This cybersecurity advisory for December 28, 2025, covers a series of critical threats, including the active exploitation of the "MongoBleed" (CVE-2025-14847) memory leak in MongoDB and the "React2Shell" (CVE-2025-55182) RCE vulnerability in the React framework. The period also saw major data breach disclosures from 700Credit and Baker University, affecting millions. Ransomware activity remains high, with attacks on Romanian critical infrastructure by "The Gentlemen" and a claimed breach of Chrysler by the Everest group. State-sponsored activity also features prominently with updated advisories on the BRICKSTORM backdoor and the re-emergence of Iran's "Prince of Persia" APT.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.