Your Cybersecurity Update for Thursday, 27 November 2025 (Ep.33)

RadioCSIRT English Edition
RadioCSIRT English Edition
Your Cybersecurity Update for Thursday, 27 November 2025 (Ep.33)
Loading
/

Welcome to your daily cybersecurity briefing.

CERT-FR: Advisory 2025-AVI-1042
CERT-FR has issued a new advisory describing several critical vulnerabilities impacting Gitlab.

RomCom via SocGholish
Arctic Wolf reports a campaign in which the RomCom threat group leveraged the SocGholish delivery infrastructure for the first time to deploy a targeted Mythic loader. The intrusion targeted a U.S. company indirectly connected to Ukraine, highlighting the evolving infection chains associated with GRU Unit 29155.

ShadowV2 IoT Botnet
Fortinet has analyzed ShadowV2, a Mirai-based IoT botnet observed exclusively during the major AWS outage in October. The botnet exploited at least eight vulnerabilities across devices from D-Link, TP-Link, DigiEver, TBK, and others. Activity targeted routers, NAS systems, and DVRs across multiple sectors, with global impact.

Don’t Think – Patch Now !

Sources:

CERT-FR – 2025-AVI-1042
https://www.cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-1042/

Arctic Wolf – RomCom / SocGholish https://arcticwolf.com/resources/blog/romcom-utilizing-socgholish-to-deliver-mythic-agent-to-usa-companies-supporting-ukraine/

BleepingComputer – ShadowV2 Botnet https://www.bleepingcomputer.com/news/security/new-shadowv2-botnet-malware-used-aws-outage-as-a-test-opportunity/

Your feedback is welcome.
Email: radiocsirt@gmail.com
Website: https://www.radiocsirt.org
Weekly Newsletter: https://radiocsirtintl.substack.com