December Roundup of Trending News in Cybersecurity

Read more cybersecurity news in this edition of NetSec News.

Jessica Owens

MSSP Training & Development Coordinator, T2 SOC Analyst

North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks

North Korean hackers are exploiting the critical React2Shell vulnerability to deploy a sophisticated Linux-focused backdoor called EtherRAT that uses multiple persistence methods and even blockchain-based communication, signaling a dangerous escalation in state-linked malware attacks. (BleepingComputer)

“The EtherRAT incident shows how attackers are hiding their control channels inside trusted public infrastructure making them difficult to block or shut down. The real risk is not just the initial breach, but long term invisible access that allows attackers to quietly maintain control and monitor activity over time. For organizations using React or Next.js, patching and post incident checks are critical, as these attacks are designed to remain hidden and persist.”
– Alex Malooley, Tier 2 SOC Analyst at C3 Integrated Solutions

Agentic browsers promise productivity—but Gartner says they’re too dangerous to touch

AI powered agentic browsers promise major productivity gains, but Gartner warns they pose serious security risks due to autonomous actions, excessive access to sensitive data, and a lack of enterprise controls, making them too risky to adopt right now. (Security Buzz)

Beyond the watering hole: APT24’s pivot to multi-vector attacks

China-linked APT24 has shifted to multi-vector attacks using highly obfuscated BADAUDIO malware delivered through compromised websites, supply chain attacks and targeted phishing, showing three years of evolution and rising sophistication that defenders need to understand and mitigate. (Google Cloud Blog)

$400,000 worth of lobster stolen en route to Costco stores, shipper says

A shipment of lobster worth about $400,000 bound for Costco stores in Illinois and Minnesota was stolen after criminals posing as a legitimate carrier picked up the load in Massachusetts and drove off with it, highlighting a rising trend in sophisticated cargo theft that could disrupt supply chains and raise consumer costs. (NBC News)

Featured Chrome browser extension caught intercepting millions of users’ AI chats

A “Featured” Google Chrome extension with millions of users was secretly capturing and sending every prompt from AI chat services like ChatGPT, Gemini and Claude to remote servers, exposing vast amounts of potentially sensitive user data and showing how marketplace trust can be abused by malicious software. (The Hacker News)

CISA, NSA and Cyber Centre warn critical infrastructure of BRICKSTORM malware used by People’s Republic of China state-sponsored actors

U.S., Canadian & NSA cybersecurity teams warn that Chinese state-linked hackers are using a stealthy backdoor malware called Brickstorm to infiltrate and persist in critical infrastructure systems like VMware and Windows — urging urgent scans, patches, and threat hunting. (CISA)

Meet the Author

Jessica Owens

MSSP Training & Development Coordinator, T2 SOC Analyst

Jessica Owens serves as both MSSP Training & Development Coordinator and T2 SOC Analyst at C3 Integrated Solutions, roles which bring a unique dual perspective to the team. Holding Sec+, ITILv4, CPO, and PORP certifications, she specializes in bridging gaps between technical security operations, client care and success, and team development. She is passionate about creating operational solutions that streamline processes, improve functionality, and strengthen team cohesion. Through her role as SOC Liaison for Network Security News, she contributes to delivering timely insights on critical threats and industry challenges for both general and organizational audiences.