Transcript
A (0:00)
From the CISO series, it's Cybersecurity Headlines.
A (0:06)
These are the cybersecurity headlines for Thursday, December 4, 2025. I'm Lauren Verno.
A (0:16)
Record breaking DDoS attack Azuro just broke the DDoS record again, firing off a massive 29.7 terabyte per second attack that Cloudflare had to absorb. This botnet is basically a rentable army of up to 4 million hacked routers and IoT devices, and it's been hammering targets all year. Cloudflare says nearly half of those attacks are now hypervolumetric, and one recent wave even disrupted parts of the US Internet despite not being the intended target.
A (0:59)
React bug puts servers at risk A maximum severity vulnerability in React server components could let attackers run arbitrary code on servers without authentication. The flaw affects apps using React server function endpoints and even Next JS with app router as well as libraries bundling RSC like Veit parcel and redwood. JS researchers warn nearly 40% of cloud environments may be exposed.
A (1:36)
Ransom House attack cripples retailer Japan's A school is finally getting back online six weeks after a ransomware attack forced companies to to order supplies by fax, the Japanese retailer Think Staples meets Amazon for office goods, has reopened limited online sales for corporate customers and says it'll gradually restore its full catalog. The ransom house attack exposed customer and supplier data and disrupted supply chains for brands like Muji, which later confirmed its own customer data was affected. It's the latest in a wave of major ransomware hits on Japanese companies, including Asahi, which is still recovering months later.
A (2:26)
Ransomware payment Denied Unless.
A (2:30)
The UK Government is moving forward with a proposed ban on ransomware payments for public sector and critical national infrastructure organizations with national security exemptions to avoid life or death dilemmas. That's from Security Minister Dan Jarvis. The legislation would also require other businesses to notify authorities if they plan to pay a ransom. Jarvis called the current system quote not sustainable and is consulting across government, CNI organizations and allies in the five eyes and G7 to ensure the ban is effective and and workable.
A (3:14)
Huge thanks to today's episode sponsor Vanta. This message comes from vanta. What's your 2am Security worry? Is it do I have the right controls in place or are my vendors secure? Enter Vanta Vanta automates manual work so you can stop sweating over spreadsheets, chasing audit evidence and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data and simplifies your security at scale. Get started@vanta.com CISO that's V A N T A.com CISO foreign.
