Latest Internet & Cybersecurity News

đź“…December 9, 2025 at 1:00 AM
Critical React2Shell vulnerability actively exploited by China-linked groups; major ransomware attacks disrupt emergency services; data breaches impact millions globally; AI and cybersecurity standards evolve.
1

Critical React2Shell Flaw Actively Exploited by China-Linked Hackers

The severe React2Shell vulnerability (CVE-2025-55182) is being widely exploited by multiple China-linked threat actors targeting cloud and web applications. AWS and other major platforms report attempted exploits, prompting emergency patching and inclusion in CISA's Known Exploited Vulnerabilities catalogSource 1Source 3Source 5Source 8Source 12.

2

CodeRED Ransomware Attack Disrupts Emergency Alert Services

The OnSolve CodeRED emergency notification system suffered a ransomware attack by INC Ransom group, causing outages and data breaches affecting several U.S. local governments. Authorities urged residents to reset passwords after exposure of clear-text credentials, highlighting risks in life-safety alerting systemsSource 2.

3

Coupang Data Breach Exposes 33.7 Million Customer Accounts

E-commerce giant Coupang confirmed a data breach affecting over 33 million users in East Asia. Unauthorized access occurred for five months exploiting weaknesses in multiple software components including WordPress plugins and React2Shell vulnerabilitiesSource 2.

4

Cloudflare Mitigates Record-Breaking 29.7 Tbps DDoS Attack

Cloudflare successfully blocked what is recorded as the largest distributed denial-of-service attack reaching 29.7 terabits per second, originating from the AISURU botnet-for-hire. This attack demonstrates an increase in hyper-volumetric DDoS threats to global internet infrastructureSource 4.

5

Pharma Firm Inotiv Confirms Major Cyberattack and Data Theft

Inotiv disclosed a cyberattack in early August 2025 causing system outages and data leaks. The company is complying with legal notifications while restoring operational networks amidst evolving cybersecurity threats in healthcare researchSource 6.

6

Healthcare Cyber Insurance Sees Rising Risk Amid Ransomware and Litigation

The healthcare industry faces an inflection point for cyber insurance due to escalating ransomware attacks and legal challenges, prompting industry-wide reevaluation of cybersecurity and risk management approachesSource 1.

7

AXA XL Joins ISASecure to Promote Industrial Cybersecurity Standards

Insurance giant AXA XL became part of ISASecure certification program to strengthen cybersecurity risk prevention in industrial automation and control systems, adhering to ISA/IEC 62443 standardsSource 7.

8

FBI Warns of Fake Social Media Photos Altered to Create False Evidence

The FBI issued an alert on the rising criminal use of manipulated social media images to fabricate fake evidence, underscoring emerging threats in digital image authenticity and social engineering scamsSource 5.

9

New GhostFrame Phishing Kit Powers Large-Scale Deception Campaigns

Security analysts detected a sophisticated phishing kit named GhostFrame spreading globally to harvest credentials. The campaign’s scale indicates high threat actor investment in stealth phishing infrastructureSource 5.

10

NVIDIA and WatchGuard Release Critical Security Patches for Server and Firewall Vulnerabilities

NVIDIA issued urgent patches for Triton Interface Server to prevent remote denial-of-service attacks. WatchGuard disclosed critical vulnerabilities allowing code injection into Firebox firewall appliances, necessitating immediate updates by organizationsSource 1Source 5.