Latest Internet & Cybersecurity News

đź“…December 30, 2025 at 1:00 AM
Critical exploits like MongoBleed in MongoDB and Chrome extension hacks dominate cybersecurity news, alongside massive credential leaks, ransomware recaps, and AI threats as 2025 ends.
1

Dozens of Chrome Extensions Hacked, Exposing Millions to Data Theft

Dozens of popular Chrome extensions were compromised, potentially exposing millions of users to data theft through malicious updates.Source 1 The breaches occurred over the weekend, highlighting risks in browser extension ecosystems.Source 1 Users are urged to review and update extensions immediately.Source 1

2

MongoBleed Vulnerability (CVE-2025-14847) Under Active Exploitation

A critical MongoDB flaw allowing unauthenticated data leaks from heap memory is being actively exploited worldwide.Source 7Source 9 Over 87,000 vulnerable servers are exposed, mainly in the US, China, Germany, and India.Source 7Source 9 MongoDB issued urgent patching advisories amid public PoC exploits.Source 9

3

Historic Mega Leak of 16 Billion Credentials Exposed

A massive dataset aggregating 16 billion login credentials from Google, Apple, Facebook, and GitHub was disclosed, marking the largest password exposure ever.Source 2 Threat actors quickly began exploiting it for attacks.Source 2 Organizations must urgently review and reset affected credentials.Source 2

4

Trust Wallet Extension Hack Leads to $7 Million Crypto Theft

Trust Wallet confirmed a hack on its browser extension, resulting in $7 million in cryptocurrency stolen from users.Source 1 The incident underscores vulnerabilities in crypto wallet extensions.Source 1 Affected users should monitor accounts and enable enhanced security.Source 1

5

WatchGuard Firebox Critical RCE Vulnerability Exploited

Over 115,000 WatchGuard Firebox devices remain unpatched against CVE-2025-14733, enabling unauthenticated remote code execution via IKEv2 VPN.Source 2 CISA added it to KEV catalog, mandating federal patches by Dec 26.Source 2 Global exposures persist into the holidays.Source 2

6

Coupang Pays $1.18 Billion Compensation for Data Leak

South Korean e-commerce giant Coupang announced $1.18 billion in compensation to users affected by a major data leak.Source 1 The breach exposed sensitive customer information.Source 1 This highlights ongoing accountability pressures post-incidents.Source 1

7

FortiGate Authentication Bypass Threats Emerge

New FortiGate vulnerabilities enable authentication bypass, urging audits of logs and management interfaces.Source 2 Professionals must restrict exposures to prevent unauthorized access.Source 2 The flaws pose risks to network perimeters.Source 2

8

MENA Region Targeted by Coordinated Fake Job Scams

A campaign impersonating recruiters targets MENA professionals at energy and finance firms like Aramco via LinkedIn ads.Source 2 Victims install infostealer malware stealing VPN credentials.Source 2 It bypasses defenses through social engineering.Source 2

9

Hacker Claims Theft of 40 Million Condé Nast Records

A hacker leaked Wired records and threatens to release 40 million more from Condé Nast after a data breach.Source 13 The incident follows initial Wired exposure.Source 13 Publishers face rising data theft risks.Source 13

10

Goldman Sachs Warns Clients of Outside Law Firm Breach

Goldman Sachs alerted clients about a data breach at an external law firm, potentially exposing sensitive information.Source 1 The warning emphasizes third-party risks.Source 1 Clients should enhance monitoring and security.Source 1

11

AI Supply Chain Poisoning and Credential Theft Rise in 2025

Malware hidden in Hugging Face AI models and trojanized PyPI packages targeted developers using Pickle serialization.Source 5 LLMjacking steals credentials for unauthorized AI access, with Microsoft suing offenders.Source 5 Vetting sources is critical for AI security.Source 5