This cybersecurity advisory for December 20, 2025, covers a surge of critical vulnerabilities and active zero-day exploits. Major vendors including HPE, WatchGuard, Cisco, Apple, and MongoDB are scrambling to patch flaws being weaponized by threat actors, with CISA issuing multiple emergency directives. Highlights include a perfect 10.0 CVSS score for an HPE OneView RCE, actively exploited zero-days in Cisco email gateways and Apple products, and a memory leak in MongoDB dubbed 'MongoBleed'. Other significant events include a major data breach at the University of Sydney, a guilty plea from a Nefilim ransomware operator, and new social engineering attacks targeting WhatsApp users.
Help others stay informed about cybersecurity threats