
Loading summary
A
From the CISO series, it's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Wednesday, December 17, 2025. I'm Sarah Lane. Rogue NuGet package steals data Researchers from Socket Security have uncovered a malicious NuGet package that impersonates the popular. NET library Tracer FODI to steal cryptocurrency wallet data. The typo squatted Package Tracer Fodi NL log sat in the NuGet repository for around six years, using name tricks and hidden code to exfiltrate Stratus wallet files and passwords to attacker controlled servers in Russia. Venezuela's PDVSA suffers Attack Reuters reports that Venezuela's state oil company PDVSA was hit by a ransomware attack that knocked out administrative systems, forcing workers offline and suspending oil cargo loadings, though production and refining were unaffected. This comes amid escalating tensions with the U.S. both PDVSA and the Venezuelan government blamed the U.S. for the attack. With more than 11 million barrels stranded on vessels patched Fortinet Flaws Exploited Attackers are actively exploiting two critical fortinet authentication bypass vulnerabilities that we talked to you about last week, shortly after Fortinet released patches. The flaws affect multiple Fortinet products when ForticLoud SSO is enabled and allow attackers to gain unauthenticated admin access via forged SAML assertions. Researchers at cybersecurity company Arctic Wolf observed attackers downloading system configuration files, exposing network details and credentials. Fortinet says patch immediately or disable forticloud SSO until systems are upgraded. Jump Cloud Windows Agent flaw the Latest Researchers at XM Cyber disclosed a critical local privilege escalation flaw in the JumpCloud remote assist for Windows Agent that allows low privileged users to gain system level access or trigger denial of Service attacks. The bug affects versions prior to 031.7.0 and stems from unsafe file operations during uninstallation, where a system level process interacts with user writable temp directories. JumpCloud has released a patch huge thanks to our sponsor, Adaptive Security. This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Picture a new hire who interviews well. Except they're synthetic AI, video, AI, voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality. The attack surface is trust itself. Adaptive fights back with realistic deep fake simulations and training that actually sticks. Learn more at adaptivesecurity. Com Amazon Warns of Sandworm Shifted Tactics Amazon Threat Intelligence warns that the Russia linked hacking group known as Sandworm is in an ongoing campaign against Western critical infrastructure, especially energy companies. Instead of exploiting software vulnerabilities, the group now primarily targets port poorly configured network edge devices hosted on AWS to gain and maintain access. Amazon says it has notified affected customers remediated compromised systems and that the activity reflects customer misconfigurations rather than flaws in AWS itself. Ink Dragon hides in European networks Researchers from Checkpoint report that a China linked espionage group known as Ink Dragon has expanded operations into European government networks, compromising misconfigured Microsoft IIS and SharePoint servers to steal credentials and establish long term access. The group uses victim infrastructure as covert relay nodes and updated its final draft backdoor to blend in with Microsoft cloud activity, including hiding command traffic in email drafts. A separate China linked group, Rude Panda, was also found to be accessing some of the same networks. Celiq Malware builds off Google Play apps Mobile security firm Iverify reports a new Android malware as a service called Selec that lets cybercriminals create Trojanized versions of legitimate Google Play apps. It is being sold on underground forums for $150 per month or $900 lifetime, and lets attackers wrap malware inside real apps while preserving their normal functionality, helping infections stay hidden longer and potentially evade play. Protect capabilities include screen streaming, file theft, credential harvesting via app overlays, hidden browser access using stored cookies and encrypted command and control communications. Beware of Gift Card Draining the US treasury is warning consumers about a surge in holiday cyber scams, highlighting business impersonation, fake charities and gift card draining as the most common threats. Scammers are increasingly using AI, voice cloning and cryptocurrency to make fraud more convincing and harder to trace. With losses from online shopping scams nearing hundreds of millions of dollars, the treasury urges consumers to verify charities and transactions, use secure payment methods, strengthen account security and report fraud quickly. Are you subscribed to the CISO Series YouTube channel? Because we're posting daily shorts about the biggest cybersecurity news of the day, as well as demos, interviews, original content and the best clips from across all of our podcasts. Make sure you are subscribed so you can stay up to date on our latest and greatest. If you have thoughts on the news from today or about our show in general, be sure to reach out to us at feedback and@cisoseries.com we really want to hear from you. I'm Sarah Lane reporting for the CISO Series. Stay classy out there, and we'll talk to you tomorrow.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Podcast: Cyber Security Headlines (CISO Series)
Host: Sarah Lane
Date: December 17, 2025
Episode Theme:
A rapid-fire overview of the most urgent cybersecurity stories of the day, detailing active threats, reported attacks, and latest vulnerability exploits targeting various organizations and individuals around the world.
This episode spotlights proactive and ongoing threats facing organizations and consumers: from sophisticated supply chain attacks (NuGet), disruptive ransomware against national infrastructure (PDVSA), critical product vulnerabilities under active exploit (Fortinet, JumpCloud), and increasingly sophisticated cybercriminal tactics (Sandworm, Celiq malware, and AI-driven gift card scams).
Sarah Lane’s fast-paced delivery and direct reporting style keep the focus on technical details, actionable recommendations, and emerging trends. The warning is clear: attackers are evolving quickly, making vigilance and rapid patching more crucial than ever.