In the 24-hour period ending December 22, 2025, the cybersecurity landscape was dominated by a significant ransomware attack on Romania's national water authority, which disrupted IT systems but spared critical water operations. Concurrently, Apple issued emergency patches for two actively exploited zero-day vulnerabilities in its WebKit engine. Major data breach disclosures also made headlines, with Nissan revealing a third-party breach affecting 21,000 customers, the University of Phoenix confirming a Clop ransomware incident impacting 3.5 million individuals, and AllerVie Health notifying patients of an attack by the Anubis ransomware group. These events highlight ongoing threats to critical infrastructure, the persistent danger of zero-day exploits, and the expanding attack surface through supply chains.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.