Latest Internet & Cybersecurity News

📅December 17, 2025 at 1:00 AM
December 2025 sees Chinese BRICKSTORM malware espionage, major breaches at 700Credit and TriZetto, critical patches from Microsoft and Fortinet, ICS vulnerabilities, and cloud outages.
1

CISA, NSA Expose Chinese BRICKSTORM Malware in Multi-Year Espionage Campaign

Joint advisory from CISA, NSA, and Canadian Cyber Centre reveals BRICKSTORM backdoor used by Chinese state-sponsored actors targeting VMware vSphere and Windows for persistent access in government and IT sectors.Source 1Source 2 Malware steals VM snapshots for credentials and uses DNS-over-HTTPS for covert communications, with access maintained from April 2024 to September 2025.Source 2 Organizations urged to scan networks and block unauthorized DNS-over-HTTPS traffic.Source 2

2

700Credit API Breach Exposes 5.6 Million People's Data

Michigan-based 700Credit suffered a breach via flawed API connection, allowing access to client data from May to October 2025, affecting over 5.6 million individuals.Source 2 China-linked groups like Earth Lamia exploited it post-disclosure, deploying miners and backdoors; CISA added to Known Exploited Vulnerabilities.Source 2 North Korean actors also targeted the flaw, with 39% of cloud environments vulnerable.Source 2

3

TriZetto Healthcare Provider Confirms Year-Long Data Breach

TriZetto Provider Solutions detected unauthorized access to its web portal on October 2, 2025, but breach started in November 2024, exposing patient names, SSNs, and insurance data.Source 2 The portal serves physicians, hospitals, and health systems with revenue management tools.Source 2 Forensic analysis confirmed access to historical eligibility reports.Source 2

4

Microsoft December 2025 Patches Address Actively Exploited CVE-2025-62221

Microsoft's security update fixes multiple vulnerabilities, including actively exploited CVE-2025-62221; Canada's Cyber Centre stresses rapid enterprise patching.Source 1 CISA added CVE-2022-37055 (D-Link routers) and CVE-2025-66644 (Array Networks) to exploited catalog.Source 1 Fortinet patched authentication bypass flaws CVE-2025-59718/59719 in FortiCloud, FortiOS, FortiWeb.Source 1

5

CISA Issues 12 New ICS Advisories Targeting Industrial and Medical Devices

Mid-December advisories cover vulnerabilities in Mitsubishi Electric, Advantech, Johnson Controls, and medical devices, expanding healthcare OT attack surface.Source 1 Australia's ACSC warns of pro-Russia hacktivists disrupting exposed ICS infrastructure with low-sophistication attacks.Source 1 Persistent risks to critical infrastructure highlighted.Source 3

6

Massive AWS Cloud Outage Impacts Millions for 15 Hours

AWS suffered a widespread 15-hour outage in October 2025, affecting millions due to cybersecurity and software issues.Source 4 Listed among top 10 cloud outages including Microsoft Azure and Google Cloud disruptions.Source 4 Highlights ongoing reliability challenges in major providers.Source 4

7

Ingram Micro Ransomware Attack via Leaked VPN Credentials

SafePay ransomware group exploited leaked GlobalProtect VPN credentials at Ingram Micro, taking six days to remediate.Source 4 Attack slipped past perimeter defenses, prompting new safeguards and monitoring.Source 4 Part of broader 2025 cloud and supply chain incidents.Source 4

8

Microsoft Azure Global Outage Hits Multiple Services

October 29 outage affected every Azure region due to Azure Front Door configuration change, impacting Entra, Purview, Defender, and more.Source 4 Caused latencies, timeouts in Azure Portal, SQL Database, Virtual Desktop, and Copilot for Security.Source 4 AFD CDN/security service was central to the issues.Source 4

9

CISA Releases Version 2.0 Cross-Sector Cybersecurity Performance Goals

Updated goals integrate NIST Framework, adding governance for accountability, risk management, and operational cybersecurity embedding.Source 1 Aims to standardize defenses across sectors amid rising threats.Source 1 Released end of December 2025.Source 1

10

React Framework Vulnerabilities Enable Remote Code Execution

Critical flaws in React allow server-side code execution, source code exposure, DoS; 165,000 IPs and 644,000 domains vulnerable as of December 10.Source 3 Tied to Cl0p ransomware exploiting MOVEit-like issues, with $50M ransom demands.Source 3 Exploitations ongoing across organizations.Source 3

11

SIFMA Updates Financial Services Cyber Incident Reconnection Framework

SIFMA and FSSCC release updated framework to help financial firms reconnect post-cyber incidents.Source 7 Enhances recovery coordination for sector resilience.Source 7 Responds to evolving threats in 2025.Source 7

12

AI-Driven Threats Surge with GenAI Phishing and Deepfakes in 2025

Generative AI fueled phishing, deepfakes, social engineering, ransomware; businesses expose risks adopting GenAI without controls.Source 5 Recommendations include stronger identity verification and updated incident response for AI threats.Source 5 Reshaped external and internal cyber risks.Source 5