Skip to content

breach_cve_trends

AI and the Future of Offensive Security: Insights from Bruce Schneier and Bikash Barai

In a recent Fireside Chat, Bruce Schneier- renowned cryptographer, Harvard professor, and one of the most influential voices in cybersecurity- joined Bikash Barai, Founder & CEO of FireCompass, to discuss how AI is fundamentally reshaping pentesting, red teaming, and the future of cyber defense. Watch the Full Fireside Chat Recording Gain first-hand insights from Bruce… Read More »AI and the Future of Offensive Security: Insights from Bruce Schneier and Bikash Barai

Weekly Report: New Hacking Techniques and Critical CVEs 2 Dec – 10 Dec 2025

Between 2-10 December 2025, three developments stand out for enterprise defenders: Shai-Hulud 2.0 npm worm: A rapidly evolving supply chain threat abusing npm and GitHub Actions to build a self-propagating CI/CD worm, with active reporting and defensive guidance released during this week. The underlying campaign began in September but continued and evolved into December, especially… Read More »Weekly Report: New Hacking Techniques and Critical CVEs 2 Dec – 10 Dec 2025

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 2 Dec – 10 Dec 2025

From December 2-10, 2025, disclosures around an Oracle E‑Business Suite campaign, a large third‑party fintech breach, and several sector‑specific data exposures highlighted how platform and vendor compromises are driving multi‑organization risk. University of Phoenix confirmed a significant Oracle EBS breach tied to CVE‑2025‑61882, Marquis Software’s ransomware breach impacted over 74 U.S. banks and credit unions,… Read More »Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 2 Dec – 10 Dec 2025

React2Shell (CVE-2025-55182): Pre‑Auth RCE In React & Next.js- A Log4Shell‑Style Wake‑Up Call

On 3rd December 2025, a critical remote code execution vulnerability was disclosed in the React Server Components (RSC) ecosystem, widely known as React2Shell and tracked as CVE‑2025‑55182 (React) and CVE‑2025‑66478 (Next.js, later merged into the main CVE). The flaw allows unauthenticated remote code execution (pre‑auth RCE) on servers using React Server Components and frameworks like… Read More »React2Shell (CVE-2025-55182): Pre‑Auth RCE In React & Next.js- A Log4Shell‑Style Wake‑Up Call

Inotiv Ransomware Attack

Date of Incident: August 2025 Overview: In August 2025, Inotiv, a healthcare services company, suffered a ransomware attack that disrupted business operations and compromised the personal information of 9,542 individuals. The cyberattack involved exploiting vulnerable remote access services and phishing techniques, encrypting 162,000 files totaling 176 GB. The attack aligned with MITRE ATT&CK techniques, featuring… Read More »Inotiv Ransomware Attack