TL;DR: The week of 18 to 25 December 2025 was dominated by active exploitation of Cisco and Fortinet flaws, alongside Cellik Android RAT’s Play Store trojanization, elevated ransomware claims, and continued targeting of email security gateways, according to FireCompass. The pattern shows why exposed perimeter controls and trusted app channels now create immediate identity and access risk, not just patching debt.
NHIMG editorial — based on content published by FireCompass: Weekly Report on New Hacking Techniques and Critical CVEs, 18 Dec to 25 Dec 2025
By the numbers:
- The week of December 18 to 25, 2025 saw 64 tracked ransomware claims on December 18 alone.
- Qilin accounted for 20.86% of the ransomware ecosystem activity tracked in the report.
- Akira represented 13.9% of the ransomware ecosystem activity tracked in the report.
Questions worth separating out
Q: What breaks when a perimeter appliance is exploited before patching is complete?
A: When an internet-facing gateway is exploited before patching finishes, the trust boundary itself becomes the failure point.
Q: Why do exposed gateways and SSO appliances create so much downstream risk?
A: They sit on privileged traffic paths and often see credentials, tokens, and authenticated sessions in transit.
Q: How can security teams tell whether mobile trojans are becoming an identity problem?
A: Watch for overlay-driven phishing, unusual permission grants, sideloading attempts, and business logins that coincide with abnormal device behaviour such as camera, microphone, or data spikes.
Practitioner guidance
- Prioritise internet-facing appliance exposure review Inventory all exposed email gateways, VPN concentrators, and firewall management surfaces, then validate whether patching, feature flags, or quarantine services create unauthenticated or low-friction entry points.
- Enforce mobile application control on BYOD Block sideloaded APKs through MDM, require device compliance for business access, and alert on overlay behaviour, anomalous permission requests, or unusual sensor use.
- Review SSO and federation trust assumptions Check whether forged or replayed authentication assertions could still be accepted on perimeter devices, then tighten certificate validation, logging, and config export protections.
What's in the full article
FireCompass's full weekly report covers the operational detail this post intentionally leaves for the source:
- Exact attack flow for Cisco AsyncOS RCE, including the quarantine path and backdoor behaviour
- Technical request and response patterns for the Fortinet SSO bypass that exposed admin sessions
- The darkweb claim mix by family, including the 64 tracked claims and ransomware distribution
- CISO takeaways on specific defensive actions for SEG exposure, mobile threat hunting, and perimeter validation
👉 Read FireCompass's weekly report on active exploitation and critical CVEs →
Active exploitation, Play Store trojans, and perimeter compromise?
Explore further
Active exploitation is now an identity governance problem, not just a vulnerability problem. The report shows attackers using exposed appliances to intercept or forge access, which means the control failure is often trust in the system boundary itself. When gateways and SSO layers are compromised, IAM assumptions about authenticated sessions become unreliable. Practitioners should manage externally reachable systems as part of identity risk, not as separate infrastructure hygiene.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, according to The State of Non-Human Identity Security.
A question worth separating out:
Q: Should organisations prioritise perimeter hardening or mobile controls first?
A: Do both, but prioritise whichever path currently exposes the most privileged access. If external gateways and SSO appliances are internet-facing, hardening them first reduces immediate blast radius. If BYOD is a major access channel, mobile application control and posture enforcement become equally urgent because they protect the credentials users bring into the environment.
👉 Read our full editorial: Weekly report on active exploitation and mobile trojans