IT Security News Daily Summary 2025-12-18

169 posts were published in the last hour 22:32 : RegScale Open Sources OSCAL Hub to Further Compliance-as-Code Adoption 22:2 : Hewlett Packard Enterprise (HPE) fixed maximum severity OneView flaw 21:2 : HPE OneView Vulnerability Allows Remote Code Execution Attacks…

APT35 Leak Reveals Spreadsheets Containing Domains, Payments, and Server Information

Iranian cyber unit Charming Kitten, officially designated APT35, has long been dismissed as a noisy but relatively unsophisticated threat actor a politically motivated collective known for recycled phishing templates and credential-harvesting pages. Episode 4, the latest intelligence dump, fundamentally rewrites…

New Lazarus and Kimsuky Infrastructure Discovered with Active Tools and Tunneling Nodes

Security researchers from Hunt.io and Acronis Threat Research Unit have uncovered a sophisticated network of operational infrastructure controlled by North Korean state-sponsored threat actors Lazarus and Kimsuky. The collaborative investigation revealed previously undocumented connections between these groups’ campaigns, exposing active…

FBI Confirms 630 Million Stolen Passwords

The cybersecurity landscape has faced a series of alarming developments this week, culminating in the FBI’s announcement regarding a massive cache of stolen data. Investigators discovered 630 million passwords stored on hardware confiscated from an individual hacker, highlighting the scale…