
Loading summary
A
From the CISO series. It's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Wednesday, December 10, 2025. I'm Sarah Lane, Spain Arrest over data Records Spanish authorities arrested a 19 year old in Barcelona for allegedly stealing 64 million personal records from nine companies and attempting to sell them online. The data included names, addresses, emails, phone numbers, DNI numbers and ibans. The teen used multiple accounts and pseudonyms on hacker forums, computers and cryptocurrency. Wallets linked to the sales were confiscated. Separately, Ukrainian cyber Police arrested a 22 year old who sold access to hacked switch social media accounts using custom malware and a 5000 account bot farm. Facing up to 15 years in prison. Goodbye Dark Telegram Kaspersky analyzed more than 800 blocked cybercrime channels on Telegram and found the underground is steadily moving away from the platform due to rising shutdowns. The median lifespan of illicit channels grew from five months in 2021 through 2022 to to nine months in 2023 through 2024, but blocking activity accelerated since late 2024. Telegram's lack of default end to end encryption, centralized infrastructure and closed server code make it less attractive to experienced operators. Scammers poison AI search Results Scammers appear to be manipulating the public websites that AI tools rely on, causing systems like Google's AI Overview and Perplexity's comment to recommend fraudulent customer support numbers. Researchers at Aurascapes Ora Labs say that attackers are planting Geo and AEO optimized spam across compromised government and university sites, WordPress blogs, YouTube descriptions and Yelp reviews. LLMs then scrape and merge this poison content into answers that look legitimate. Tests showed bogus numbers for Emirates and British Airways surfaced by both Perplexity and Google. React to Shell tied to North Korea Sysdig researchers say that new React to Shell attacks are starting to resemble North Korean intrusion campaigns. The team found a compromised app dropping Ether Rat, a remote access trojan that uses Ethereum smart contracts for command and control and installs five persistent mechanisms. The tooling overlaps with DPRK linked contagious interview activity, suggesting either North Korean operators have adopted React, who Shell or multiple state groups are sharing techniques. Sysdig says Ether Rat reflects a shift from opportunistic crypto mining to stealthy long term access with blockchain based C2 and resilient persistence.
Huge thanks to our sponsor Adaptive Security. This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Picture a new hire who interviews well accept their synthetic AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs and access. That is the new reality. The attack surface is trust itself. Adaptive fights back with realistic deep fake simulations and training that actually sticks. Learn more@adaptivesecurity.com.
Humanoid robots go Mainstream Security experts warn that the rise of AI powered humanoid robots poses new cyber risks, including the potential for physical botnets. With forecasts of billions of robots by 2060 across industries and households, vulnerabilities in connectivity, AI learning and embedded sensors could allow attacks, espionage or hijacking. A recent proof of concept exploited unitree robots Bluetooth interface allowing wormable malware Experts predict a new sector for humanoid robot cybersecurity we will emerge Fortinet warns of bypass flaws Fortinet patched critical vulnerabilities in Fort OS, Forti, Web, Fort Proxy and FortiSwitch Manager that could let attackers bypass forticloud SSO authentication exploits abuse weak cryptographic signature verification via malicious SAML messages for to cloud. SSO is not enabled by default, but admins should disable it if it's active until updating. Additional fixes address unverified password changes and hash based authentication bypasses. Khashoggi Widow files Complaint Hanan Alader Khashoggi has filed a complaint in France alleging that Saudi Arabia infected her devices with NSO Groups PA Pegasus spyware before Jamal Khashoggi's 2018 murder. The filing cites Citizen Lab's analysis showing both her phones were compromised, likely during questioning in the United Arab Emirates, and argues that interception is linked to events leading to her husband's death. A French judge will decide whether to investigate. A US judge dismissed her earlier lawsuit against NSO in in 2023 Castle Loader as Gray Bravo Expands Malware service Recorded Futures Insect Group has identified four distinct threat clusters using the Castle Loader Malware Loader, highlighting Gray Bravo's expansion as a malware as a service provider. Gray Bravo's toolkit includes Castle Rat and Castlebot, which deploys dll, EXE and PE payloads for such as Deer Stealer, Redline Stealer and netsupport Rats. The clusters exploit phishing, click fix campaigns, fake software updates and malvertising, often targeting logistics and travel sectors. Operations leverage multi tiered infrastructure including tier 1 C2 servers and VPs backups. If you have thoughts on the news from today or about our show in general, be sure to reach out to us@feedbackisoseries.com we really want to hear from you. I am Sarah Lane reporting for the CISO series and you stay classy. Planet Earth.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Host: Sarah Lane
Podcast: CISO Series – Cyber Security Headlines
Episode Date: December 10, 2025
This episode delivers concise updates on the most pressing stories in the infosec world, including a major arrest in Spain over stolen records, a shift away from Telegram by cybercriminals, AI search results compromised by scammers, growing ransomware-as-a-service threats, and emergent cybersecurity concerns regarding humanoid robots, among others. The discussion highlights evolving attack techniques and the complexities facing security professionals as technology and threat landscapes rapidly change.
Incident: Spanish authorities arrested a 19-year-old in Barcelona for stealing 64 million personal records from nine companies. The data included names, addresses, emails, phone numbers, DNI numbers, and IBANs.
Details:
Related Story: Ukrainian cyber police also arrested a 22-year-old selling access to hacked social media accounts via custom malware and a bot farm (5,000 accounts). The suspect faces up to 15 years in prison.
“The teen used multiple accounts and pseudonyms on hacker forums, computers and cryptocurrency wallets linked to the sales were confiscated.”
— Sarah Lane (00:17)
Analysis: Kaspersky found a decline in cybercrime activity on Telegram as law enforcement shut down more illicit channels.
Trends:
Implication: Cybercriminals are seeking alternative, more secure platforms.
“The underground is steadily moving away from the platform due to rising shutdowns.”
— Sarah Lane (01:10)
Issue: Attackers are manipulating websites that AI models use for generating answers, causing AI platforms like Google’s AI Overview and Perplexity’s comment to suggest fraudulent customer support numbers.
Tactics:
Impact: AI-generated responses appear legitimate but provide users with scam contact numbers.
Proof: Researchers found phony support numbers for Emirates and British Airways in both Google and Perplexity results.
“LLMs then scrape and merge this poison content into answers that look legitimate.”
— Sarah Lane (01:56)
Discovery: Sysdig researchers identified a new wave of React to Shell attacks that mirror North Korean hacking campaigns.
Mechanism:
Significance: Represents a shift from opportunistic cryptocurrency mining to stealthy, blockchain-based long-term access.
Attribution: Likely North Korean operators or shared tactics among state groups.
“Sysdig says Ether Rat reflects a shift from opportunistic crypto mining to stealthy long term access with blockchain based C2 and resilient persistence.”
— Sarah Lane (02:59)
Warning: As AI-powered humanoid robots move toward mainstream adoption, experts warn of new “physical botnet” threats.
Forecast: Billions of robots could be in use by 2060.
Security Flaws: Vulnerabilities in connectivity, AI learning, and embedded sensors could allow for attacks, espionage, or hijacking.
Proof-of-Concept: Bluetooth flaws in Unitree robots demonstrated the feasibility of wormable malware in robots.
“A recent proof of concept exploited Unitree robots’ Bluetooth interface allowing wormable malware.”
— Sarah Lane (04:22)
Update: Fortinet patched major vulnerabilities in its FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager products.
Vulnerability: Attackers could bypass FortiCloud SSO authentication by exploiting weak cryptographic verification of SAML messages.
Advice: Admins should disable SSO until updates are applied.
Other Fixes: Also addressed password change and authentication bypass issues.
“Admins should disable it if it’s active until updating.”
— Sarah Lane (05:23)
Threat: Recorded Future’s Insect Group highlights four distinct threat clusters utilizing the Castle Loader malware service, underlining Gray Bravo’s expansion.
Techniques: Includes use of CastleRat and CastleBot to deliver multiple payloads (Deer Stealer, Redline Stealer, NetSupport RATs).
Tactics: Phishing, malicious software updates, malvertising, and “click fix” campaigns, targeting logistics and travel sectors.
“Operations leverage multi-tiered infrastructure including tier 1 C2 servers and VPs backups.”
— Sarah Lane (06:39)
“The attack surface is trust itself.”
— Sponsor ad for Adaptive Security (03:30)
“Experts predict a new sector for humanoid robot cybersecurity will emerge.”
— Sarah Lane (04:37)
Sarah Lane delivers crisp, factual updates with urgency and clarity, emphasizing both the evolving nature of cyber threats and the expanding complexity of safeguarding data, devices, and people.
For more details or to dive into individual stories, visit CISOseries.com.