Latest Internet & Cybersecurity News

📅December 29, 2025 at 1:00 PM
2025 saw escalating cyber threats including ransomware deaths, MongoDB exploits, AI vulnerabilities, DDoS surges, and policy shifts amid rising violence.
1

MongoDB CVE-2025-14847 Actively Exploited Worldwide

A critical MongoDB vulnerability, CVE-2025-14847 (CVSS 8.7), enables unauthenticated attackers to leak sensitive data like passwords and API keys from server memory via malformed packets.Source 4 Over 87,000 vulnerable instances exist globally, mainly in the US, China, and Europe, with 42% of cloud environments affected.Source 4 Urgent patching is recommended as exploitation is ongoing.Source 4

2

Cloudflare Blocks 8.3 Million DDoS Attacks in Q3 2025

Cloudflare's defenses stopped 8.3 million DDoS attacks in Q3 2025, averaging 3,780 per hour, signaling relentless threats into 2026.Source 5 The surge underscores the need for robust autonomous protections against escalating volumetric assaults.Source 5 Businesses are urged to prepare for intensified DDoS campaigns.Source 5

3

First Confirmed Ransomware-Related Death Linked to Synnovis Attack

The Synnovis ransomware incident, confirmed in 2025, marks the first direct cybercrime death, disrupting UK healthcare services.Source 2 Despite occurring in 2024, official linkage established this year highlights ransomware's lethal potential.Source 2 Previous unconfirmed cases include US Medicare patient deaths.Source 2

4

Cybercriminals Weaponize Preschoolers' Data in Kido International Breach

Ransomware group Radiant Group leaked personal data of 10 schoolchildren, including addresses and parents' contacts, from Kido International.Source 2 This attack on preschoolers represents a new low in targeting vulnerable populations.Source 2 It exemplifies ransomware gangs' disregard for ethical boundaries.Source 2

5

Rise in Violence and Amputations Tied to Cybercrime in Europe

CrowdStrike reported a dramatic increase in 'violence as a service' across Europe, including amputations to coerce crypto payments from victims.Source 2 Growing cryptocurrency values fuel cybercriminals' extreme tactics.Source 2 This trend signals coalescing of physical violence with digital extortion.Source 2

6

AI Prompt Injections Emerge as Top Security Threat

Prompt injection vulnerabilities in LLMs and AI agents like ChatGPT and Copilot allow attackers to hijack instructions, posing risks to enterprise tools.Source 3 These flaws stem from inability to distinguish commands from data, affecting browsers and chatbots.Source 3 Secure communication protocols are essential to mitigate hijacking.Source 3

7

LLMjacking: Credential Theft for LLM Abuse Surges

Cybercriminals steal LLM API credentials for unauthorized access, racking up costs over $100,000 daily and bypassing safeguards.Source 3 Microsoft sued a gang specializing in this 'LLMjacking' to build illicit services.Source 3 Victims include users of Amazon Bedrock and similar platforms.Source 3

8

Malware Hidden in Hugging Face AI Models Discovered

ReversingLabs uncovered malware in AI models on Hugging Face, enabling supply chain poisoning attacks on developers.Source 3 Vetting sources for AI libraries is critical amid shadow AI proliferation.Source 3 Enterprises face risks from unmonitored employee AI experimentation.Source 3

9

Trump Administration Slashes US CISA Budget and Staff

President Trump's second term enacted deep cuts to CISA, ousting officials and threatening the CVE program.Source 1 These changes rocked the US cyber establishment with global ripple effects.Source 1 Policy shifts under the new administration impacted industry widely.Source 1

10

UK Advances Cyber Security Bill with Ransomware Payment Ban

The UK laid its Cyber Security and Resilience Bill before Parliament in November 2025, including a ban on ransomware payments for critical sectors.Source 1 It covers hospitals, schools, councils, and CNI like datacentres.Source 1 Consultations preceded the bill's progress.Source 1

11

Microsoft Exchange Servers Targeted in Joint Agency Alert

Australian, Canadian, and US agencies issued an emergency alert on securing Microsoft Exchange servers, a frequent attack vector.Source 1 Criticism mounts over Microsoft's security obligations amid Patch Tuesday flaws.Source 1 The guide addresses historical high-impact incidents.Source 1

12

Crisis24 Ransomware Disrupts US Emergency Alerts

Ransomware hit Crisis24's CodeRED system, stealing citizen data and halting emergency notifications for weather and threats.Source 2 Affected municipalities used social media as workaround during downtime.Source 2 No crises occurred, but it exposed chaos potential.Source 2