Security Highlights Of The Day [08/12/25]
New Wave of VPN Login Attempts Targets Palo Alto GlobalProtect Portals
A large campaign began on December 2, targeting Palo Alto GlobalProtect portals with brute-force attempts and later scanning SonicWall SonicOS API endpoints. The activity originated from over 7,000 IPs tied to hosting provider 3xK GmbH (AS200373), according to GreyNoise.
Source: BleepingComputer
AI-Automated Threat Hunting Brings GhostPenguin Out of the Shadows
Trend Micro uncovered GhostPenguin, a multithreaded Linux backdoor using RC5-encrypted UDP communications, discovered via AI-driven automated threat hunting. The backdoor supports remote shell access, file operations, and resilient command delivery through synchronized threads.
Source: Trend Micro
China-Linked Warp Panda Targets North American Firms in Espionage Campaign
CrowdStrike reports that Warp Panda is conducting advanced cyber espionage against North American legal, tech and manufacturing firms. The actor demonstrates strong OPSEC and cloud/VM expertise, with observed targeting of VMware vCenter environments in 2025.
Source: Infosecurity Magazine
Over 70 Domains Used in Months-Long Phishing Spree Against US Universities
Infoblox uncovered a months-long phishing operation targeting at least 18 U.S. universities. Attackers used more than 70 domains and bypassed MFA using the Evilginx adversary-in-the-middle toolkit to steal login credentials.
Source: Hackread
Inside Shanya, a Packer-As-A-Service Fueling Modern Attacks
Sophos analyzed Shanya, a new packer-as-a-service tool now favored by ransomware groups, partially replacing HeartCrypt. Shanya supports complex obfuscation and has been used in targeted attacks observed during incident response operations.
Source: Sophos
‘Broadside’ Mirai Variant Targets Maritime Logistics Sector
Cydome researchers identified “Broadside,” a Mirai variant exploiting CVE-2024-3721 in maritime digital recording devices. The flaw enables remote command injection and persistent monitoring via Netlink, threatening global logistics operations.
Source: Dark Reading
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE
Security researcher Ari Marzouk disclosed 30+ vulnerabilities in AI-powered IDEs like Cursor, Windsurf, GitHub Copilot, Roo Code, Zed.dev and others. The flaws, dubbed “IDEsaster,” combine prompt injection with legitimate features to enable data exfiltration and remote code execution.
Source: The Hacker News
Marquis Software Breach Affects Over 780,000 Nationwide
Marquis Software confirmed a breach affecting more than 780,000 individuals after attackers exploited a SonicWall vulnerability to access and exfiltrate sensitive files from its systems. The impacted data included financial and personal information from client institutions.
Source: Infosecurity Magazine
LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak
Researchers identified LockBit 5.0 infrastructure hosted on 205.185.116.233 and the domain karma0.xyz, both tied to PONYNET. The exposure reveals operational details amid LockBit’s resurgence with upgraded malware capabilities.
Source: Cybersecurity News
AWS: China-Linked Threat Actors Weaponized React2Shell Hours After Disclosure
AWS warns that China-linked threat actors began exploiting the newly disclosed React2Shell vulnerability (CVE-2025-55182) within hours. Although AWS services are unaffected, the flaw impacts organizations running vulnerable React/Next.js deployments.
Source: Security Affairs