logo

Security briefing: December 2025

ID: efd80b9a-b17e-55c2-8015-b26327ceb9b0

STIX ID: report--efd80b9a-b17e-55c2-8015-b26327ceb9b0

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2026-01-06

Date Updated: 2026-05-01

...
...

December 2025 security roundup: multiple high-risk incidents surfaced including React2Shell (CVE-2025-55182) — an unauthenticated RCE with public PoC — active exploitation of MongoBleed (CVE-2025-14847) affecting many MongoDB instances, the BRICKSTORM backdoor used by state-linked actors to target Linux cloud environments and steal credentials, and the discovery of EtherRAT, a sophisticated blockchain-based C2 implant tied to React2Shell exploits; the month also saw an ESA source-code breach and significant DDoS disruption in France. The report urges prompt patching, deployment of IOCs/detections, stronger authentication and segmentation, and increased monitoring for anomalous activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.