Open Source Alerts

Officials accuse North Korea’s Lazarus of $30 million theft from crypto exchange

A recent cyberattack on South Korea's largest cryptocurrency exchange, Upbit, resulted in the theft of $30 million. The attack is attributed to North Korea's Lazarus Group.

Google addresses 107 Android vulnerabilities, including two zero-days

Google's December security update for Android addresses 107 vulnerabilities, including two high-severity zero-day vulnerabilities, CVE-2025-48633 and CVE-2025-48572. This update marks the second-highest number of vulnerabilities patched this year.

Full Disclosure: [REVIVE-SA-2025-005] Revive Adserver Vulnerability

A vulnerability in Revive Adserver, identified as CVE-2025-55129, has been reported. This vulnerability involves an incomplete list of disallowed inputs, allowing for potential impersonation attacks.

Police takes down Cryptomixer cryptocurrency mixing service

Law enforcement agencies in Switzerland and Germany have successfully dismantled the Cryptomixer cryptocurrency mixing service. This operation, known as "Operation Olympia," resulted in the seizure of €24 million in Bitcoin.

South Korea’s Coupang Hit by Massive Data Breach Affecting Nearly 34 Million Customers

Coupang, a leading South Korean e-commerce platform, has experienced a massive data breach affecting nearly 34 million customers. This incident is one of the largest cybersecurity breaches in South Korea in recent years.

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a cross-site scripting (XSS) vulnerability, CVE-2021-26829, in OpenPLC ScadaBR to its Known Exploited Vulnerabilities (KEV) catalog.

Brsk confirms breach as bidding begins for 230K+ records

British telco Brsk has confirmed a data breach involving unauthorized access to its customer database, affecting over 230,000 records. The stolen data includes customer names, email and home addresses, phone numbers, and installation details.

Contagious Interview campaign expands with 197 npm Ppackages spreading new OtterCookie malware

The "Contagious Interview" campaign, linked to North Korean threat actors, has expanded with the addition of 197 new malicious npm packages. This campaign targets software developers in the crypto and Web3 sectors.

PostHog admits Shai-Hulud 2.0 was its biggest security scare

PostHog experienced a major security incident involving the Shai-Hulud 2.0 npm worm, which compromised its JavaScript SDKs: posthog-node, posthog-js, and posthog-react-native.

Public GitLab repositories exposed more than 17,000 secrets

A researcher spotted 17,430 verified live secrets in public GitLab repositories, with a secret density 35% higher than in Bitbucket. These secrets include API keys, passwords, and tokens, posing significant security risks to affected organizations.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags