University of Phoenix Breach – Weekly News Roundup

Here is the most recent Cybersecurity news for the past week:

🎓 University of Phoenix Breach Affects 3.5 Million
The University of Phoenix has confirmed a massive data breach impacting nearly 3.5 million individuals, stemming from the Cl0p ransomware group’s exploitation of zero-day vulnerabilities in the Oracle E-Business Suite (EBS). The compromised data includes names, Social Security numbers, and financial details, with the university offering credit monitoring to those affected as the investigation continues.

 

https://www.securityweek.com/3-5-million-affected-by-university-of-phoenix-data-breach

🔥 Critical WatchGuard and Cisco Flaws Under Attack
Federal agencies have issued urgent warnings regarding actively exploited vulnerabilities in network security products, specifically WatchGuard Firebox (CVE-2025-14733) and Cisco AsyncOS (CVE-2025-20393). These critical flaws allow unauthenticated remote code execution, prompting CISA to add them to its Known Exploited Vulnerabilities (KEV) catalog and mandating immediate patching for federal networks.

 

🍏 Apple Patches WebKit Zero-Day Exploited in Spyware Campaigns
Apple has released emergency security updates for iOS and macOS to address a critical WebKit zero-day vulnerability (CVE-2025-14174) that was being actively exploited in the wild. The flaw allowed attackers to execute arbitrary code via malicious web content and was reportedly used in targeted spyware attacks against high-risk individuals.

 

🔓 Massive Data Leak Exposes 200 Million User Records
A significant data breach involving third-party analytics provider Mixpanel has exposed over 200 million records from the adult content platform Pornhub. The leaked database contained email addresses, geographic locations, and search histories, highlighting the growing supply chain risks associated with third-party data processors.

 

https://research.checkpoint.com/2025/22nd-december-threat-intelligence-report

🕵️ Urban VPN Extension Caught Harvesting AI Chat Logs
Security researchers have discovered that the popular “Urban VPN Proxy” browser extension, with millions of installs, was secretly harvesting user prompts entered into AI chatbots like ChatGPT and Claude. This privacy violation has raised serious concerns about browser extension permissions and the confidentiality of sensitive interactions with AI tools.

 

https://thehackernews.com/2025/12/weekly-recap-firewall-exploits-ai-data.html

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.