logo

Security briefing: December 2025

ID: 6d95237b-82ab-51eb-a870-154886b9b59b

STIX ID: report--6d95237b-82ab-51eb-a870-154886b9b59b

Feed Name: Sysdig Blog

Threat Score
88/100

Date Published: 2026-01-06

Date Updated: 2026-05-01

...
...

December 2025 security roundup: critical unauthenticated RCE in React Server Components (React2Shell CVE-2025-55182) with public PoC, widespread MongoDB memory-leak data exposure (MongoBleed CVE-2025-14847) actively exploited, BRICKSTORM backdoor linked to China-state actors targeting Linux cloud environments, EtherRAT multi-stage campaign leveraging Ethereum smart contracts for C2, an ESA source-code/data breach, and disruptive DDoS activity — the report provides IOCs, detection guidance, and urges patching, monitoring, and resilience measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.