Latest Internet & Cybersecurity News

📅December 25, 2025 at 1:00 PM
Recent cybersecurity threats include nation-state attacks, critical vulnerabilities in Fortinet products, DDoS disruptions to French postal service, data breaches, and major acquisitions amid rising global risks.
1

Pro-Russian Hackers Claim DDoS Attack on French Postal Service La Poste

A pro-Russian hacking group took responsibility for a major DDoS attack that knocked offline central systems at France's national postal service La Poste on December 24, 2025, disrupting package deliveries and online payments.Source 3Source 4 The attack blocked services and delayed operations, highlighting ongoing geopolitical cyber tensions.Source 3 Authorities are investigating the impact on critical infrastructure.Source 4

2

CISA Adds Critical Fortinet Vulnerabilities to KEV Catalog

CISA added CVE-2025-59718 (CVSS 9.1) and CVE-2025-59719 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in Fortinet products like FortiOS and FortiWeb when FortiCloud SSO is enabled.Source 1 Attackers exploited these flaws days after patches, targeting admin accounts and exfiltrating config files.Source 1 U.S. federal agencies must remediate by December 23, 2025, under BOD 22-01.Source 1

3

Fortinet Warns of Active Exploitation of Old SSL VPN 2FA Bypass Flaw

Fortinet reported recent abuse of CVE-2020-12812 (CVSS 5.2), an improper authentication vulnerability in FortiOS SSL VPN allowing login without 2FA under specific LDAP configurations.Source 7 Exploitation requires local users with 2FA linked to LDAP groups used in policies.Source 7 Organizations should review configurations and apply mitigations immediately.Source 7

4

China-Linked Ink Dragon Conducts Sophisticated Campaigns Against Governments

China-linked group Ink Dragon used FINALDRAFT backdoor and legitimate tools in disciplined campaigns targeting governments and telecoms in Europe, Asia, and Africa.Source 1 The group impacted dozens of victims, including a Russian IT provider, blending engineering with evasion tactics.Source 1 Check Point highlighted ongoing activity since early 2025.Source 1

5

ShinyHunters Allegedly Breaches SoundCloud, Followed by DoS Attacks

Cyber extortion group ShinyHunters reportedly breached SoundCloud, threatening data leaks unless paid, with subsequent DoS attacks briefly disrupting access.Source 1 The platform contained the breach and attributed outages to security changes.Source 1 SoundCloud remains operational amid the incident.Source 1

6

Salt Typhoon China-Linked Attacks Extend to National Guard Networks

Hacking group Salt Typhoon targeted multiple U.S. National Guard networks in 2024, with effects persisting into 2025, as confirmed by officials.Source 2 CISA warned of ongoing China-linked threats alongside BRICKSTORM malware using stolen credentials.Source 2 This underscores persistent nation-state cyber risks.Source 2

7

Red Hat GitLab Breach Exposes 21,000 Customers' Data

Hackers compromised Red Hat’s GitLab instances, stealing personal information of 21,000 customers.Source 3 The incident is part of broader supply chain risks in tech services.Source 3 Red Hat is addressing the fallout from the data theft.Source 3

8

ServiceNow Acquires Cybersecurity Firm Armis for $7.75 Billion

ServiceNow announced a $7.75 billion acquisition of cyber asset management firm Armis, following rumors and Armis's recent $435 million funding.Source 3Source 9 The deal aims to enhance enterprise security capabilities.Source 9 It marks a major consolidation in the cybersecurity market.Source 3

9

Shinhan Card Data Breach Impacts 192,000 South Korean Merchants

South Korea's Shinhan Card suffered a breach exposing data of 192,000 merchants on December 24, 2025.Source 10 The incident adds to rising data breach trends in financial services.Source 10 Investigations are underway to assess full scope and response.Source 10

10

Critical Fireware OS Vulnerability Allows Remote Code Execution

A critical flaw, CVE-2025-37164, in WatchGuard's Fireware OS iked process enables unauthenticated remote code execution.Source 3 Organizations using affected systems should patch urgently.Source 3 This vulnerability poses high risk to network security appliances.Source 3

11

Treasury Department Compromised by China-Sponsored Actor via BeyondTrust

A China state-sponsored threat actor exploited a BeyondTrust remote access key, accessing Treasury workstations and unclassified documents early 2025.Source 2 CISA confirmed no wider agency impact after collaboration.Source 2 The breach highlighted third-party software risks.Source 2

12

Escalated Cyber Attacks Target U.S. Federal Court Filing Platform

The U.S. federal court system's electronic case filing platform faced heightened attacks in 2025.Source 2 Officials reported increased cyber risks to judicial infrastructure.Source 2 This reflects broader threats to government systems.Source 2

Latest Internet & Cybersecurity News | DeckBook AI