This cybersecurity brief for December 31, 2025, covers a series of high-impact events, including the discovery of critical vulnerabilities in widely used technologies and significant data breaches stemming from supply chain compromises. Key incidents include 'MongoBleed,' a critical memory disclosure flaw in MongoDB, and a remote-hijacking vulnerability in WHILL electric wheelchairs. Supply chain attacks resulted in an $8.5 million theft from Trust Wallet users and the exposure of 30,000 Korean Air employee records. Additionally, a new malicious AI tool, 'DIG AI,' has emerged on the dark web, designed to automate cybercrime, and former cybersecurity professionals have pleaded guilty to conducting ransomware attacks, highlighting a severe insider threat.
Help others stay informed about cybersecurity threats