Latest Internet & Cybersecurity News

๐Ÿ“…December 22, 2025 at 1:00 AM
Critical Cisco zero-days exploited, PornHub and SoundCloud breaches, holiday phishing surges, ransomware records $2.1B, nation-state hacks dominate 2025 cybersecurity threats.
1

Cisco Email Security Zero-Day Actively Exploited by Chinese Threat Group

A suspected Chinese-nexus group has compromised Cisco email security devices since late November 2025, planting backdoors and log-purging tools.Source 1 CVE-2025-20393 allows unauthenticated remote code execution with CVSS 10.0, added to CISA KEV catalog; over 100 devices affected worldwide.Source 2Source 4 Cisco urges immediate patching by December 24.Source 4

2

PornHub Suffers Major Data Breach Exposing 1.2M User Credentials

Attackers stole usernames, emails, and encrypted passwords from over 1.2 million PornHub accounts, fueling credential stuffing risks.Source 2 The breach highlights vulnerabilities in adult platforms and third-party risk management.Source 2 Investigations ongoing amid extortion attempts linked to Mixpanel data exposure.Source 3

3

SoundCloud Breached and Hit by Repeated DoS Attacks

SoundCloud confirmed a data breach and ongoing denial-of-service attacks, causing VPN user connection failures.Source 1 Users reported errors in days leading to disclosure on December 22, 2025.Source 1 The incident underscores risks to streaming services during high traffic periods.Source 1

4

PCPcat Malware Compromises 59,000 Servers via Next.js and React RCE Flaws

PCPcat exploits CVE-2025-29927 and CVE-2025-66478 for unauthenticated RCE, hijacking Node.js processes in under 48 hours.Source 2 Attackers exfiltrate credentials and deploy tunneling tools like GOST and FRP.Source 2 Over 59,000 servers impacted globally.Source 2

5

Holiday Phishing and AI-Driven Scams Surge 30% During Christmas 2025

Cybercriminals exploit shoppers with fake deals, 33,500+ Christmas-themed phishing emails, and 10,000 daily phony ads.Source 4Source 8 AI lowers barriers for realistic scams impersonating Walmart, FedEx via urgent delivery notifications.Source 8 Delivery scams doubled since 2024, stealing credentials en masse.Source 8

6

Ransomware Payments Hit Record $2.1 Billion in 2025

Global ransomware payments soared to $2.1 billion this year, driven by aggressive attacks on critical sectors.Source 4 Nation-state actors amplify disruptions in infrastructure.Source 4 Financial incentives fuel escalating threats into 2026.Source 4

7

North Korean Hackers Lead Crypto Theft with $2.02 Billion Stolen in 2025

North Korea-linked groups stole $2.02 billion in cryptocurrency, topping global theft via large-service breaches.Source 1Source 11 Chainalysis reports shift to high-value targets for quick monetization.Source 1 Microsoft 365 users also targeted in device code phishing.Source 1

8

Russian APT28 Targets Ukrainian UKR.NET with Credential Harvesting

BlueDelta (Fancy Bear) sends fake PDFs linking to phishing portals, stealing logins, 2FA, and IPs via ngrok tunnels.Source 2 Campaign hits popular Ukrainian webmail and news service.Source 2 Infrastructure masks C2 for persistent access.Source 2

9

CISA Adds Multiple Flaws to KEV: Cisco, SonicWall, Fortinet, Apple

U.S. CISA cataloged exploited vulnerabilities in Cisco IOS XE, SonicWall SMA, Fortinet products, WatchGuard, ASUS, and Apple.Source 3Source 10 SonicWall flaw actively exploited; hackers hit Fortinet days post-patch.Source 3 Agencies mandate urgent mitigations.Source 3

10

Scripted Sparrow BEC Ring Tracked in Global Phishing Campaigns

Fortra tracked Scripted Sparrow from June 2024-December 2025, posing as firms to phish finance teams for wire transfers.Source 1 Highly targeted emails evade detection in persistent operation.Source 1 ESET uncovers LongNosedGoblin APT using Group Policy for Southeast Asia surveillance.Source 1

11

GhostPairing Abuses WhatsApp Linking for Account Hijacking

GhostPairing campaign exploits WhatsApp device pairing from phone numbers to gain full access.Source 3 Attackers hijack accounts via malicious links.Source 3 Added to ongoing threats in weekly security roundups.Source 3

12

DDoS Attacks Surge Dramatically in 2025 Targeting Critical Infrastructure

Distributed Denial of Service attacks escalated, risking online services and key sectors.Source 4 Android botnet Kimwolf infects 1.8M+ devices for DDoS strikes.Source 10 SoundCloud among recent high-profile victims.Source 1