A roundup of recent developments in information security and detection engineering highlights both evolving cyber threats and the community's response through updated detection rules. Notable news includes AI-powered cyber attacks targeting Russian arms firms, concerns over open-source software supply chain risks raised by U.S. Senate leadership, and the increasing use of automated data analysis in government enforcement. These stories underscore the growing sophistication of threat actors and the need for vigilance in both public and private sector cybersecurity.
In parallel, detection engineering teams released 19 new and 87 updated rules across major platforms such as Sigma, Splunk, YARA, KQL, Elastic, and Sublime Security. Key improvements include expanded phishing detections for services like Monday.com and SendGrid, enhanced rules for defense evasion using Windows processes, and refined cloud threat detection for AWS and Azure environments. These updates aim to improve threat coverage and operational efficiency in response to the latest attack techniques and adversary behaviors.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Russian arms firms were targeted in cyber attacks described as AI-powered and attributed to Paper Werewolf (GOFFEE). The reporting presents this as a current campaign development disclosed in the December 19-21, 2025 roundup.
Following its 2022 ransomware incident, Osaka General Medical Center implemented major IT security improvements. The response was highlighted as a significant post-incident remediation step.
A fraudulent e-apostille website in Bangladesh exposed sensitive data belonging to more than 1,100 citizens. The report identifies the site as the source of the data exposure.
A U.S. shareholder lawsuit was filed against Coupang in connection with a major data leak in South Korea. The filing marked an escalation from the underlying breach to investor litigation.
The U.S. Department of Justice charged 54 individuals allegedly tied to the Tren de Aragua gang for ATM jackpotting attacks using Ploutus malware. The roundup identifies this as a newly reported law enforcement action.
Former Michigan coach Matt Weiss was implicated in hacking incidents involving exploitation of a flaw in the University of Michigan's account recovery system. The roundup reports the implication but does not provide a specific incident date.
Pro-Russian hackers, including the DDoSia group, launched more than 1,200 DDoS attacks against Belgian critical infrastructure. Belgian defenses reportedly repelled all of the attacks.
Between December 15 and December 22, 2025, nine major GitHub repositories were updated with 19 new and 87 modified detection rules across Sigma, Splunk, YARA, KQL, Elastic, and Sublime Security. The changes expanded coverage for phishing, defense evasion, cloud threats, Linux and Windows activity, and malware including the XZ backdoor and GrimResource.
Osaka General Medical Center in Japan was hit by a ransomware attack in 2022. The incident later prompted the hospital to overhaul its IT security measures.
The threat group Paper Werewolf, also known as GOFFEE, was described as having been active since 2022. Later reporting linked it to AI-assisted cyber attacks against Russian arms firms.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.