Latest Internet & Cybersecurity News

đź“…December 26, 2025 at 1:00 PM
Major AWS outage disrupts services amid holiday cyber threats; critical CVEs in Net-SNMP, Cisco, n8n exploited; ransomware surges with AI; Russian campaigns target infrastructure.
1

Massive AWS Outage Disrupts Holiday Gaming and Services on Christmas 2025

A widespread AWS outage on December 25, 2025, affected Fortnite, Steam, and other platforms, marking the third major disruption this year.Source 2Source 4 Speculation points to potential cyber attacks or connectivity issues amid holiday vulnerabilities.Source 2 This highlights cloud infrastructure fragility powering much of the internet.Source 2Source 4

2

Critical Net-SNMP Vulnerability CVE-2025-68615 Allows Remote Attacks

A buffer overflow in Net-SNMP's snmptrapd daemon (CVE-2025-68615) enables remote attackers to crash services or execute code via malicious SNMP traps.Source 2 Emerged as a top concern on December 25, 2025, urging immediate patching.Source 2 Affects network management widely used in enterprises.Source 2

3

Cisco Secure Email Gateway Zero-Day CVE-2025-20393 Under Exploitation

Critical zero-day in Cisco Secure Email Gateway (CVE-2025-20393) allows unauthenticated remote code execution, compromising email appliances.Source 2 Disclosed on December 25, 2025, putting defenders on high alert.Source 2 Active exploitation reported, demanding urgent updates.Source 2

4

Russian GRU Sandworm Campaign Targets Global Critical Infrastructure

Multi-year Russian state-sponsored campaign by GRU's Sandworm targets energy sectors in Western countries via misconfigured edge devices.Source 1 Shifts from vulnerabilities to customer-owned devices for credential theft and lateral movement.Source 1 Emphasizes stealth with modular tools and cloud abuse for espionage.Source 1

5

Rhysida Ransomware Evolves as Double-Extortion Threat

Rhysida ransomware, active since 2023, uses encryption and data theft, with rapid sophistication increases.Source 1 CYFIRMA assesses need for layered defenses and credential management.Source 1 Recent claims include large datasets for sale on dark web.Source 1

6

Sorb Threat Actor Active in Data Leaks and Breaches

Sorb group engages in data-leak operations, selling stolen data on dark web marketplaces.Source 1 Linked to multiple security breaches with unauthorized access.Source 1 High activity and capability noted in recent intelligence.Source 1

7

n8n Remote Code Execution Vulnerability CVE-2025-68613

Critical RCE in n8n (CVE-2025-68613) affects versions up to 1.122.0, disclosed December 24, 2025.Source 9 Authenticated users can execute code via workflow expressions in insufficiently isolated contexts.Source 9 Patches available; monitoring solutions incoming.Source 9

8

TikTok Fined $600m for GDPR Violations on China Data Transfers

Irish regulator fined TikTok €530m ($600m) in May 2025 for transferring EU users' PII to China without proper safeguards.Source 5 TikTok's assurances were incorrect, lacking GDPR-equivalent protections under Chinese law.Source 5 Company appealing the decision.Source 5

9

Holiday Season Heightens Cyber Risks for Enterprises

Hackers target holidays when security teams are reduced, exploiting unpatched vulnerabilities and weak MFA.Source 7 Sophos advises pre-holiday reviews; past incidents like SolarWinds revealed near Christmas.Source 7 AI may aid defenses during lulls.Source 7

10

AI-Generated Ransomware and NFC Attacks Dominate 2025 Threats

Surge in AI-created ransomware and NFC exploits for contactless payments as 2025 ends.Source 2Source 3 Blurring lines between state espionage and cybercrime using trusted platforms like GitHub.Source 3 PyStoreRAT and Aisuru botnet highlight industrialized threats.Source 3

Latest Internet & Cybersecurity News | DeckBook AI