This cybersecurity advisory for December 20, 2025, covers a surge of critical vulnerabilities and active zero-day exploits. Major vendors including HPE, WatchGuard, Cisco, Apple, and MongoDB are scrambling to patch flaws being weaponized by threat actors, with CISA issuing multiple emergency directives. Highlights include a perfect 10.0 CVSS score for an HPE OneView RCE, actively exploited zero-days in Cisco email gateways and Apple products, and a memory leak in MongoDB dubbed 'MongoBleed'. Other significant events include a major data breach at the University of Sydney, a guilty plea from a Nefilim ransomware operator, and new social engineering attacks targeting WhatsApp users.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.