LIVE NEWS
  • Calls for Global Digital Estate Standard as Fraud Risk Grows
  • An ode to craftsmanship in software development
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
  • Some Middle East Flights Resume but Confusion Reigns From Iran Strikes
  • Clinton Deposition Videos Released in Epstein Investigation
  • Elevance stock tumbles as CMS may halt Medicare enrollment
  • Wild spaces for butterflies to be created in Glasgow
  • You can now adjust how your caller card looks for calls on Android phones
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor
Cybersecurity

In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor

primereportsBy primereportsDecember 5, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor
Share
Facebook Twitter LinkedIn Pinterest Email


SecurityWeek’s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports. 

Here are this week’s stories:

Claude Skills used to execute ransomware

Cato Networks has used Skills, a new feature for Anthropic’s Claude AI assistant, to execute ransomware in a controlled environment. Antrophic says the code execution functionality works as intended for Skills. Cato argues that legitimate Skills could be weaponized via minor changes, and that they can propagate through public repositories and social engineering. However, the security firm admits that Claude displays clear approval prompts to the user. 

Array vulnerability exploited in the wild

Japan’s JPCERT/CC has warned that a vulnerability affecting Array Networks’ AG secure access gateways has been exploited in attacks. The flaw, a command injection issue that does not have a CVE identifier, was patched in May 2025 with the release of ArrayOS AG 9.4.5.9. JPCERT has found evidence that the vulnerability has been exploited against users in Japan since August 2025. The impacted product is prevalent in Asia. 

Advertisement. Scroll to continue reading.

North Korea suspected of $30 million Upbit cryptocurrency heist

Upbit, a major South Korea-based cryptocurrency exchange, recently had roughly $30 million of cryptocurrency stolen. The heist is believed to be the work of the North Korean hacking group Lazarus. Back in 2019, hackers stole $49 million worth of Ethereum from Upbit. 

Akamai patches HTTP request smuggling vulnerability

Akamai announced this week that it recently patched a vulnerability tracked as CVE-2025-66373 that could have exposed customers to HTTP request smuggling attacks. These types of attacks can typically be leveraged to steal credentials or other sensitive data, and to redirect users to arbitrary websites. HTTP request smuggling makes headlines every few years due to its potentially significant impact. 

CISA staff told not to speak with reporters

A leaked internal email revealed that leadership at the cybersecurity agency CISA has asked staff not to talk to news reporters in an unauthorized capacity, according to Nextgov/FCW. “In today’s culture of information saturation, it is imperative that we ensure all official information communicated on behalf of CISA is current, accurate, unbiased, and authoritative. This includes any official information communicated to the media,” the email reads. It’s unclear whether the memo was triggered by a particular incident.

North Korean fake IT worker recruiters caught on camera

Researchers conducted a thorough investigation into North Korea’s fake IT worker scheme, detailing how legitimate developers are lured into renting their credentials and identities to secure remote jobs in companies that prohibit hiring from the country. The investigation, which included video calls with several North Korean recruiters, revealed that the recruiters asked for 24/7 access to the developer’s computer to facilitate the masquerade.

X fined €120 million over disinformation

The European Commission has fined the social media company X with €120 million ($139 million) over its alleged failures to handle disinformation. The fine was issued under the Digital Services Act (DSA), which requires companies to protect users against disinformation and influence operations or face fines of up to 6% of their turnover. 

New MuddyViper backdoor used by Iranian cyberspies 

The Iranian cyberespionage group named MuddyWater has developed a new backdoor dubbed MuddyViper by ESET. The security firm has observed attacks aimed at Israel, with at least one victim in Egypt. Unlike previous MuddyWater attacks, which were noisy and easy to detect, the new activity was more focused and sophisticated.

PickleScan vulnerabilities

JFrog has disclosed the details of three recently patched PickleScan vulnerabilities. PickleScan is a tool for scanning machine learning (ML) models to detect malicious content. The vulnerabilities found by JFrog could have been exploited to “evade PickleScan’s malware detection and potentially execute a large-scale supply chain attack by distributing malicious ML models that conceal undetectable malicious code”.

Related: In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked

Related: In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePromise and Perils of Using AI for Hiring: Guard Against Data Bias 
Next Article Keir Starmer rejects EU customs union after Lammy comments
primereports
  • Website

Related Posts

Cybersecurity

Calls for Global Digital Estate Standard as Fraud Risk Grows

March 4, 2026
Cybersecurity

Samsung Unpacked 2026 live blog: Updates on Galaxy S26 Ultra, preorder deals, and pricing

February 25, 2026
Cybersecurity

Marquis sues SonicWall over backup breach that led to ransomware attack

February 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20255 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Calls for Global Digital Estate Standard as Fraud Risk Grows
  • An ode to craftsmanship in software development
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.