Latest Internet & Cybersecurity News

📅December 20, 2025 at 1:00 PM
Critical vulnerabilities exploited in Fortinet and Cisco products, nation-state attacks on Ukraine and crypto, ransomware trends declining, AI cybersecurity surge, and major 2025 breaches dominate headlines.
1

Fortinet FortiGate Vulnerabilities CVE-2025-59718 and CVE-2025-59719 Exploited in the Wild

Attackers are exploiting critical flaws in Fortinet FortiGate devices allowing unauthorized SSO logins and config exfiltration, linked to Chinese infrastructure. Arctic Wolf observed malicious activity from December 12, targeting admin accounts.Source 2Source 3 CISA added CVE-2025-59718 to KEV catalog with remediation due by December 23.Source 3

2

Cisco Secure Email Gateway Actively Attacked via CVE-2025-20393

Cisco reports active exploitation of CVE-2025-20393 in Secure Email Gateway and Web Manager appliances with Spam Quarantine exposed online, discovered December 10.Source 4 The improper input validation flaw is in CISA's KEV catalog without a patch yet.Source 4 Targets both physical and virtual setups.Source 4

3

BlueDelta Russian APT Targets UKR.NET with Credential Harvesting

Russian state-sponsored BlueDelta (APT28/Fancy Bear) runs persistent phishing campaign against Ukrainian webmail service UKR.NET.Source 2 Emphasizes need for phishing-resistant MFA.Source 2 Insikt Group details the sustained operation.Source 2

4

North Korean Lazarus Group Uses WinRAR n-Day CVE-2025-8088 for Crypto Theft

Lazarus exploits WinRAR vulnerability via email to deploy Blank Grabber Trojan stealing browser data, Discord/Telegram sessions, and crypto wallet keys like MetaMask.Source 2 Disguised as toolkits in RAR files.Source 2 Targets credentials and wallets.Source 2

5

Venezuela's PDVSA Oil Giant Hit by Cyberattack Amid US Tensions

PDVSA suffers cyberattack as tensions with US rise, part of escalating threat actor activity.Source 3 Cybercriminals use alarming spying and theft tactics in related campaigns like GhostPoster.Source 3 Highlights infrastructure vulnerabilities.Source 3

6

DXS International NHS Software Supplier Discloses Cyber Incident

UK firm DXS International, providing NHS clinical tools, reports breach on internal servers discovered December 14.Source 4 Engaged experts; notified ICO and regulators.Source 4 Affects GP practices across England.Source 4

7

RBHA Ransomware Breach Exposes Sensitive Health and Financial Data

Ransomware attack on September 29 encrypts RBHA network, stealing SSNs, passports, accounts, and health info.Source 4 Notified HHS OCR on December 4.Source 4 Data theft confirmed in breach notice.Source 4

8

Apple Patches Zero-Day Flaws Used in Sophisticated Attacks

Apple fixed zero-day vulnerabilities exploited for sophisticated attacks, topping December 19 news.Source 8 Part of ongoing mobile security threats.Source 8 Users urged to update immediately.Source 8

9

Cybersecurity Pros Rapidly Adopt AI Tools Amid New Risks

Cyber teams now 90%+ using AI for threats, per CSA-Google survey; requires data security overhaul for prompt injection, model inversion.Source 7 CSA proposes new AI Controls Matrix additions.Source 7 PwC predicts responsible AI focus in 2026.Source 7

10

Clop Ransomware Extorts Companies via Oracle E-Business Breaches

Clop exploits Oracle servers, stealing data from giants like Cloudflare, Google, LinkedIn; demands ransoms with exec personal info.Source 5 Follows mass-hacks like MOVEit; new victims ongoing.Source 5 Largest 2025 breaches include US gov, Treasury.Source 5

11

FinCEN Reports Slight Downward Trend in Ransomware Incidents

US FinCEN data shows ransomware peaking but declining slightly 2022-2024, despite 2025 class actions over breaches.Source 6Source 7 Key findings from BSA report highlight trends.Source 7 Continued high-impact attacks persist.Source 6

12

Silver Fox False-Flag SEO Poisoning Targets Chinese Users

Silver Fox uses SEO poisoning for backdoors in 20+ apps, impersonating Russian actors with Cyrillic; hits China, AsiaPac, Europe, NA since July.Source 2 ReliaQuest assesses as false-flag.Source 2 Broad campaign uncovered.Source 2