CybersecKyle

196 Followers
696 Following
2K Posts

Above-average tech nerd. Father. Husband. Millennial. Associate C|CISO

I work in #IT focusing on Managed Services, Cybersecurity, and more.

Interests:
#IT #RMM #SysAdmin #CyberSecurity #InfoSec #Privacy #Python #Apple #iOS #Tech

searchable

Bloghttps://weblog.kylereddoch.me
Socialshttps://profile.kylereddoch.me
GitHubhttps://github.com/kylereddoch
Signal@beardedtechguy.86
Ko-Fihttps://ko-fi.com/kylereddoch

⭐📰 New Starred Article! 📰⭐

4 issues holding back CISOs’ security agendas

https://www.csoonline.com/article/4117010/4-issues-holding-back-cisos-security-agendas.html

4 issues holding back CISOs’ security agendas

58% of CISOs believe their organization is unprepared to respond to a cyberattack. Cyber execs and experts shed light on common strategy issues, providing advice on how to address them.

CSO Online
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads

A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as the KMSAuto tool for illegally activating Windows and Office software.

BleepingComputer

Cybersecurity researchers have disclosed details of what has been described as a "sustained and targeted" spear-phishing campaign that has published over two dozen packages to the npm registry to facilitate credential theft.

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials https://thehackernews.com/2025/12/27-malicious-npm-packages-used-as.html

#Cybersecurity #NPM #Phishing

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

Researchers uncovered 27 malicious npm packages used over five months to host phishing pages that steal credentials from targeted organizations.

The Hacker News
Top 5 Ransomware Attacks of 2025: Biggest Fallouts, Biggest Lessons

Discover the top 5 ransomware attacks of 2025, their devastating impacts, and crucial lessons for bolstering your cybersecurity strategies in 2026.

Horrible news for all those Firefox users.

Mozilla’s New CEO Confirms Firefox Will Become an “AI Browser” https://www.omgubuntu.co.uk/2025/12/mozilla-new-ceo-firefox-ai-browser-strategy

#Firefox #AI #Browsers

Mozilla's New CEO Says Firefox Will "Evolve" into an AI Browser - OMG! Ubuntu

Anthony Enzor-DeMeo has finally taken up his role as CEO of Mozilla Corporation, publishing a blog post to celebrate in which he spells out the company's

OMG! Ubuntu
CachyOS Wants to Improve Your Server Performance Now https://itsfoss.com/news/cachyos-server-edition-plans/
CachyOS Wants to Improve Your Server Performance Now

The devs plan a hardened server image with optimized packages and pre-tuned settings.

It's FOSS

beardedtechguy just liked 💙

🎶 'Tonight, Tonight' by Stephen Wilson Jr. on Last.fm. 🎶

https://www.last.fm/music/Stephen+Wilson+Jr./_/Tonight,+Tonight

#LastFM #Music

From yesterday: More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys.

Over 10,000 Docker Hub images found leaking credentials, auth keys https://www.bleepingcomputer.com/news/security/over-10-000-docker-hub-images-found-leaking-credentials-auth-keys/

#cybersecurity #docker

Over 10,000 Docker Hub images found leaking credentials, auth keys

More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys.

BleepingComputer

From yesterday:

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors https://thehackernews.com/2025/12/react2shell-exploitation-delivers.html

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

Critical React Server Components flaw (CVE-2025-55182) fuels automated attacks dropping miners and multiple new Linux malware families.

The Hacker News
Another Chrome zero-day under attack: update now

If we’re lucky, this update will close out 2025’s run of Chrome zero-days. This one is a V8 type-confusion issue already being exploited in the wild.

Malwarebytes