For the period ending December 21, 2025, the cybersecurity landscape is dominated by a surge in actively exploited critical vulnerabilities. Security teams are grappling with zero-days in Microsoft Windows, SonicWall, and WatchGuard appliances, all added to CISA's KEV catalog. A new CVSS 10.0 flaw dubbed 'React2Shell' is being used to compromise web applications globally. Major incidents also include a significant data breach at fintech vendor Marquis impacting over 400,000 bank customers, a sophisticated 'GhostPairing' account takeover attack on WhatsApp, and a ransomware strike on an Australian fertility clinic. These events highlight persistent threats from unpatched systems, supply chain weaknesses, and social engineering.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.