG Compromises Okendo Reviews Widget, Exposing Thousands of E-…
    Jun 22, 2026
  • Cybercriminals Exploit Fake Microsoft Teams Transcripts to Deploy Pers…
    Jun 22, 2026
  • Thousands Targeted, Hundreds Compromised: Inside the FortiBleed Creden…
    Jun 22, 2026
  • Novel GhoLoader malware campaign detected, using unique ’10 mous…
    Jun 22, 2026
  • INC Ransomware Emerges as a Major Global Cyber Threat, Rapidly Expandi…
    Jun 19, 2026
  • Dropping Elephant Deploys Advanced Fileless Malware, Neutralizing AMSI…
    Jun 19, 2026
  • ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Compromises Universi…
    Jun 19, 2026
  • Cybercriminals Weaponize Wallpaper Engine to Hijack Steam Accounts in …
    Jun 19, 2026
  • AI-Powered ClickFix Campaign Targets Brazilian Banks, Deploys SmartRAT…
    Jun 19, 2026

Popular Posts

  • Thousands Targeted, Hundreds Compromised: Inside the FortiBleed Creden…
    Jun 22, 2026
  • Cybercriminals Exploit Fake Microsoft Teams Transcripts to Deploy Pers…
    Jun 22, 2026
  • SmartApeSG Compromises Okendo Reviews Widget, Exposing Thousands of E-…
    Jun 22, 2026
  • Novel GhoLoader malware campaign detected, using unique ’10 mous…
    Jun 22, 2026
  • Ransomware Group ‘Gentlemen’ Industrializes EDR Evasion with Kernel-Le…
    Jun 22, 2026

Find Me On

© 2026 CyberP1. All Rights Reserved.
  • Contact
  • Privacy Policy
  • Terms of Service