Threat Advisories:
Hive Pro recognized in Gartner® Magic Quadrant™ for Exposure Assessment Platform, 2025 Watch platform in action
December 30, 2025

Weekly Threat Digest : 22nd DECEMBER to 28th DECEMBER 2025

HiveForce Labs

HiveForce Labs

For a detailed threat digest, download the PDF file here



HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the increasing complexity and frequency of global cyber incidents. Over the past week, three major attacks were detected, two critical vulnerabilities were publicly disclosed, and one active threat actor group was monitored, signaling a concerning escalation in malicious activity.

CVE-2025-68613 is a critical remote code execution vulnerability in the n8n workflow automation platform. It stems from weak sandbox isolation in the expression evaluation engine. This flaw enables full system compromise, unauthorized data access, and manipulation of automated workflows.

Prince of Persia, also referred to as Infy, is an Iranian state-linked advanced persistent threat that has been active since 2007. The group is known for long-term cyber-espionage operations targeting strategic entities in support of national intelligence objectives.

CVE-2025-14847 is a high-severity vulnerability dubbed MongoBleed in the MongoDB Server that requires no authentication. It allows remote attackers to read sensitive heap memory by exploiting an error in Zlib packet decompression, potentially exposing confidential data and internal memory contents. These underscore the need for disciplined security updates and sustained monitoring in response to rapidly evolving attack methodologies.



Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo