Latest Internet & Cybersecurity News

📅December 27, 2025 at 1:00 AM
December 2025 sees surge in critical CVEs, ransomware attacks, state-sponsored hacks, and major data breaches impacting global infrastructure and enterprises.
1

December 2025 Critical CVE Round-Up: Zero-Days and RCEs

December 2025 featured a surge of critical vulnerabilities including React2Shell (CVE-2025-55182), a CVSS 10.0 zero-day RCE in React Server Components allowing unauthenticated code execution, ideal for phishing.Source 1 FortiGate authentication bypass flaws (CVE-2025-59718, CVE-2025-59719) saw malicious SSO attempts.Source 1 Security teams urged to prioritize patching enterprise frameworks and firewalls.Source 1

2

Ransomware Hits Romania’s Water Management Authority

A ransomware attack compromised around 1,000 systems across Romania’s 11 river basin organizations starting December 20, using Windows BitLocker to lock files.Source 2Source 6 Attackers demanded contact within 7 days, but operational capabilities remained unaffected.Source 2 This highlights ongoing ransomware threats to critical infrastructure.Source 2

3

Interpol’s Operation Sentinel Arrests 500+ in Cybercrime Bust

Operation Sentinel led to over 500 arrests across 19 countries, recovering $3M linked to BEC, extortion, and ransomware, with 6,000 malicious links taken down.Source 2 Six ransomware variants were decrypted during the month-long effort.Source 2 Nigerian police also arrested three tied to Raccoon0365 phishing platform.Source 2

4

Suspected Chinese Hackers Breach UK Foreign Office

Storm-1849, linked to ArcaneDoor campaign, reportedly breached UK Foreign Office in October using Cisco zero-days targeting government networks.Source 2 Cisco warned of ongoing activity in September.Source 2 This underscores state-sponsored threats to diplomatic entities.Source 2

5

Iranian APT Prince of Persia Resurfaces After 5 Years

Infy (Prince of Persia) launched a covert campaign targeting Middle East, Europe, India, Canada with updated Foudre downloader and Tonnerre implant.Source 3 Attack chains evolved to use executables in documents and DGA-based C2.Source 3 Focuses on profiling and data exfiltration from high-value victims.Source 3

6

Qilin, DragonForce, LockBit Form Ransomware Alliance

In September 2025, DragonForce announced alliance with Qilin and LockBit amid police crackdowns and ecosystem fragmentation.Source 3 Ransomware claims rose 61% YoY, with Qilin leading at 13% of claims.Source 3 LockBit inactive since June despite version 5.0 announcement.Source 3

7

Operation PCPcat Compromises 59,000+ Next.js Servers

Sophisticated campaign exploited CVE-2025-29927 and CVE-2025-66478 for RCE, stealing credentials from over 59,000 Next.js servers worldwide.Source 3 Targets developers for mass credential theft.Source 3 Highlights vulnerabilities in modern web frameworks.Source 3

8

Russian GRU Sandworm Targets Global Critical Infrastructure

Multi-year campaign by Russia’s GRU/Sandworm shifted to misconfigured edge devices for credential theft and lateral movement, focusing on Western energy sector.Source 4 Marks evolution in critical infrastructure attacks.Source 4 High-confidence attribution to state actors.Source 4

9

TikTok Fined $600M for GDPR Violations on China Data Transfers

Irish watchdog imposed €530M ($600M) fine on TikTok for transferring EU users' PII to China servers, contradicting prior assurances.Source 5 Exposed gaps in data protection under Chinese law vs. GDPR.Source 5 Part of 2025's top data breach fines.Source 5

10

Capita Slapped with £14M Fine Over 2023 Ransomware Breach

UK ICO fined Capita £14M for security failures enabling ransomware affecting 7M pension customers across 600 funds.Source 5 Issues included poor privilege controls, slow alerts, and inadequate testing.Source 5 Long-term outages impacted essential services.Source 5

11

Rhysida Ransomware Hits Japanese Firm Yokosuka Gakuin

CYFIRMA reported Rhysida compromise of Yokosuka Gakuin, a Japanese educational institution, with data posted on underground forums.Source 4 Part of rising ransomware trends targeting various sectors.Source 4 Emphasizes need for robust defenses in non-critical entities.Source 4

12

Qilin Ransomware Breaches Singapore’s Dacon Networks

Singapore IT firm Dacon Networks Pte Ltd compromised by Qilin, exposing 1.2M records including 351K phone numbers, offered for sale at $300.Source 4 Data includes confidential organization info.Source 4 Authenticity unverified but highlights regional risks.Source 4