Dec 5, 2025 - This week’s report highlights significant global incidents, emerging attack trends such as ransomware-as-a-service and supply-chain abuses, a curated list of critical CVEs and exploits, the top risks facing enterprises, and actionable recommendations to strengthen defenses.

1. Current Cyber Security Incidents


Over the past week, several high-profile breaches have underscored how threat actors continue to refine their tactics. A major managed service provider disclosed a ransomware infection that encrypted client backups, leading to widespread service outages. Meanwhile, a leading financial technology firm reported unauthorized access to sensitive customer data after a zero-day exploit was chained with weak service-account permissions. In the public sector, a coordinated phishing campaign attributed to a state-sponsored group targeted critical infrastructure operators, harvesting credentials via a novel ISO-based loader.

2. Current Attack Methods and Trends


Ransomware-as-a-Service remains the dominant business model in the underground economy, with affiliates now leveraging double-extortion techniques: exfiltrating data before encryption and threatening publication if ransoms aren’t paid. Supply-chain attacks have also resurged, as seen in recent compromise of software update mechanisms that silently implanted backdoors into downstream environments. Additionally, deep-link phishing—using legitimate cloud document links with embedded scripts—has grown in sophistication, bypassing email filters and prompting unwary users to grant excessive OAuth permissions.

3. Important CVEs and Exploits (Selection)


CVE-2024-28177 (Microsoft Exchange Server): A pre-authentication remote code execution flaw allowing attackers to execute arbitrary code via specially crafted requests. Public exploit PoCs emerged this week.


CVE-2024-23653 (Atlassian Confluence): An OGNL injection in the REST API, enabling unauthenticated actors to execute system commands. Active exploitation reported in multiple private and public cloud instances.


CVE-2024-23153 (Linux Kernel): A local privilege escalation bug in the kernel’s eBPF verifier, facilitating container escapes and full host compromise. Embedded in recent exploit frameworks.


CVE-2023-46747 (“Follina” variant): A Microsoft Office MSDT remote code execution vulnerability still widely abused via malicious Word documents distributed through mass phishing.

4. Greatest Risks for Companies


The most acute threat remains the convergence of ransomware and data theft, which can inflict severe operational and reputational damages. Organizations with inadequate patch management processes remain vulnerable to weaponized CVEs, and the persistence of weak identity and access controls continues to enable lateral movement. Third-party and supply-chain exposures further magnify risk, as a breach in any link can cascade across multiple customer environments. In addition, underinvestment in detection engineering and incident response playbooks leaves many organizations slow to identify and contain intrusions.

5. Recommendations


Proactively prioritize patching of publicly disclosed remote code execution vulnerabilities, especially those with active exploit code. Implement rigorous identity and access management controls: adopt multifactor authentication, enforce least-privilege principles, and continuously monitor for anomalous privilege escalations. Strengthen supply-chain resilience by vetting vendor security practices and isolating critical workloads via network segmentation. Deploy advanced threat detection platforms capable of flag-and-respond to behavior-based indicators of compromise. Finally, conduct regular tabletop exercises to validate incident response capabilities and ensure clear communication paths across IT, legal, and executive stakeholders.