Security vendors and open-source communities released significant updates in November 2025 to improve detection and mitigation of emerging threats. Detection rule repositories such as Sigma, Splunk, Elastic, and Neo23x0 introduced new and refined rules targeting AWS defense evasion, supply chain attacks, and the Shai-Hulud worm, while Elastic added higher-order correlation rules to link endpoint and network alerts. ProjectDiscovery’s Nuclei Templates saw two major releases, adding 197 new templates and coverage for 83 CVEs, including 19 actively exploited vulnerabilities from CISA’s KEV catalog, with a focus on high-fidelity detection for enterprise and cloud environments.
Sysdig highlighted critical vulnerabilities affecting container runtimes (runc) and the Linux kernel, urging immediate patching and providing detection guidance for their customers. These efforts reflect a broader industry push to address both newly discovered and actively exploited vulnerabilities, with coordinated detection engineering and rapid template development to help organizations stay ahead of evolving attacker techniques and campaigns.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Across November 2025, ProjectDiscovery released Nuclei Templates versions 10.3.2 and 10.3.4, adding 197 new templates and coverage for 83 CVEs, including 19 vulnerabilities from CISA's Known Exploited Vulnerabilities catalog. The releases also improved detection fidelity and added capabilities such as HTTP/2 support and enhanced protocol detection.
Between 2025-11-24 and 2025-12-01, eight major GitHub detection repositories added 61 new rules and modified 36 others. The updates expanded coverage for AWS defense evasion, the Shai-Hulud worm, phishing, macOS and Linux behaviors, and correlation-based detections while also tuning rules to reduce false positives.
During November 2025, the UK introduced the Cyber Security and Resilience Bill to strengthen national cybersecurity requirements and resilience obligations.
In November 2025, South Korean retailer Coupang disclosed a breach affecting 33.7 million accounts, with reporting indicating a possible insider-related cause.
A supply chain breach involving SitusAMC was reported in November 2025, with downstream impact affecting major financial-sector organizations.
In November 2025, the Shai-Hulud supply chain worm re-emerged, compromising nearly 1,000 software packages and leaking tens of thousands of credentials on GitHub.
A Windows Kernel zero-day tracked as CVE-2025-62215 was reported in November 2025 as being actively exploited in the wild, elevating concern over ongoing attacks against Windows systems.
In November 2025, three container escape vulnerabilities in runc—CVE-2025-3113, CVE-2025-52565, and CVE-2025-52881—were reported as affecting Docker and Kubernetes environments and potentially allowing root access on host systems. The disclosures prompted urgent patching efforts.
In November 2025, CISA confirmed that the long-standing Linux kernel vulnerability CVE-2024-1086 was being actively exploited in ransomware operations, enabling full administrative control on affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.