• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Screen Connect
Support
Customer Portal
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Altec
        • Avalara
        • AvidXchange
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • Fortis
        • FreightPOP
        • Lumber
        • Microsoft 365
        • Netstock
        • Ottimate
        • Quadient
        • Sage Fixed Assets
        • Sage HRMS
        • Sage Intacct Payroll powered by ADP
        • Savant WMS
        • Scanco
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Bizinsight
        • Concur
        • Crystal Reports
        • Fraxion
        • Fusion RMS
        • FYISoft
        • JobOps
        • KnowledgeSync
        • Lockstep Collect
        • Nectari
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage Intelligence
        • Sage Supply Chain Intelligence
        • Scissortail HCM
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Time & Billing Pro
        • Timekeeper
        • True Sky
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed IT Services
        • Managed Cloud Services
        • Network Assurance Core
        • Email Hosting
        • IT Support
        • Microsoft 365 Services
        • Server Monitoring
        • Virtualization
      • Cybersecurity
          • CyberAssurance CORE™
          • Cybersecurity Solutions
          • Backup & Continuity
          • Dark Web Monitoring
          • EDR
          • Encryption
          • MFA
          • Penetration Testing
          • Security Training
          • Spam & Virus Filtering
          • vCIO
          • Vulnerability Assessment
      • Cloud Services
        • Cloud Hosting
        • Infrastructure-as-a-Service
        • Acumatica IaaS
      • Industries
        • Financial Services
        • Healthcare
        • Construction
      • Locations
          • Nationwide
          • Austin
          • California
          • Chicago
          • Minneapolis
          • New Jersey
          • New York
          • North Carolina
          • Philadelphia
          • Phoenix
          • San Diego
          • Seattle
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

SWK Cybersecurity News Recap December 2025

December 16, 2025 by Hector

Home » Cybersecurity » SWK Cybersecurity News Recap December 2025

Wooden letters spelling "December" arranged above a 2025 calendar with decorative leaf design for SWK Technologies cybersecurity news recap

As the year closes, cybersecurity news continues to make major headlines in December 2025. This month’s recap by SWK Technologies features stories such as several state-sponsored hacking and malware campaigns, multiple breaches across different industries and more:

CISA and NSA Warn of China-backed Malware Campaign

CISA, the NSA and Canadian cybersecurity officials issued a joint warning on December 4 about BRICKSTORM malware used by Chinese state-sponsored actors. The backdoor program can steal virtual machine snapshots for credential theft and create hidden rogue VMs, and targets VMware vSphere and Windows systems specifically, affecting primarily government organizations and IT businesses. BRICKSTORM uses multiple encryption layers and DNS-over-HTTPS to hide communications while maintaining long-term access to compromised networks. In one case, threat actors obtained and maintained access from April 2024 through September 2025. CISA released detection rules and urged organizations to scan their networks, block unauthorized DNS-over-HTTPS traffic and segment networks to restrict DMZ access.

API Breach at 700Credit Exposes Over 5 Million People

700Credit, a Michigan-based credit verification provider serving over 18,000 auto dealerships, disclosed a breach affecting at least 5.6 million people. Threat actors exploited a flawed API connection to a partner’s software integration in July and then gained access to 700Credit’s electronically stored client data between May and October 2025. The API returned information for any valid consumer ID without verifying account ownership. Exposed information includes names, addresses, dates of birth and Social Security numbers. 700Credit discovered the breach on October 25 and has notified the FBI and FTC. The company is offering affected individuals one year of credit monitoring through TransUnion and has filed consolidated breach notifications on behalf of affected dealers.

Decryption Bug Found in Ransomware Strain Favored by Pro-Russia Hacktivists

Pro-Russia hacktivist group CyberVolk launched VolkLocker ransomware-as-a-service in August 2025, but researchers discovered a critical flaw allowing victims to decrypt files without paying. The Golang-based ransomware hard-codes master encryption keys into executables and writes them to a plaintext file in the system’s temp folder. SentinelOne researchers stated they believe this represents a test artifact that was not removed before deployment, suggesting quality control issues as the group recruits affiliates. VolkLocker operates entirely through Telegram and costs between $800 and $2200 depending on operating system support. CyberVolk also now sells standalone remote access trojans and keyloggers for $500 each.

React2Shell Vulnerability Exploited Within Hours of Discovery

CVE-2025-55182, dubbed React2Shell, is a maximum-severity vulnerability in React Server Components that allows unauthenticated remote code execution. Disclosed December 3, the flaw affects React 19.x and Next.js 15.x/16.x when using App Router. Applications using default configurations are vulnerable even without explicit server functions. Within hours of disclosure, China-linked groups including Earth Lamia and Jackpot Panda began exploitation attempts. Threat actors deployed cryptocurrency miners, backdoors and credential harvesters targeting cloud environment variables and metadata. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on December 5. Researchers also reported uncovering North Korean actors exploiting the flaw, while other data shows 39% of cloud environments contain vulnerable instances.

Healthcare Software Provider Confirms Breach

TriZetto Provider Solutions, a vendor of revenue management systems designed for healthcare, notified clients in December about unauthorized access to a web portal used by physicians, hospitals and health systems. The company discovered suspicious activity on October 2, 2025, but forensic analysis revealed the breach began in November 2024. Threat actors accessed historical eligibility transaction reports containing patient data including names, addresses, dates of birth, Social Security numbers and health insurance information. TriZetto engaged cybersecurity professionals for investigation and confirmed the attackers’ access was removed. The company is offering to handle breach notifications and cover credit monitoring costs for affected individuals, but the total number of victims impacted remains unclear.

Contact SWK Technologies to Learn More

Cyber threats and security regulations will continue to evolve in 2026, from state-sponsored cyber attacks to new vulnerabilities that will emerge for hackers to exploit. The experienced cybersecurity team at SWK Technologies will help you keep track of the biggest risks to your business and develop a strategy to protect your data from external and internal threats, as well as adapt to changing security regulations.

Contact SWK here to learn how our cybersecurity solutions will help strengthen your cyber defense and prepare your business for the challenges ahead in 2026.

Contact Us

Category: Cybersecurity, Blog, News and Events

Sidebar

Recent Posts

  • SWK Cybersecurity News Recap December 2025
  • 2025 Year-End Closing in Acumatica
  • Sage Intacct Construction AI: The Future of Job Costing, WIP, and Financial Control
  • Microsoft 365 Price Increases Will Take Effect July 2026
  • Sage 100 Year-End Resources for 2025
  • Sage Intacct Multi-Entity Accounting: A Modern Solution for Complex Financial Operations
  • End of Year Cybersecurity Tips for 2025

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Wooden letters spelling "December" arranged above a 2025 calendar with decorative leaf design for SWK Technologies cybersecurity news recap

SWK Cybersecurity News Recap December 2025

Read moreSWK Cybersecurity News Recap December 2025
3D metallic numbers displaying 2026 with the number 5 below, representing Acumatica's 2025 year-end closing transition to 2026

2025 Year-End Closing in Acumatica

Read more2025 Year-End Closing in Acumatica
sage intacct construction AI

Sage Intacct Construction AI: The Future of Job Costing, WIP, and Financial Control

Read moreSage Intacct Construction AI: The Future of Job Costing, WIP, and Financial Control

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2025 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.