Isometric network nodes revealing critical vulnerabilities and cyber attack news.

Daily Cybersecurity News - December 27, 2025

CVE-2025-68156: Expr Denial of Service via Unbounded Recursion

High

Executive Summary

CVE-2025-68156 affects the Expr expression language, where unbounded recursion in built-in functions can lead to a denial-of-service; the issue is fixed in version 1.17.7. This vulnerability can cause a process-level crash due to stack exhaustion when evaluating expressions that invoke certain built-in functions on untrusted data.

Vulnerability Details

  • Affected Product: Expr versions 1.0.0 through 1.17.6
  • Identifier: CVE-2025-68156
  • CVSS Score: 7.5 (High)
  • Exploitation Status: Proof of concept exists

Risk & Impact

  • Triage: Upgrade immediately to prevent potential denial-of-service.
  • Attack Vector: A remote attacker can pass specially crafted input to trigger uncontrolled recursion in functions like `flatten`, `min`, `max`, `mean`, and `median`.
  • Ease of Exploit: Low attack complexity and no required privileges make it an easy target.

Action Plan

  • Immediate Action: Upgrade to Expr version 1.17.7 or later.
  • Workaround: Ensure evaluation environments do not contain cyclic references; validate or sanitize external data before passing it to Expr; wrap expression evaluation with panic recovery.
  • Detection: Monitor for unusual CPU usage or application crashes resulting from stack overflow.

Relevant professional terms

Denial of Service (DoS)
An attack that attempts to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to a network.
Stack Overflow
A situation in which a program attempts to write data beyond the boundaries of the stack, potentially leading to a crash or arbitrary code execution.

New MongoDB Vulnerability Allows Unauthenticated Memory Access

High

Executive Summary

A high severity vulnerability in MongoDB, identified as CVE 2025-14847, allows unauthenticated attackers to read uninitialized heap memory due to improper handling of length parameter inconsistency; status is confirmed as a critical Memory Disclosure analogous to "Heartbleed".

Vulnerability Details

  • Affected Product: MongoDB
  • Identifier: CVE-2025-14847
  • CVSS Score: 8.7 (High)

Risk & Impact

  • Triage: Critical - Immediate patching or mitigation required.
  • Attack Vector: Unauthenticated network access.
  • Ease of Exploit: Potentially high due to unauthenticated access.

Action Plan

  • Immediate Action: Apply available patches or upgrade to a secure version.
  • Workaround: Disable zlib compression (via net.compression.compressors) to neutralize the exploit path without binary upgrades; restrict network access.
  • Detection: Monitor for unusual network activity and access patterns.

Relevant professional terms

Heap Memory
A region of a computer's memory that is dynamically allocated and used by programs during runtime.
Unauthenticated Access
Access to a system or data that is granted without requiring the user to provide credentials or prove their identity.

Trust Wallet: Chrome Extension Exploit

Executive Summary

A security incident involving the Trust Wallet Chrome extension version 2.68 led to approximately $7 million in losses for users. The attackers injected malicious code into the extension, compromising user's seed phrases.

Attack Overview

  • Attack Path: A compromised Chrome extension update (version 2.68) contained malicious code that exfiltrated users' seed phrases. The malicious code was disguised as legitimate analytics code.

Impact Assessment

  • Data Stolen: User's seed phrases were stolen.

Detection & Hunting

  • IOCs: The malicious domain used was api.metrics-trustwallet[.]com.

Strategic Takeaway

The incident highlights the increasing risks associated with browser-based wallets and the importance of supply chain security.

Relevant professional terms

Supply Chain Attack
A cyberattack that targets vulnerabilities in the supply chain, such as software updates, to compromise the end-users.
Seed Phrase
A series of words that can be used to recover a cryptocurrency wallet.

Grubhub Crypto Scam Campaign

Executive Summary

Grubhub users are targeted with fraudulent emails promising a tenfold Bitcoin payout in exchange for an initial transfer to a specified wallet. The goal of this campaign is to steal cryptocurrency from unsuspecting victims.

Key TTPs

  • Initial Access: Phishing emails sent to Grubhub users.
  • Execution: Victims are lured into sending Bitcoin to a specified wallet.
  • Defense Evasion: Emails appear to originate from a legitimate Grubhub subdomain.

Campaign Analysis

This is a classic crypto reward scam that has been observed over the past few years. Analysis indicates a probable Compromised Third-Party Marketing Vendor, as the emails passed SPF and DKIM authentication checks, which is technically difficult to achieve via simple DNS takeover.

Targeting & Infrastructure

  • Target Profile: Grubhub users, including merchant partners and restaurants.
  • Infrastructure: b.grubhub[.]com subdomain used to send fraudulent emails.
PRO TIP: Phishing often relies on your main email being public. By using aliases, you can instantly spot fake emails and identify exactly which service leaked your data. Use email aliases to track the source.

Relevant Terms

  • Phishing: A cyber attack that uses disguised email as a trick to reveal sensitive information.
  • DNS Takeover: An attack where an attacker gains control over a domain name system (DNS) server, allowing them to redirect traffic and send emails that appear legitimate.

Evasive Panda APT: DNS Poisoning Delivers MgBot

Executive Summary

The China-linked Evasive Panda APT group conducted a cyber espionage campaign targeting organizations in Türkiye, China, and India. The group poisoned DNS requests to deliver the MgBot backdoor, active between November 2022 and November 2024.

Key TTPs

  • Initial Access: Exploiting software update mechanisms via Adversary-in-the-Middle (AitM) attacks and DNS poisoning.
  • Execution: Multi-stage shellcode execution with a custom C++ loader built with the Windows Template Library (WTL).
  • Defense Evasion: Hybrid encryption (DPAPI and RC5) and code obfuscation to evade detection.

Campaign Analysis

Evasive Panda utilized DNS poisoning to redirect victims to attacker-controlled servers, distributing loaders disguised as legitimate application updates. The group has been active since 2012, continuously evolving its tactics to maintain persistence in compromised systems.

Targeting & Infrastructure

  • Target Profile: Victims in Turkey, China, and India across multiple industries.

Actionable Intelligence

  • IPs: 60.28.124[.]21, 123.139.57[.]103, 103.96.130[.]107
  • Targeted Domain: p2p.hd.sohu[.]com

Relevant Terms

  • DNS Poisoning: A type of attack where DNS records are manipulated to redirect traffic to malicious servers.
  • APT: An Advanced Persistent Threat, typically a state-sponsored group that uses various cyber attack techniques to gain unauthorized access to a computer network and remain undetected for a long time.

La Poste DDoS Attack Disrupts French Services

Executive Summary

The French postal service, La Poste, and its banking arm, La Banque Postale, were hit by a DDoS attack during the holiday season, disrupting online services and parcel deliveries. The pro-Russian group NoName057(16) claimed responsibility for the attack.

Key TTPs

  • Initial Access: DDoS attack flooded network with traffic.
  • Execution: Disrupted online services, parcel tracking, and banking access.
  • Defense Evasion: Overwhelmed network resources to prevent legitimate access.

Campaign Analysis

The attack significantly impacted La Poste's operations during its busiest time of the year, affecting both postal and banking services. The incident highlights the vulnerability of critical infrastructure to availability-focused cyberattacks.

Targeting & Infrastructure

  • Target Profile: French postal service and banking customers.
  • Infrastructure: La Poste's online infrastructure, including websites, apps, and banking services.

Relevant Terms

  • DDoS: A distributed denial-of-service attack floods a network with traffic, overwhelming its resources.
  • Botnet: A network of computers infected with malware and controlled by a single attacker.
Source: The Record