logo

Intelligence Insights: December 2025

ID: e6bd982b-ed19-500d-bfd2-f39e6847b970

STIX ID: report--e6bd982b-ed19-500d-bfd2-f39e6847b970

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2025-12-18

Date Updated: 2026-04-29

Author: The Red Canary Team

...
...

Red Canary's November 2025 intelligence roundup identifies the most prevalent threats observed across customer environments, led by JustAskJacky (malicious Node.js lures executing reconnaissance and arbitrary in-memory commands), the Sha1-Hulud npm/GitHub Actions worm that stole credentials and propagated via CI runners, abuse of ScreenConnect RMM for direct adversary access, and MacSync Stealer targeting macOS credentials and wallets; it also notes the takedown and absence of recent Rhadamanthys activity following a multinational disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.