Multiple nation-state actors, including China, Russia, Iran, and North Korea, are intensifying cyber operations targeting critical infrastructure, government entities, and private sector organizations worldwide. China-linked groups such as Ink Dragon have expanded espionage campaigns against European governments, while Russia-linked actors like Callisto have targeted NGOs and are implicated in disruptive attacks in Europe. Iran's MuddyWater has focused on critical infrastructure in Israel and Egypt, and North Korea is increasing disruptive attacks on various sectors. These activities are accompanied by sophisticated cybercrime campaigns, exploitation of zero-day vulnerabilities, and significant data breaches affecting sectors such as health, telecommunications, and justice.
In response, Western governments and institutions are taking legal and policy actions, including EU sanctions and fines, UK and Polish legal proceedings against Russian actors, and increased attribution of attacks to state-sponsored groups. However, there is growing concern that U.S. cyber defenses are lagging behind adversaries, with strained mission capacity, weakened public-private collaboration, and unstable federal leadership. Experts call for renewed strategic focus, improved coordination with allies, and robust policy reforms to counter the persistent and evolving threat landscape posed by hostile nation-states.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
On publication of the op-ed, former Cyberspace Solarium Commission leaders warned that U.S. cyber defenses were falling behind due to leadership instability, workforce shortages, weakened public-private collaboration, and reduced international coordination. They urged rapid action to restore CISA leadership, rebuild cyber diplomacy capacity, and address federal cybersecurity staffing and funding problems.
During December 2025, several policy developments were reported, including safe-harbour laws for security researchers, bans on certain apps and devices, and new cybersecurity partnerships. CERT-EU presented these as notable governance and regulatory actions for the month.
In December 2025, multiple zero-day and known vulnerabilities, including flaws affecting SonicWall, Fortinet, Cisco, and React2Shell, were actively exploited. CERT-EU said both opportunistic actors and China-linked groups were involved in related campaigns.
During December 2025, data breaches were reported affecting France's Ministry of Interior, telecom provider SFR, Barts Health NHS, and Docker Hub. CERT-EU grouped these as major breach events disclosed during the month.
In December 2025, Venezuela's state oil company experienced a disruptive cyberattack. CERT-EU highlighted the incident as part of a broader pattern of disruptive operations.
In December 2025, Romania's water agency was affected by a disruptive cyber incident. CERT-EU included the case among significant attacks on essential services.
In December 2025, disruptive attacks affected postal and banking services in France. CERT-EU cited the incidents as examples of operational disruption impacting public-facing services.
In December 2025, large-scale campaigns involving malicious browser extensions were identified. CERT-EU listed them among the month's major cybercrime and user-targeting threats.
During December 2025, ransomware operators were reported exploiting endpoint detection and response tools as part of their attack chains. CERT-EU highlighted this as a notable evolution in ransomware tradecraft.
In December 2025, the Spiderman phishing kit was used in campaigns aimed at European banks. CERT-EU cited it as a major cybercrime development during the month.
In December 2025, the Iran-linked MuddyWater group conducted operations against critical infrastructure targets in Israel and Egypt. CERT-EU included the activity among the month's notable state-sponsored campaigns.
In December 2025, China-linked actors including Ink Dragon and ShadyPanda expanded espionage and surveillance operations targeting European governments and users globally. CERT-EU identified these campaigns as part of a broader rise in state-sponsored activity.
During December 2025, the United Kingdom and Poland stepped up legal actions targeting Russian intelligence activity. CERT-EU highlighted these measures as part of the month's response to state-backed cyber and hybrid threats.
In December 2025, the European Union sanctioned Russian individuals and entities in response to hybrid threats. The action was part of a broader set of legal and policy responses to hostile state activity.
In December 2025, the European Union imposed a €120 million fine on X, formerly Twitter, for violations of the Digital Services Act. CERT-EU listed the penalty as a notable regulatory cyber-related development for the month.
During December 2025, CERT-EU reported increased state-sponsored operations, disruptive attacks, cybercrime, and active exploitation of vulnerabilities across Europe and globally. The activity included campaigns linked to China and Iran, ransomware incidents, phishing operations, and multiple significant breaches and service disruptions.
The Cyberspace Solarium Commission previously published bipartisan recommendations to strengthen U.S. cyber defense and layered deterrence, which later authors cited as the foundation for needed reforms. The exact date is not specified in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.