Daily Digest

CISA Warns of Actively Exploited 'MongoBleed' Flaw; Supply Chain Attacks Double in 2025 Amid Holiday Ransomware Surge

CISA Warns of Actively Exploited 'MongoBleed' Flaw; Supply Chain Attacks Double in 2025 Amid Holiday Ransomware Surge

December 29, 2025
7 articles (5 new, 2 updated)
21 min read

Summary

This cybersecurity brief for December 28-29, 2025, covers several critical developments. CISA has issued an urgent warning about the 'MongoBleed' (CVE-2025-14847) vulnerability in MongoDB, now under active exploitation. Supply chain attacks continue to escalate, with Korean Air suffering a breach via a subsidiary, attributed to the Clop ransomware group exploiting an Oracle zero-day. A year-end report confirms that software supply chain attacks more than doubled in 2025. Ransomware groups, including Qilin and Medusa, capitalized on the holiday period to launch a wave of attacks, while malicious Chrome extensions were found to have stolen AI chat data from nearly a million users. Finally, Microsoft and Adobe released their last patches of the year, fixing over 190 vulnerabilities, including an actively exploited Windows zero-day.

Filter by Category

New Articles (5)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats