Digital shields breached by zero-day exploits and critical cyberattacks.

Daily Cybersecurity News - December 23, 2025

Threat Actors Exploit Zero-Day Vulnerability in WatchGuard Firebox Devices

Critical

Executive Summary

A zero-day vulnerability, CVE-2025-14733, is under active exploitation in WatchGuard Firebox firewalls, allowing remote code execution. CISA has added this vulnerability to its KEV catalog, urging federal agencies to patch it immediately.

Vulnerability Details

  • Affected Product: WatchGuard Firebox Fireware OS versions 11.10.2 up to 11.12.4_Update1, 12.0 or higher, and 2025.1 and higher
  • Identifier: CVE-2025-14733
  • CVSS Score: 9.3 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate patching is critical due to active exploitation and potential for remote code execution.
  • Attack Vector: Attackers can send a specially crafted request to the firewall via IKEv2 negotiation, triggering a memory corruption error in the iked process.
  • Ease of Exploit: Exploits can be launched remotely over the network, require no authentication, and do not depend on user interaction.

Action Plan

  • Immediate Action: Upgrade to Fireware OS versions 2025.1.4, 12.11.6, 12.5.15, or 12.3.1_Update4 (B728352).
  • Workaround: Verify strictly if IKEv2 was ever configured. The vulnerability persists in "Zombie" states: if a Mobile/Dynamic VPN was previously configured and deleted, the device remains vulnerable as long as a Static Branch Office VPN exists. Immediate patching is the only reliable fix; merely deleting the dynamic interface is insufficient.
  • Detection: Monitor for outbound connections to the listed IOC IP addresses, IKE process hangs or crashes, and abnormally large CERT or IDi payloads in IKE_AUTH requests.

Relevant professional terms

Zero-Day Vulnerability
A software vulnerability that is known to the vendor but does not have a patch available, and is actively being exploited by attackers.
Out-of-Bounds Write
A type of memory corruption vulnerability that occurs when a program attempts to write data beyond the allocated memory boundaries, potentially leading to arbitrary code execution.
Source: Dark Reading

Critical n8n Flaw Enables Arbitrary Code Execution

Critical

Executive Summary

A critical security vulnerability, CVE-2025-68613, has been disclosed in the n8n workflow automation platform, potentially allowing authenticated attackers to execute arbitrary code with the privileges of the n8n process. This vulnerability has a CVSS score of 9.9 and requires immediate patching.

Vulnerability Details

  • Affected Product: n8n workflow automation platform versions starting from 0.211.0 up to but not including 1.120.4, 1.121.1, and 1.122.0
  • Identifier: CVE-2025-68613
  • CVSS Score: 9.9 (Critical)
  • Exploitation Status: Proof-of-concept exploit code has been released.

Risk & Impact

  • Triage: Immediate patching is required due to the potential for full instance takeover, data exposure, and lateral movement.
  • Attack Vector: By submitting specially crafted workflow expressions, an attacker can execute OS-level commands with the privileges of the n8n process.
  • Ease of Exploit: Exploitation requires authentication but no elevated privileges beyond workflow creation or editing.

Action Plan

  • Immediate Action: Upgrade to n8n versions 1.120.4, 1.121.1, or 1.122.0.
  • Workaround: If upgrading is not immediately possible, limit workflow creation and editing permissions to fully trusted users and/or deploy n8n in a hardened environment with restricted operating system privileges and network access.
  • Detection: Monitor system logs for unauthorized activity and review recent workflow modifications.

Relevant professional terms

Remote Code Execution (RCE)
A vulnerability that allows an attacker to execute arbitrary code on a target system.
CVSS Score
A numerical score reflecting the severity of a vulnerability, helping organizations prioritize their vulnerability management processes.

La Poste Suffers DDoS Attack

Executive Summary

France's national postal service, La Poste, and its banking arm, La Banque Postale, were hit by a suspected cyberattack. The attack, a DDoS incident, disrupted online services, package deliveries, and online payments for millions of customers.

Attack Overview

  • Attack Path: A distributed denial-of-service (DDoS) attack overwhelmed La Poste's digital infrastructure.

Impact Assessment

  • Operational Impact: Disrupted online banking, package deliveries, and online payments.

Strategic Takeaway

The attack highlights the vulnerability of critical infrastructure during peak seasons, emphasizing the need for robust cybersecurity measures.

Relevant professional terms

DDoS
A distributed denial-of-service attack floods a server with traffic, making it unavailable.
Network Incident
An event that disrupts normal network operations.

Uzbekistan License Plate System Exposure

Executive Summary

The Uzbek government's national license plate scanning system was discovered to be exposed to the internet, allowing unauthorized access without a password. This exposure potentially compromises the privacy and security of vehicle and owner data within Uzbekistan.

Attack Overview

  • Attack Path: Unsecured access to the national license plate scanning system via the internet.

Impact Assessment

  • Data Stolen: Potentially all data within the license plate system.

Strategic Takeaway

The lack of password protection highlights a critical failure in access control and security protocols for sensitive government systems.

Relevant professional terms

License Plate Recognition (LPR)
A technology that uses optical character recognition to automatically read vehicle registration plates.
Access Control
Security measures used to control who can access or use resources, including systems, applications, and data.
Source: TechCrunch

Russian Cyberattacks Target Danish Infrastructure

Executive Summary

Pro-Russian groups, Z-Pentest and NoName057(16), conducted cyberattacks against a Danish water utility and Danish websites. The attacks aimed to create insecurity and undermine support for Ukraine.

Key TTPs

  • Initial Access: Exploitation of exposed VNC services (ports 5900-5910) using default or weak credentials to gain direct control over OT/HMI interfaces.
  • Execution: Altering water pressure in waterworks, resulting in burst pipes.
  • Defense Evasion: Going into island mode operation.

Campaign Analysis

The threat actor is executing a "counter-intelligence" operation aiming to neutralize defenders. They disguise the backdoor as legitimate Proof-of-Concept (PoC) exploits for high-profile vulnerabilities (e.g., WatchGuard, WordPress) on GitHub, specifically luring security researchers into executing malicious code.

Targeting & Infrastructure

  • Target Profile: Danish critical infrastructure, including water utilities and government websites.
  • Infrastructure: Compromised Zyxel firewalls were used to conduct DDoS attacks.

Relevant Terms

  • DDoS: A distributed denial-of-service attack floods a server with traffic to make it unavailable.
  • Hybrid War: A strategy combining military and non-military tools to destabilize an adversary.

Webrat Targets Security Researchers via Github

Executive Summary

The Webrat Trojan is being distributed through GitHub repositories, disguising itself as exploits for known vulnerabilities. This campaign targets cybersecurity researchers and inexperienced professionals, aiming to compromise their systems.

Key TTPs

  • Initial Access: Masquerading as vulnerability exploits in GitHub repositories.
  • Execution: Victims are lured into downloading and running the malicious code directly on their machines.
  • Defense Evasion: The malware is packaged into password-protected archives.

Campaign Analysis

The threat actor is attempting to infect information security specialists by disguising the backdoor as game cheats, software cracks, and PoCs. Webrat allows attackers to control infected systems and steal data from cryptocurrency wallets and messaging accounts.

Targeting & Infrastructure

  • Target Profile: Security researchers, budding security professionals, and users interested in vulnerability exploits.
  • Infrastructure: GitHub repositories are used to distribute the malware.

Relevant Terms

  • Trojan: A type of malware that is disguised as legitimate software.
  • Exploit: A piece of code that takes advantage of a vulnerability in a system or application.
Source: Securelist

DOJ Seizes Domain in Bank Account Scheme

Executive Summary

The US Justice Department seized the domain web3adspanels.org, used in a bank account takeover scheme. Cybercriminals targeted US victims, attempting to steal millions through compromised bank accounts.

The Scheme

  • TTP 1: Used malicious ads on Google and Bing to lure users to fake bank websites.
  • TTP 2: Phishing sites tricked victims into handing over login credentials.
  • TTP 3: Stored and manipulated stolen bank login credentials on a backend web panel.

The Consequence

  • Outcome: The scheme resulted in approximately $28 million in attempted losses. (Note: The $14.6 billion figure cited in recent DOJ reports refers to a separate, unrelated National Healthcare Fraud operation).

Strategic Takeaway

The seizure disrupts the criminals' ability to access stolen credentials and steal bank account funds.

Relevant Terms

  • Phishing: Deceptive practice of tricking individuals into revealing sensitive information like usernames, passwords, and credit card details by disguising as a trustworthy entity.
  • Account Takeover: A form of identity theft and fraud where a criminal gains access to someone else's account and uses it as their own.
Source: SecurityWeek