
Threatwire Report Highlights Cybersecurity Incidents and Vulnerabilities
The Threatwire report of December 22, 2025, highlights several cybersecurity incidents and vulnerabilities. Anna’s Archive, a clandestine digital library, announced it has backed up nearly all of Spotify: 99.9% of metadata (256 million titles) and 86 million music files (300 TB), covering 99.6% of listens. The archive reveals that 70% of titles have fewer than 1,000 listens, a phenomenon attributed to the proliferation of AI-generated music. Spotify is treating this as a security incident.
Three researchers (Evob, Daniel, MDL) discovered four critical vulnerabilities in Mintlify, an AI documentation platform, including CVE-2025-67842 (XSS allowing remote code execution via malicious SVGs). The vulnerabilities, now patched, affected companies like Cursor, despite attempts to downplay the issue.
The Rust for Linux project recorded its first CVE (CVE unspecified), related to a race condition in the Android binder, causing memory corruption. Additionally, 159 other CVEs for the Linux kernel in C were published on the same day.
Finally, SoundCloud experienced outages related to a database theft, and Shiny Hunters exploited a leak at MixPanel to target premium users of an adult site. Google has discontinued its dark web reporting tool, hinting at a future replacement. https://www.youtube.com/watch?v=JFyVU0LONLA