Digital shields failing against AI deepfakes and network data exposures.

Daily Cybersecurity News - December 24, 2025

Flock AI Camera Feeds Exposed

Executive Summary

More than 60 Flock AI-powered surveillance cameras had their live streams exposed on the web without requiring a username or password. Critical vulnerabilities CVE-2025-59403 (Auth Bypass) and CVE-2025-59405 (Hardcoded Credentials) have been assigned. While the vendor claims a cloud fix, firmware remains vulnerable.

Vulnerability Details

  • Affected Product: Flock AI Surveillance Cameras
  • Identifier: CVE-2025-59403 & CVE-2025-59405
  • Exploitation Status: Trivial / Active Exposure

Risk & Impact

  • Triage: High Urgency
  • Attack Vector: Unprotected web access to live camera feeds.
  • Ease of Exploit: Trivial

Action Plan

  • Immediate Action: Secure all Flock AI camera feeds with proper authentication.
  • Workaround: Implement network segmentation to isolate camera feeds.
  • Detection: Monitor network traffic for unauthorized access to camera feeds.

Relevant professional terms

Surveillance Camera
A video camera used for observing an area.
Authentication
The process of verifying the identity of a user, device, or other entity.
Source: The Verge

University of Phoenix Data Breach

Executive Summary

The University of Phoenix suffered a data breach affecting approximately 3.5 million individuals after unauthorized access to its systems. The Clop ransomware group claimed responsibility, exploiting a zero-day vulnerability in the Oracle E-Business Suite (EBS).

Attack Overview

  • Attack Path: Exploitation of a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS).
  • Attacker: Clop ransomware group.

Impact Assessment

  • Data Stolen: Sensitive personal and financial information, including names, contact information, dates of birth, Social Security numbers, and bank account details, of approximately 3.5 million individuals.

Detection & Hunting

  • IOCs: e90bdaaf5f9ca900133b699f18e4062562148169b29cb4eb37a0577388c22527, 55e070a86b3ef2488d0e58f945f432aca494bfe65c9c4363d739649225efbbd1, 37546b811e369547c8bd631fa4399730d3bdaff635e744d83632b74f44f56cf6.

Strategic Takeaway

The exploitation of a zero-day vulnerability highlights the need for proactive threat hunting and robust patch management strategies.

Relevant professional terms

Ransomware
A type of malware that encrypts a victim's files, rendering them inaccessible, and demands a ransom payment to restore access.
Zero-day Vulnerability
A software vulnerability that is unknown to the vendor and for which no patch is available, making it highly dangerous.

Uzbekistan ALPR System Exposure

Executive Summary

Uzbekistan's national license plate scanning system was exposed to the internet due to a lack of password protection. This allowed unauthorized access to sensitive data, including vehicle locations, driver images, and traffic violations.

Attack Overview

  • Attack Path: Unauthenticated access to the surveillance system via the internet.

Impact Assessment

  • Data Stolen: Terabytes of data (millions of records/events), including vehicle locations, driver images, and traffic violations.

Strategic Takeaway

The exposure highlights the critical need for robust access controls and security measures in national surveillance systems to protect sensitive personal data.

Relevant professional terms

ALPR (Automatic License Plate Recognition)
A technology that uses optical character recognition to automatically read vehicle license plates.
Surveillance System
A system used to monitor the activities, behavior, or other changing information, usually of people for the purpose of influence, management, direction, or protection.
Source: TechCrunch

Urban Vpn Proxy Intercepts AI Chats

Executive Summary

The Urban VPN Proxy browser extension is intercepting and capturing user conversations across multiple AI platforms. This data harvesting is enabled by default, without a user-facing option to disable it, and operates continuously, regardless of VPN functionality.

Key TTPs

  • Initial Access: Users install the Urban VPN Proxy browser extension.
  • Execution: The extension uses dedicated "executor" scripts for each targeted AI platform to actively intercept and capture conversational data.
  • Defense Evasion: The harvesting is enabled by default with no user-facing toggle to disable.

Campaign Analysis

The extension injects code into supported AI websites, overriding standard browser network functions to capture prompts, responses, timestamps, and session identifiers. The collected data is then compressed and transmitted to analytics servers.

Targeting & Infrastructure

  • Target Profile: Users of AI platforms such as ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), and Meta AI.
  • Infrastructure: The extension affects over 8 million users across Chrome and Edge.

Actionable Intelligence

  • IPs: N/A
  • Domains: N/A

Relevant Terms

  • Data Exfiltration: The unauthorized transfer of data from a computer or network to an external device or location.
  • Clickstream Data: A record of the websites a user has visited and the sequence of clicks they made while browsing the Internet.

Evasive Panda Targets DNS with MgBot

Executive Summary

The Evasive Panda APT group is conducting adversary-in-the-middle (AitM) attacks to deliver the MgBot implant. This campaign, active from November 2022 to November 2024, showcases the group's evolving tactics.

Key TTPs

  • Initial Access: Strategic website compromise and supply chain intrusion.
  • Execution: Uses shellcode encrypted with DPAPI and RC5 to deploy MgBot.
  • Defense Evasion: Employs a new loader to evade detection and uses hybrid encryption.

Campaign Analysis

Evasive Panda is improving its tactics by developing new loaders and employing hybrid encryption practices. The group leverages distinct implants for Windows (MgBot) and macOS (Macma).

Targeting & Infrastructure

  • Target Profile: Targets include government entities, NGOs, universities, and private individuals, primarily in Taiwan, Hong Kong, and mainland China.
  • Infrastructure: Compromised Internet service providers (ISPs) are used to distribute malicious software updates.

Actionable Intelligence

  • IPs: 60.28.124.21, 123.139.57.103, 140.205.220.98

Relevant Terms

  • APT: An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack targeting specific entities.
  • DNS Poisoning: A type of DNS attack where falsified DNS records are introduced to redirect traffic to malicious servers.
Source: Securelist

WebRAT Distributed Via GitHub PoCs

Executive Summary

The WebRAT malware is being spread through GitHub repositories disguised as proof-of-concept exploits. This campaign targets users seeking game cheats, pirated software, and security researchers.

Key TTPs

  • Initial Access: Exploiting GitHub repositories with fake PoCs.
  • Execution: Dropper (rasmanesc.exe) elevates privileges and disables Windows Defender to download WebRAT.
  • Defense Evasion: Uses password-protected ZIP archives with decoy files.

Campaign Analysis

The malware is sold to cybercriminals, and discussions suggest it has been used for blackmail and swatting. WebRAT can deploy additional malicious payloads like cryptocurrency miners.

Targeting & Infrastructure

  • Target Profile: Gamers, users of pirated software, and security researchers.
  • Infrastructure: GitHub repositories, YouTube, and pirated software websites.

Actionable Intelligence

  • Domains: ezc5510min.temp.swtest[.]ru, shopsleta[.]ru
  • IPs: 104.21.80.1 (UDP).

Relevant Terms

  • RAT (Remote Access Trojan): Malware that allows an attacker to control a system.
  • Dropper: A type of malware that installs other malware onto a target system.

Nomani Scam Leverages AI Deepfakes for Investment Fraud

Executive Summary

The Nomani investment scam utilizes AI-generated deepfake videos and social media malvertising to deceive users into investing in fraudulent schemes. This campaign targets individuals through social media platforms, aiming to steal money and personal data.

Key TTPs

  • Initial Access: Fraudulent ads on social media platforms like Facebook and YouTube, often impersonating legitimate brands and trusted entities.
  • Execution: Victims are directed to phishing websites that mimic local news outlets or advertise cryptocurrency management tools.
  • Defense Evasion: Use of AI-generated video testimonials featuring well-known personalities to build trust.

Campaign Analysis

The Nomani scam has grown significantly, with a 62% increase in detections, expanding its reach beyond Facebook to other platforms. This campaign uses increasingly short-lived ad campaigns designed to churn identities and infrastructure faster than defenders can blacklist.

Targeting & Infrastructure

  • Target Profile: Individuals interested in investment opportunities, including those previously targeted by scams.
  • Infrastructure: Utilizes fake social media profiles, stolen legitimate accounts, and phishing websites mimicking trusted brands.

Actionable Intelligence

  • Domains:Quantum Bumex, Immediate Mator, Bitcoin Trader

Relevant Terms

  • Deepfake: AI-generated videos that convincingly mimic a person's appearance and voice.
  • Phishing: A technique used by cybercriminals to deceive individuals into revealing sensitive information via deceptive websites.