MacSync Stealer Evolution: A Threat Report MacSync Stealer Evolution: A Threat Report Executive Summary This report details the evolution of the MacSync Stealer malware, a macOS threat that has transitioned from relatively simple delivery mechanisms –
Continue ReadingMonth: December 2025
WatchGuard Firewall Hijacking via Zero-Day Vulnerability
Threat Report: WatchGuard 0-day Exploitation Threat Report: WatchGuard 0-day Exploitation Report Published: December 21, 2025 18:13:42.191Z Source: CyberHunter_NL Executive Summary This report details the active exploitation of a critical zero-day vulnerability within WatchGuard firewalls. Hackers are
Continue ReadingUAT 9686 Targets Cisco Secure Email Gateway and Web Manager
Threat Overview On 2025-12-17 AlienVault released a new threat report titled UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager. The report details a Chinese-nexus advanced persistent threat (APT) that has been
Continue ReadingDeep Dive Into BlackForce Phishing Kit
Threat Overview In the latest intelligence released by AlienVault on 12 December 2025, the cybersecurity community is warned about the BlackForce phishing kit. First observed in August 2025, this kit has undergone rapid evolution, with multiple
Continue ReadingPeerBlight Linux Backdoor Exploits React2Shell Vulnerability
Threat Overview On 2025-12-10 AlienVault released a detailed threat report titled PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182. The report documents a critical vulnerability in React Server Components (CVE-2025-55182) that has already been actively exploited across multiple
Continue ReadingPeerBlight Linux Backdoor Exploits React2Shell Vulnerability
In the latest intelligence gathering, security analysts have identified a sophisticated and highly automated threat actor group that is actively exploiting a critical vulnerability in React Server Components, identified as CVE‑2025‑55182. The group, referred to in
Continue ReadingPeerBlight Linux Backdoor Exploits React2Shell Vulnerability
Threat Overview: PeerBlight Linux Backdoor Exploits React2Shell Vulnerability In a recent publication released on December 10, 2025, security researchers from AlienVault have identified a critical vulnerability in React Server Components, designated as CVE‑2025‑55182. The vulnerability is
Continue ReadingInDepthAnalysisReact2ShellCVE202555182ExploitMechanics
Introduction In the rapidly evolving landscape of cloud-native development, the React Server Components (RSC) feature has emerged as a powerful tool for building high-performance applications. However, a newly disclosed vulnerability, CVE-2025-55182, commonly referred to as “React2Shell,”
Continue ReadingArray AG Gateways Command Injection Exploitation Confirmed
Executive Summary On 2025-12-08, CyberHunter_NL released a threat report titled JPCERT Confirms Active Command Injection Attacks on Array AG Gateways. The alert, issued by JPCERT/CC, confirms that a previously unassigned command‑injection vulnerability in Array Networks’ AG
Continue ReadingZero Day Exploits Continue Prolific
On December 4 2025 AlienVault released a new threat report titled Prolific Zero-Day Exploits Continue. The report details the ongoing activities of the cyber‑espionage group Intellexa, which has continued to develop sell and deploy zero‑day vulnerabilities
Continue Reading