Latest Internet & Cybersecurity News

📅December 13, 2025 at 1:00 PM
Critical exploits of React2Shell vulnerability surge alongside patches for Ivanti, Fortinet; AI cybersecurity risks escalate with OWASP list, state sanctions, and hacktivist threats to infrastructure.
1

Active Exploits of React2Shell Vulnerability Surge, Enabling Botnets and Crypto Mining

Threat actors are exploiting CVE-2025-55182 in React Server Components to deploy backdoors, botnets, and crypto miners on corporate networks worldwide.Source 1Source 3 CISA shortened the mitigation deadline for federal agencies to December 12 due to active criminal and state-sponsored attacks targeting North/South America, Asia, and the Middle East.Source 3 React has issued new patches following additional flaws flagged by researchers, urging critical infrastructure to update immediately.Source 10

2

UK NHS Barts Health Discloses Major Data Breach by Cl0p Ransomware

Barts Health, the UK's largest NHS trust, confirmed patient and staff data theft by Cl0p ransomware gang after an August cyber-attack.Source 1 The stolen data is on the dark web, but the trust claims limited risk and seeks a High Court order to block publication.Source 1 This incident highlights ongoing ransomware threats to healthcare.Source 1

3

Ivanti, Fortinet, and SAP Release Patches for Critical Vulnerabilities

Ivanti patched CVE-2025-10573 in Endpoint Manager allowing remote code execution.Source 1Source 3 Fortinet addressed CVE-2025-59718 and CVE-2025-59719 in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, enabling FortiCloud SSO bypass via crafted SAML responses (CVSS 9.8).Source 1Source 3 SAP also announced fixes for high-severity flaws.Source 1Source 3

4

UK Sanctions Chinese Firms i-Soon and Integrity Tech for Cyber Attacks

The UK NCSC sanctioned Sichuan Anxun (i-Soon) and Integrity Technology Group on December 9 for reckless cyberattacks on over 80 IT systems.Source 4 i-Soon targeted federal and private sectors, while Integrity supported covert networks against UK systems.Source 4 This follows CISA's report on PRC-linked BRICKSTORM malware for long-term persistence in IT and government sectors.Source 4

5

OWASP Releases Top 10 Risks for Agentic AI Applications

OWASP published its inaugural Top 10 for Agentic AI 2026, addressing threats like goal hijacking and tool misuse in autonomous AI agents.Source 5 The list aids organizations securing AI that plans and executes workflows independently.Source 5 It coincides with rising AI-enabled threats in cybersecurity forecasts.Source 5Source 7

6

CISA and MITRE List 2025's Top 25 Most Dangerous Software Weaknesses

CISA and MITRE released the 2025 Top 25 Most Dangerous Software Weaknesses to guide developers and risk managers.Source 5 The list prioritizes flaws for better software security decisions amid ongoing exploits.Source 5 It aligns with urgent patching needs seen in recent vulnerabilities.Source 3

7

Pro-Russia Hacktivists Target Global Critical Infrastructure with OT Attacks

Groups like Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16 exploit insecure VNC connections in OT networks for energy, water, and agriculture sectors.Source 5Source 6 A joint CISA advisory warns of their intent to cause harm using simple tactics.Source 5Source 6 Organizations face risks to operational technology from these opportunistic attacks.Source 6

8

Europol Cracks Down on 'Violence-as-a-Service' Linked to Cybercrime

Europol arrested nearly 200 suspects in six months for 'Violence-as-a-Service' operations recruiting online for physical attacks.Source 1 Many perpetrators belong to 'The Com' network, tied to high-profile ransomware.Source 1 This exposes overlaps between cybercrime and real-world violence.Source 1

9

CISA Updates Voluntary Cybersecurity Performance Goals for Critical Infrastructure

On December 11, CISA updated its CPGs with measurable actions aligned to NIST standards for sectors like healthcare.Source 9Source 14 The guidance emphasizes governance, accountability, and risk management against common threats.Source 9 It supplements 2022 goals to enhance resilience.Source 14

10

NCSC and OpenAI Warn of Cybersecurity Risks from Large Language Models

The UK NCSC and OpenAI highlighted contrasting cyber risks of LLMs, including a double-edged sword of benefits and threats.Source 1 Warnings come amid AI's frontline role in attacks like ShadowV2 botnet and PRC espionage using Claude.Source 7Source 11 Experts stress preparation for AI-speed threats.Source 7

11

Sophisticated Phishing Targets Identity Platforms and UK Political Figures

Recent campaigns exploit web framework flaws and target major identity platforms with phishing.Source 2 Messaging-app attacks on UK politicians are rising, demanding strong protections.Source 2 These reinforce needs for rapid patching and secure communications.Source 2

12

Booz Allen CEO Warns World Unready for AI-Driven Cyber Risks

Booz Allen's Horacio Rozanski stated the world lacks readiness for AI cyber threats like ransomware and network corruption by bad actors.Source 11 He highlighted U.S.-China AI race, with China advancing space-based computing.Source 11 Anthropic detected PRC-sponsored disruption using Claude against 30+ entities.Source 11