CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (23 December 2025)

Published: Loading…

At a Glance

  • Over 115,000 WatchGuard Firebox devices remained exposed to active exploitation of CVE-2025-14733, an unauthenticated RCE flaw in Fireware OS.
  • A Ukrainian national pleaded guilty in the US for acting as a Nefilim ransomware affiliate targeting organisations across multiple countries.
  • Romania’s national water authority confirmed a ransomware attack disrupting around 1,000 systems while maintaining critical operations.
  • Multiple investigations detailed supply-chain and trust abuse, including a malicious WhatsApp API npm package downloaded over 56,000 times.
  • Large-scale data exposure incidents affected Pornhub Premium users via Mixpanel analytics and 33.7 million Coupang customers after prolonged unauthorised access.

Summary

Widespread exploitation of perimeter technologies dominated activity, led by the WatchGuard Firebox zero-day CVE-2025-14733 affecting more than 115,000 exposed firewalls. Active attacks against Fireware OS appliances coincided with patch releases, highlighting continued targeting of network edge infrastructure.

Ransomware activity combined operational disruption with legal consequences, as Romania’s national water authority confirmed a ransomware incident impacting roughly 1,000 systems while services continued manually. Separately, a Ukrainian defendant admitted participation as a Nefilim affiliate, linking law enforcement action directly to past multinational ransomware campaigns.

Supply-chain and software trust abuse featured prominently across ecosystems. A malicious WhatsApp API package on npm, downloaded more than 56,000 times, enabled message interception and account takeover, while open-source monitoring tool Nezha was repurposed for post-exploitation control.

Consumer and enterprise data exposure remained significant. Pornhub disclosed risks of sextortion following a Mixpanel-linked breach affecting over 200 million historical Premium records, while Coupang reported unauthorised access impacting 33.7 million users over several months.

Malware campaigns increasingly leveraged signed or trusted delivery mechanisms. MacSync macOS malware was distributed through a signed Swift application that bypassed Gatekeeper checks, while Android operations combined droppers, SMS theft and RAT capabilities at scale.

Regulatory and enforcement responses intensified alongside technical incidents. Operation Sentinel, coordinated by Interpol and Europol, resulted in 574 arrests tied to BEC, extortion and ransomware, as governments including South Korea advanced stricter identity verification following large-scale fraud exposure.

Highlights of the Day

South Korea mandates facial scans for new SIM registrations

South Korea will require mobile carriers to verify new SIM customers using facial recognition, aiming to curb phone-based scams enabled by stolen personal data. The measure extends existing identity checks by integrating biometric verification through carrier-operated digital ID apps, following several large-scale data breaches affecting tens of millions of residents.

WatchGuard firewall flaw enables remote code execution attacks

A critical vulnerability in WatchGuard Firebox firewalls has left more than 115,000 internet-exposed devices susceptible to active exploitation. Tracked as CVE-2025-14733, the flaw allows unauthenticated remote code execution through affected IKEv2 VPN configurations in Fireware OS, prompting its inclusion in CISA’s Known Exploited Vulnerabilities catalogue.

Nefilim ransomware affiliate pleads guilty in US case

A Ukrainian national has admitted participating as an affiliate in the Nefilim ransomware operation, which targeted large organisations across North America and Europe. Court filings describe how customised ransomware was deployed against high-revenue companies, with victims pressured through data theft and extortion threats.

MacSync malware adopts signed Swift applications

MacSync Stealer has evolved to use code-signed and notarised Swift applications, reducing the need for user interaction and bypassing traditional macOS security checks. Analysis shows the malware now delivers its payload through a native dropper that retrieves and executes second-stage components while limiting on-disk traces.

Malicious Chrome extensions spy on users via fake VPN service

Researchers uncovered two Chrome extensions posing as network testing tools that covertly intercept web traffic and exfiltrate user data. Operating under the name Phantom Shuttle, the extensions function as man-in-the-middle proxies, routing traffic through attacker-controlled infrastructure while harvesting credentials from paying subscribers.

Daily Coverage

Developments
Watchguard Firebox RceNefilim Affiliate Guilty PleaRomanian Water RansomwareMalicious Npm Packages
Vulnerabilities
CVE-2025-68613N8N >= 0.211.0, < 1.120.4 (Critical)CVE-2025-14733Fireware Os 11.10.2 (Critical)CVE-2025-13715Facedetection-Dsfd 09Deec4376F397A1124F71Bc81210Fadfaac296E (High)CVE-2025-68614Librenms < 25.12.0 (Medium)CVE-2025-68615Net-Snmp < 5.9.5 (Critical)