This cybersecurity brief for December 24, 2025, covers a surge of actively exploited critical vulnerabilities. Chinese state-sponsored actors are leveraging a CVSS 10.0 zero-day in Cisco email gateways, while another CVSS 10.0 flaw, React2Shell, is being used by nation-states against SaaS and FinTech firms. CISA has issued urgent patch deadlines for these, as well as for exploited flaws in WatchGuard firewalls, Fortinet devices, and the Android OS. Major data breaches were also disclosed, with Nissan confirming a supply chain attack via Red Hat affecting 21,000 customers, and the University of Sydney reporting a breach impacting 27,000 individuals due to a DevSecOps failure.
Help others stay informed about cybersecurity threats