Blue data pipelines illustrating critical RCE, foreign office breach, and darknet AI.

Daily Cybersecurity News - December 22, 2025

Critical RCE Vulnerability Actively Exploited in WatchGuard Firebox Firewalls

Critical

Executive Summary

Over 115,000 WatchGuard Firebox devices are vulnerable to a critical remote code execution (RCE) vulnerability, CVE-2025-14733, which is being actively exploited, allowing unauthenticated attackers to remotely execute arbitrary code. The vulnerability affects Firebox firewalls running Fireware OS and requires immediate patching or mitigation.

Vulnerability Details

  • Affected Product: WatchGuard Firebox firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and 2025.1 up to and including 2025.1.3
  • Identifier: CVE-2025-14733
  • CVSS Score: 9.3 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Urgent; immediate patching or mitigation is required to prevent potential compromise.
  • Attack Vector: The vulnerability is an out-of-bounds write in the Fireware OS IKEv2 process (iked), allowing remote, unauthenticated attackers to execute arbitrary code by sending crafted IKEv2 packets.
  • Ease of Exploit: Low complexity; successful exploitation enables unauthenticated attackers to execute arbitrary code remotely on vulnerable devices without user interaction.

Action Plan

  • Immediate Action: Upgrade Fireware OS to a fixed version (2025.1.4, 12.11.6, 12.5.15, or 12.3.1_Update4). Note: No patch is available for 11.x versions, which are end-of-life.
  • Workaround: Disable dynamic peer BOVPNs, add new firewall policies, and disable default system policies that handle VPN traffic. If unable to patch immediately, disable Mobile User VPN with IKEv2 and BOVPNs using IKEv2 with dynamic gateway peers, or restrict IKEv2 exposure to only trusted peers.
  • Detection: Monitor for anomalous VPN activity and review logs for indicators of compromise published by WatchGuard, such as abnormally large IKE_AUTH request IDi payloads or evidence of an iked process hang. Check Firebox appliances for signs of compromise, such as outbound traffic to specific IP addresses.

Relevant professional terms

Remote Code Execution (RCE)
A type of security vulnerability that allows an attacker to run arbitrary code on a remote machine or network. This can lead to the deployment of malware, data theft, or complete system takeover.
Firewall
A network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It establishes a barrier between a trusted internal network and untrusted external networks, preventing unauthorized access and malicious traffic.

UK Foreign Office Data Breach

Executive Summary

The UK government confirmed a cyberattack on the Foreign Office in October, with a potential compromise of visa-related data. Investigations are ongoing, with suspicion falling on Chinese state-sponsored actors, though official attribution remains unconfirmed.

Attack Overview

  • Attack Path: The attackers exploited a technical issue to gain access to the system.
  • Attacker: Suspected Chinese state-sponsored actors, possibly Storm-1849/ArcaneDoor.

Impact Assessment

  • Data Stolen: Potentially tens of thousands of visa details.

Strategic Takeaway

This incident highlights the persistent threat of state-sponsored espionage and the importance of securing inter-agency systems.

Relevant professional terms

Espionage
The practice of spying or using secret agents to obtain information, especially regarding a government or organization.
Zero-day Vulnerabilities
A flaw in software or hardware that is unknown to the vendor, making it available for attackers to exploit before a fix is available.
Source: SecurityWeek

Wonderland SMS Stealer Targets Uzbekistan

Executive Summary

Threat actors are using malicious dropper apps disguised as legitimate applications to deliver the Wonderland Android SMS stealer to users in Uzbekistan. The malware campaign has evolved from using pure Trojan APKs to a modular approach using droppers.

Key TTPs

  • Initial Access: Malicious dropper apps masquerading as legitimate applications.
  • Execution: Droppers deploy a built-in malicious payload locally after installation.
  • Defense Evasion: Droppers unpack embedded malware locally, bypassing traditional mobile security checks.

Campaign Analysis

The Wonderland stealer uses bidirectional command-and-control (C2) communication to execute commands in real-time, allowing for arbitrary USSD requests and SMS theft. This campaign marks a shift from "pure" Trojan APKs to more complex, multi-stage infection chains.

Targeting & Infrastructure

  • Target Profile: Users in Uzbekistan.
  • Infrastructure: The malware uses bidirectional command-and-control (C2) communication for real-time commands from operators.

Relevant Terms

  • Dropper: A type of malware that installs other malware onto a target system.
  • RAT (Remote Access Trojan): Malware that allows an attacker to remotely control an infected computer.

Scripted Sparrow: BEC with Automation

Executive Summary

The Scripted Sparrow group is a BEC operation targeting Accounts Payable teams across three continents. They impersonate executive coaching firms, sending millions of fraudulent emails monthly to steal money.

Key TTPs

  • Initial Access: Spearphishing emails with spoofed reply chains and sometimes omitting attachments to build trust.
  • Execution: Fraudulent invoices requesting payments under $50,000 to avoid approval workflows.
  • Defense Evasion: Using location spoofing and browser plugins.

Campaign Analysis

Scripted Sparrow leverages automation to send millions of emails monthly, evolving their tactics to bypass security filters. The group has been active since June 2024, refining their social engineering playbook.

Targeting & Infrastructure

  • Target Profile: Accounts Payable staff at organizations across various industries.
  • Infrastructure: Free webmail accounts, newly registered domains (NameSilo, Dynadot), and compromised legitimate mailboxes.

Actionable Intelligence

  • Domains: [119 malicious domains]
  • Email Addresses: [245 email addresses]
Pro Tip: Tired of spam? Treat your email like a digital passport, not a flyer. Use disposable addresses for sign-ups so you can delete them if they start spamming you.

Relevant Terms

  • BEC: Business Email Compromise, a type of fraud where attackers impersonate legitimate entities to steal money or information.
  • Spearphishing: A targeted phishing attack aimed at specific individuals or organizations.

Nefilim Ransomware: Ukrainian Hacker Pleads Guilty

Executive Summary

The DOJ announced that Ukrainian national Artem Aleksandrovych Stryzhak pleaded guilty to deploying Nefilim ransomware against businesses in the United States and other countries. Stryzhak gained access to the ransomware's backend platform in exchange for a percentage of extorted funds.

The Scheme

  • TTP 1: Exploited the "panel" to deploy ransomware after data theft and encryption.
  • TTP 2: Targeted companies with revenues exceeding $200 million in the US, Canada, and Australia.
  • TTP 3: Threatened to publish stolen data on "Corporate Leaks" websites if ransoms weren't paid.

The Players

  • Facilitators Arrested:Artem Aleksandrovych Stryzhak

The Consequence

  • Outcome: Stryzhak pleaded guilty to conspiracy to commit computer fraud and faces a maximum of 10 years in prison.

Strategic Takeaway

The guilty plea highlights ongoing international efforts to combat ransomware by arresting and extraditing cybercriminals.

Relevant Terms

  • Ransomware: A type of malware that encrypts a victim's files, demanding a ransom for their decryption.
  • Extradition: The legal process by which a country transfers a person to another country for criminal prosecution or punishment.

DIG AI: Uncensored Darknet AI Assistant

Executive Summary

DIG AI is an uncensored AI assistant available on the darknet that provides unrestricted guidance and support to cybercriminals and terrorists. It enables malicious actors to leverage advanced data processing capabilities for illicit purposes, bypassing content protection policies.

Key Features

  • Provides unrestricted access to AI-driven assistance for illegal activities such as hacking and fraud.
  • Generates tips ranging from explosive device manufacturing to illegal content creation, including CSAM.
  • Automates the generation of malicious scripts to backdoor vulnerable web applications.

Use Case (The "So What?")

DIG AI lowers the barrier for entry into cybercrime by providing sophisticated AI-driven capabilities that can enhance the planning and execution of criminal operations. Red teams can use this information to understand the evolving threat landscape, while blue teams can focus on proactive darknet intelligence and strengthening cyber defenses against AI-augmented threats.

Availability

Accessible via the Tor browser on the darknet.

Relevant Terms

  • Darknet: A network of websites that are not accessible through regular search engines; often used for illicit activities.
  • CSAM: Child Sexual Abuse Material.