Multiple critical zero-day vulnerabilities affecting Windows, Chrome, Apple devices, and popular enterprise software were actively exploited in December 2025, with attackers rapidly weaponizing newly disclosed flaws. Notable incidents included the exploitation of the React2Shell vulnerability in React 19, which was leveraged by a range of threat actors—from Chinese state-sponsored groups to North Korean-linked campaigns—deploying malware such as EtherRAT, PeerBlight, and BPFDoor. Emergency patches were released by vendors including Google and Apple, while Microsoft addressed an actively exploited Windows zero-day in its Patch Tuesday updates. The MITRE Top 25 Most Dangerous Software Weaknesses list for 2025 highlighted persistent coding errors that continue to be targeted by adversaries, emphasizing the need for secure development practices.
Supply chain attacks also surged, with threat actors increasingly targeting GitHub Actions to compromise software development workflows. High-profile incidents such as the exploitation of Gogs and other open-source platforms underscored the risks inherent in collaborative coding environments. Security researchers and agencies like CISA responded by adding new vulnerabilities to their Known Exploited Vulnerabilities catalogs and urging organizations to prioritize patching and adopt a shared responsibility model for securing code repositories. The rapid pace of exploitation and the diversity of attack vectors reinforced the importance of agility, visibility, and proactive defense in enterprise cybersecurity strategies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
The US Cybersecurity and Infrastructure Security Agency added exploited vulnerabilities affecting products including Ivanti EPM, Microsoft Windows, WinRAR, Sierra Wireless AirLink ALEOS, OSGeo GeoServer, and Meta React Server Components to its Known Exploited Vulnerabilities catalog. The additions signaled active risk and the need for urgent remediation.
Google and Apple released emergency security updates in response to targeted attacks exploiting vulnerabilities in their products. The updates were reported alongside active exploitation of Chrome and Apple zero-days.
The Cl0p ransomware group exploited an Oracle E-Business Suite zero-day to breach Barts Health NHS. The incident was highlighted as a notable example of active zero-day exploitation against a major healthcare target.
At Black Hat Europe, Wiz researchers Amitai Cohen and Rami McCarthy presented findings on the increase in GitHub Actions supply chain attacks and called for a shared-responsibility model for open-source security. Their presentation drew on GitHub threat intelligence and aimed to raise awareness of underreported CI/CD risks.
The FBI issued a warning about virtual kidnapping scams in which criminals manipulate victims' social media photos to make extortion attempts more convincing. The alert highlighted the growing use of AI-assisted deception in fraud schemes.
A phishing kit known as Spiderman emerged targeting European banks with advanced credential theft techniques. Reporting described it as part of a broader wave of increasingly sophisticated phishing operations in late 2025.
Threat actors were reported using platforms such as ChatGPT and Grok, along with poisoned search results, to distribute malware including AMOS Stealer. The activity reflected a broader trend of abusing trusted AI services for social engineering and malware delivery.
A vulnerability dubbed GeminiJack in Google Gemini Enterprise was reported as enabling zero-click data exfiltration through prompt injection. The issue underscored the security risks of AI assistants with broad access to enterprise data.
A remote code execution zero-day in Gogs, tracked as CVE-2025-8110, was publicly reported as under active exploitation. The flaw was listed among several high-priority vulnerabilities being weaponized in December 2025.
Multiple threat actors, including Chinese state-linked and North Korea-linked operators, began exploiting React2Shell shortly after disclosure. The activity led to malware delivery campaigns involving tools such as EtherRAT and PeerBlight and left more than 165,000 IPs exposed according to one report.
A critical remote code execution flaw dubbed React2Shell, tracked as CVE-2025-55182, was disclosed in React 19 and React/Next.js server components. Reporting described the bug as severe and rapidly weaponized after disclosure.
A major data breach at South Korean retailer Coupang resulted in the resignation of the company's CEO. The reporting frames the resignation as a significant consequence of the breach, though no further incident date is provided.
Throughout 2025, attackers increasingly abused misconfigured GitHub Actions workflows to compromise open-source software and expose secrets such as access keys and tokens. Reported incidents affected projects including Ultralytics, Singularity, Shibaud/Shai-Hulud, and tj-actions/changed-files, with one attack reportedly impacting Coinbase and nearly 70,000 customers.
Security reporting in December 2025 cited 2023 as a record year for ransomware payments, totaling $4.5 billion. The figure was presented as context for the growing scale of cybercrime and extortion activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcesecurityaffairs.com
Open sourcevulnu.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.