Skip to article
Security Alert
Emergent Story mode

Now reading

Overview

1 / 5 3 min 5 sources
Sources

Story mode

Security Alert

Cyber Threats Abound: Multiple Vulnerabilities and Attacks Hit Across the Globe

A series of alarming cyber threats has been reported in recent weeks, affecting various industries and regions, including a zero-day exploit in WatchGuard Firebox devices, Android SMS-stealer malware targeting Uzbek users, and separate threat campaigns hitting Cisco VPNs and email services.

Read
3 min
Sources
5 sources

A surge in cyber threats has been reported across the globe, with multiple vulnerabilities and attacks targeting various industries and regions. From a zero-day exploit in WatchGuard Firebox devices to Android...

Story state
Structured developing story
Evidence
Evidence mapped
Coverage
0 reporting sections
Next focus
What comes next

Continue in the field

Focused storyNearby context

Open the live map from this story.

Carry this article into the map as a focused origin point, then widen into nearby reporting.

Leave the article stream and continue in live map mode with this story pinned as your origin point.

  • Open the map already centered on this story.
  • See what nearby reporting is clustering around the same geography.
  • Jump back to the article whenever you want the original thread.
Open live map mode

Source bench

Coverage at a glance

5 cited references · links still resolving.

References
5

5 cited references attached to this briefing. Direct source links are still resolving.

  1. Reference 1 · Fulqrum Sources

    Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices

  2. Reference 2 · Fulqrum Sources

    Uzbek Users Under Attack by Android SMS-Stealers

  3. Reference 3 · Fulqrum Sources

    Cisco VPNs, Email Services Hit in Separate Threat Campaigns

  4. Reference 4 · Fulqrum Sources

    LongNosedGoblin Caught Snooping on Asian Governments

Open source workbench

Keep reporting

ContradictionsEvent arcNarrative drift

Open the deeper evidence boards.

Take the mobile reel into contradictions, event arcs, narrative drift, and the full source workspace.

  • Scan the cited sources and coverage bench first.
  • Open contradiction and narrative drift checks after the first read.
  • Move from the summary into the full evidence boards.
Open evidence boards

Stay in the reporting trail

Open the evidence boards, source bench, and related analysis.

Jump from the app-style read into the deeper workbench without losing your place in the story.

Open source workbenchBack to Security Alert
🔒 Security Alert

Cyber Threats Abound: Multiple Vulnerabilities and Attacks Hit Across the Globe

A series of alarming cyber threats has been reported in recent weeks, affecting various industries and regions, including a zero-day exploit in WatchGuard Firebox devices, Android SMS-stealer malware targeting Uzbek users, and separate threat campaigns hitting Cisco VPNs and email services.

Monday, December 22, 2025 • 3 min read • 5 source references

  • 3 min read
  • 5 source references

A surge in cyber threats has been reported across the globe, with multiple vulnerabilities and attacks targeting various industries and regions. From a zero-day exploit in WatchGuard Firebox devices to Android SMS-stealer malware targeting Uzbek users, and separate threat campaigns hitting Cisco VPNs and email services, the cyber landscape is becoming increasingly complex and treacherous.

One of the most critical vulnerabilities reported is a zero-day exploit in WatchGuard Firebox devices, which has been added to the list of edge device vendors targeted in recent weeks. This exploit has significant implications, as WatchGuard Firebox devices are widely used to secure networks and protect against cyber threats. According to reports, threat actors have been actively exploiting this vulnerability, highlighting the need for immediate patching and mitigation measures.

In a separate incident, Telegram users in Uzbekistan have been targeted with Android SMS-stealer malware. This malware is particularly concerning, as it allows attackers to intercept and steal sensitive information, including login credentials and personal data. What's worse, the attackers are continually improving their methods, making it increasingly difficult for users to detect and prevent these attacks.

Cisco has also been hit with two separate threat campaigns, one targeting its VPNs and the other its email services. The VPN attack was sophisticated, with the attackers using a five-alarm campaign to gain access to sensitive information. In contrast, the email attack was more of a "spray-and-pray" approach, with the attackers sending out large volumes of phishing emails in an attempt to trick users into divulging sensitive information.

Meanwhile, a new China-aligned APT group, known as LongNosedGoblin, has been caught snooping on government networks across Southeast Asia and Japan. This group is using Group Policy to sniff through networks, allowing them to gain access to sensitive information and potentially disrupt critical infrastructure.

In addition to these cyber threats, there have been reports of identity fraud among home-care workers, which is putting patients at risk. With the rise of the gig economy and the increasing demand for home-care services, the need for stringent identity authentication has become more pressing. Reports of patients being cared for by unqualified home-care aides with fake identities have emerged, highlighting the need for more robust identity verification processes.

These incidents serve as a stark reminder of the evolving cyber threat landscape and the need for organizations and individuals to remain vigilant and proactive in protecting themselves against these threats. As the cyber landscape continues to shift and new threats emerge, it is essential to stay informed and adapt to the changing landscape.

In conclusion, the recent surge in cyber threats highlights the need for increased awareness, education, and action to prevent and mitigate these attacks. By staying informed and taking proactive measures, individuals and organizations can reduce their risk of falling victim to these threats and protect themselves against the ever-evolving cyber landscape.

Sources:

  • Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
  • Uzbek Users Under Attack by Android SMS-Stealers
  • Cisco VPNs, Email Services Hit in Separate Threat Campaigns
  • LongNosedGoblin Caught Snooping on Asian Governments
  • Identity Fraud Among Home-Care Workers Puts Patients at Risk

A surge in cyber threats has been reported across the globe, with multiple vulnerabilities and attacks targeting various industries and regions. From a zero-day exploit in WatchGuard Firebox devices to Android SMS-stealer malware targeting Uzbek users, and separate threat campaigns hitting Cisco VPNs and email services, the cyber landscape is becoming increasingly complex and treacherous.

One of the most critical vulnerabilities reported is a zero-day exploit in WatchGuard Firebox devices, which has been added to the list of edge device vendors targeted in recent weeks. This exploit has significant implications, as WatchGuard Firebox devices are widely used to secure networks and protect against cyber threats. According to reports, threat actors have been actively exploiting this vulnerability, highlighting the need for immediate patching and mitigation measures.

In a separate incident, Telegram users in Uzbekistan have been targeted with Android SMS-stealer malware. This malware is particularly concerning, as it allows attackers to intercept and steal sensitive information, including login credentials and personal data. What's worse, the attackers are continually improving their methods, making it increasingly difficult for users to detect and prevent these attacks.

Cisco has also been hit with two separate threat campaigns, one targeting its VPNs and the other its email services. The VPN attack was sophisticated, with the attackers using a five-alarm campaign to gain access to sensitive information. In contrast, the email attack was more of a "spray-and-pray" approach, with the attackers sending out large volumes of phishing emails in an attempt to trick users into divulging sensitive information.

Meanwhile, a new China-aligned APT group, known as LongNosedGoblin, has been caught snooping on government networks across Southeast Asia and Japan. This group is using Group Policy to sniff through networks, allowing them to gain access to sensitive information and potentially disrupt critical infrastructure.

In addition to these cyber threats, there have been reports of identity fraud among home-care workers, which is putting patients at risk. With the rise of the gig economy and the increasing demand for home-care services, the need for stringent identity authentication has become more pressing. Reports of patients being cared for by unqualified home-care aides with fake identities have emerged, highlighting the need for more robust identity verification processes.

These incidents serve as a stark reminder of the evolving cyber threat landscape and the need for organizations and individuals to remain vigilant and proactive in protecting themselves against these threats. As the cyber landscape continues to shift and new threats emerge, it is essential to stay informed and adapt to the changing landscape.

In conclusion, the recent surge in cyber threats highlights the need for increased awareness, education, and action to prevent and mitigate these attacks. By staying informed and taking proactive measures, individuals and organizations can reduce their risk of falling victim to these threats and protect themselves against the ever-evolving cyber landscape.

Sources:

  • Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
  • Uzbek Users Under Attack by Android SMS-Stealers
  • Cisco VPNs, Email Services Hit in Separate Threat Campaigns
  • LongNosedGoblin Caught Snooping on Asian Governments
  • Identity Fraud Among Home-Care Workers Puts Patients at Risk

Coverage tools

Sources, context, and related analysis

Visual reasoning

How this briefing, its evidence bench, and the next verification path fit together

A server-rendered QWIKR board that keeps the article legible while showing the logic of the current read, the attached source bench, and the next high-value reporting move.

Cited sources

0

Reasoning nodes

3

Routed paths

2

Next checks

1

Reasoning map

From briefing to evidence to next verification move

SSR · qwikr-flow

Story geography

Where this reporting sits on the map

Use the map-native view to understand what is happening near this story and what adjacent reporting is clustering around the same geography.

Geo context
0.00° N · 0.00° E Mapped story

This story is geotagged, but the nearby reporting bench is still warming up.

Continue in live map mode

Coverage at a Glance

5 sources

Compare coverage, inspect perspective spread, and open primary references side by side.

Cited References

5

Direct Links

0

Source Status

Link resolution pending

Coverage Mode

Citation-only bench
5 cited references attached to this briefing Direct links still resolving

Citation-only Source Bench

This story has source references, but the direct links are still resolving. The titles below reflect the cleaned citation bench for this briefing.

5 unresolved references
  1. Reference 1 · Fulqrum Sources

    Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices

  2. Reference 2 · Fulqrum Sources

    Uzbek Users Under Attack by Android SMS-Stealers

  3. Reference 3 · Fulqrum Sources

    Cisco VPNs, Email Services Hit in Separate Threat Campaigns

  4. Reference 4 · Fulqrum Sources

    LongNosedGoblin Caught Snooping on Asian Governments

  5. Reference 5 · Fulqrum Sources

    Identity Fraud Among Home-Care Workers Puts Patients at Risk

Fact-checked Real-time synthesis Bias-reduced

This article was synthesized by Fulqrum AI from 5 trusted sources, combining multiple perspectives into a comprehensive summary. All source references are listed below.