Latest Internet & Cybersecurity News

đź“…December 10, 2025 at 1:00 AM
2025 ends with rising AI-driven cyber threats, massive data breaches, critical vulnerabilities in major platforms, state-sponsored cybercrime, and urgent global cybersecurity measures.
1

2025 Cyber Threat Landscape Highlights $64.8 Billion US Scam Losses

US consumers lost an estimated $64.8 billion to scams in 2025, with 70% experiencing at least one scam. AI-driven threats and malware dominated the cyber threat landscape, prompting calls for stronger consumer protections and stricter verification on online review platforms to combat widespread fake reviews and scamsSource 1.

2

Pharmaceutical Researcher Inotiv Suffers Major Ransomware Breach

Inotiv confirmed a Qilin ransomware attack exposing personal, financial, and health data of over 9,000 individuals. This breach exposes rising supply chain risks within pharmaceutical and healthcare sectorsSource 2.

3

Critical Vulnerabilities Discovered in WatchGuard Firebox and Other Systems

Critical vulnerabilities were found in WatchGuard Firebox appliances allowing code injection and integrity bypass. Additionally, new exploits targeting WhatsApp, Signal, Cal.com authentication, and unique SVG clickjacking attacks emerged, threatening enterprise and consumer security globallySource 3.

4

Microsoft December 2025 Patch Tuesday Fixes 57 Vulnerabilities Including Zero-Day

Microsoft addressed 57 vulnerabilities, including an actively exploited Windows zero-day (CVE-2025-62221) affecting Cloud Files Mini Filter Driver. 2025 ended as the second-largest year by volume of patched defects, with growing concerns over AI-related bugs and increasing attack surfacesSource 4.

5

Massive Data Breaches in 2025 Expose Over 45 Billion Records Globally

Analysis of 2025 reveals top data breaches compromised 45 billion records, including the largest credential breach ever—16 billion passwords collected globally mainly due to cloud misconfigurations and compromised credentials. High-impact breaches targeted fintech firms like Prosper Marketplace, exposing millions of sensitive customer records and SSNsSource 5.

6

Pro-Russia Hacktivist Groups Intensify Cyberattacks on NATO and US Critical Infrastructure

Pro-Russia groups including NoName057(16) and Sector16 continue DDoS and SCADA network intrusions in North Atlantic Treaty Organization (NATO) states and US critical infrastructure using unsophisticated but effective tactics, signaling growing geopolitical cyber tensionSource 6.

7

2025 Sees AI-Powered Malware Surge and Insider Threats Impacting Major Brands

Cybersecurity experts report AI has become a real malware threat, automating attacks rapidly. Insider threats surged with employees colluding with ransomware gangs, zero-day brokers selling exploits, and major crypto heists, shaping a complex 2025 cybercrime environmentSource 7.

8

CISA Warns of Critical D-Link Router Buffer Overflow Flaw Exploited in Active Attacks

CISA added CVE-2022-37055 to its Known Exploited Vulnerabilities catalog, urging federal agencies and private users to patch or discontinue vulnerable D-Link routers due to ongoing exploitation and lack of vendor patches, highlighting persistent IoT security challengesSource 8.

9

US Justice Department Takes Down Russian State-Sponsored Cybercrime Groups

US authorities announced enforcement actions against two pro-Russian state-sponsored cyber criminal groups responsible for cyber intrusion campaigns. Related arrests include individuals charged with illegally exporting advanced AI technology, emphasizing increasing law enforcement focus on nation-state cyber threatsSource 9.

10

Global Firms to Boost Cybersecurity Budgets Amid Rising Software Supply Chain Attacks

Organizations worldwide plan to increase cybersecurity spending in 2026, targeting third-party risk and supply chain security. Software supply chain attack costs reached $60 billion in 2025 and are expected to exceed $138 billion by 2031, reflecting the escalating economic impact of cybercrimeSource 11.