This cybersecurity brief for December 28-29, 2025, covers several critical developments. CISA has issued an urgent warning about the 'MongoBleed' (CVE-2025-14847) vulnerability in MongoDB, now under active exploitation. Supply chain attacks continue to escalate, with Korean Air suffering a breach via a subsidiary, attributed to the Clop ransomware group exploiting an Oracle zero-day. A year-end report confirms that software supply chain attacks more than doubled in 2025. Ransomware groups, including Qilin and Medusa, capitalized on the holiday period to launch a wave of attacks, while malicious Chrome extensions were found to have stolen AI chat data from nearly a million users. Finally, Microsoft and Adobe released their last patches of the year, fixing over 190 vulnerabilities, including an actively exploited Windows zero-day.
Help others stay informed about cybersecurity threats