Latest Cyber News

New cyber threats are being released every day. We include some of these here brought to you by one of our key vendors – Cybaverse.

February 19, 2026
Security

Check Point shows Grok & Microsoft Copilot can be abused as stealth C2 proxies: malware makes the AI fetch attacker URLs and returns commands via AI output, blending into trusted AI web traffic (often without auth).

Targets

  1. Enterprises that allow/rarely inspect AI service domains (e.g., grok.com, copilot.microsoft.com) as “normal” outbound traffic
  2. Windows endpoints where embedded browser components (e.g., WebView2) can be used to automate hidden AI web sessions

Recommended Actions / Mitigations

  1. Treat AI assistant domains as high-value egress: monitor, log, and alert on unusual/automated access patterns and high-frequency fetch/summarise behaviour
  2. Restrict or broker AI web access (CASB/SWG policies), and add inspection controls where feasible (URL categories, allowlists, user/device-based controls)
  3. Detect abuse patterns: URL requests with suspicious/encoded query strings, repeated “summarise this URL” prompts, headless/hidden webview activity
  4. For AI providers/tenant admins: enforce authentication and add enterprise visibility/controls around URL-fetch/browsing features

References

  1. https://cybersecuritynews.com/grok-and-copilot-for-malware-communication/https://cybersecuritynews.com/grok-and-copilot-for-malware-communication/
  2. https://research.checkpoint.com/2026/ai-in-the-middle-turning-web-based-ai-services-into-c2-proxies-the-future-of-ai-driven-attacks/https://www.bleepingcomputer.com/news/security/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/

Major NPM Supply Chain Attack Exposes Billions of Weekly Downloads

9th September 2025

A major supply chain attack has hit the open-source ecosystem after attackers gained access to an npm maintainer’s account through a phishing campaign. Malicious versions of several widely used npm packages, which together see more than 2.6 billion downloads each week, were published with hidden code designed to steal cryptocurrency transactions from users’ browsers.

The phishing emails looked like genuine security notices from npm, pressuring developers to update their two factor authentication details or risk losing access to their accounts. Once the attackers were inside, they pushed out altered versions of popular packages such as chalk, debug, ansi styles and supports color. The injected malware was designed to intercept web3 activity, silently replacing wallet addresses and redirecting payments to attacker controlled accounts.

Researchers found that the malicious code hooked into standard browser functions and wallet APIs to monitor and manipulate cryptocurrency activity. Although the attack was short lived and mainly affected fresh installs during the compromise period, the sheer scale of the packages involved makes it one of the most notable npm incidents to date.

This comes on the back of several similar compromises in recent months and reinforces the message that open source software is a growing target for attackers. Organisations should treat third party code with the same caution as any other part of their supply chain by enabling multifactor authentication, monitoring dependencies and strengthening security in development environments.

AI-driven attack tool accelerates exploitation of newly disclosed flaws

4th September 2025

A new AI-powered hacking framework is being used by cybercriminals to exploit recently disclosed vulnerabilities at unprecedented speed.

The tool, known as HexStrike-AI, has become a hot topic on underground forums after it was linked to the rapid weaponisation of Citrix vulnerabilities, including CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424. Thousands of systems remain exposed, leaving many organisations at heightened risk.

From security tool to attack weapon

HexStrike-AI was originally developed as a legitimate red teaming platform. It uses AI agents to coordinate and automate penetration testing tasks across more than 150 security tools. Designed with resilience in mind, the framework can retry or adjust operations when it encounters an error, creating an almost unstoppable testing cycle.

While the project was shared openly on GitHub, where it quickly gained popularity among researchers, it has also caught the eye of attackers. On dark web forums, hackers have been discussing how to deploy HexStrike-AI to exploit Citrix NetScaler ADC and Gateway flaws within hours of their disclosure.

Reports suggest attackers may already be using it to gain unauthorised access, execute code remotely, and install webshells on compromised appliances. Some compromised devices are even being advertised for sale.

Shrinking patching windows

Traditionally, exploiting newly disclosed vulnerabilities could take days. With tools like HexStrike-AI, that window may shrink to mere minutes. This acceleration leaves IT teams under even greater pressure to patch quickly before attackers strike.

The concern isn’t just about one tool or one set of vulnerabilities, it’s about the wider trend. AI-driven attack frameworks mark a shift in how fast and effectively adversaries can scale their operations.

What organisations should do

While patching known vulnerabilities as soon as possible remains critical, the rise of AI-assisted exploitation highlights the need for a layered defence strategy. Threat intelligence, adaptive detection, and AI-driven defences are becoming increasingly important to stay ahead of automated attacks.

For UK organisations, this is a reminder that reacting quickly to advisories is no longer enough. Staying informed, building resilience, and adopting proactive security measures are essential to reduce the impact of these evolving threats.

Major Cyber Incident Disrupts Jaguar Land Rover Production

3rd September 2025

Jaguar Land Rover (JLR) has confirmed it was recently hit by a cyberattack that forced the shutdown of several key systems. The disruption has had a serious impact on both production lines and retail operations.

In a short update, the company explained that it had taken the decision to shut down its own systems in order to contain the incident. At this stage, JLR has stated there is no evidence that customer data has been compromised.

The automaker added it is working urgently to restore global applications in a “controlled manner” but gave no firm timeline on when operations will return to normal.

Operations brought to a halt

Reports of disruption first surfaced from UK dealerships, where staff were unable to register new vehicles or provide certain parts at service points. The Solihull production plant, which manufactures flagship models such as the Land Rover Discovery, Range Rover, and Range Rover Sport, was also affected.

With an annual turnover of around £29 billion and more than 39,000 employees worldwide, the scale of this incident highlights the risks faced by large, complex organisations reliant on interconnected digital systems.

Timing and tactics

The attack reportedly took place over the weekend, a window often exploited by cybercriminals, knowing that security teams may be operating at reduced capacity and response times can be slower. So far, no group has claimed responsibility for the attack, and details of the method or malware used have not been disclosed.

Wider lessons

Incidents like this underline the importance of operational resilience, especially in industries where downtime has an immediate impact on production and service delivery. For manufacturers, the ripple effects extend beyond the factory floor, affecting supply chains, dealerships, and ultimately customers.

For organisations of all sizes, the key reminder is that cyberattacks are rarely just about stolen data, they can grind entire businesses to a halt.

How to Detect Malicious AI Agents Before They Do Real Damage

29th July 2025

As artificial intelligence continues to develop, so do the cyber threats that come with it. We are entering a phase where AI-driven agents are not just assisting businesses; they are also being used by attackers to carry out sophisticated, automated attacks. Traditional defences alone are no longer enough.

To stay ahead of these threats, organisations need to combine intelligent technology with human expertise, especially by fostering better collaboration between security, fraud, and DevOps teams.

The Growing Threat: AI Agents That Mimic Legitimate Users

Many businesses already recognise that AI can be misused. What is new is the rise of agentic AI, which refers to autonomous AI tools capable of making decisions and taking action on their own. These agents can carry out entire attack chains, from gathering credentials to executing transactions and probing for vulnerabilities.

Because these AI agents often look and behave like legitimate users, detecting them requires a shift in thinking. We must go beyond what the agent is doing and begin to understand why it is doing it.

Six Practical Ways to Identify Malicious AI Agents

1. Analyse Behaviour and Understand Intent

The most reliable way to detect malicious agents is to study their behaviour. Are they following normal user flows, or skipping steps and heading straight for valuable areas like login pages or checkouts?

Common warning signs include unusual session flows, bursts of rapid API calls, or behaviours that do not match the account’s usual patterns. Understanding intent helps distinguish between trustworthy and suspicious actions.

2. Connect Behaviour to Digital Identity

Even if an AI agent is new, its behaviour can still link it to known risk profiles. By analysing patterns in how it moves through a website, how quickly it completes tasks, and whether its actions match past behaviour, organisations can build a picture of trustworthiness.

Behavioural clues, such as skipping directly to sensitive areas or using inconsistent purchase habits, help security teams flag potential threats early.

3. Check for Signal Integrity

Malicious agents often manipulate device or browser-level data to avoid detection. Inconsistencies between reported and actual device details, suspicious browser headers, or odd operating system information can all signal an attempt to hide malicious intent.

When signals do not line up, it is a clear sign that the agent needs further scrutiny.

4. Identify and Attribute Traffic Patterns

Just as malware can be fingerprinted, so can the traffic generated by agentic AI. Malicious agents tend to use techniques such as rotating proxies, connecting from high-risk networks, and presenting inconsistent or missing session data.

By identifying these patterns early, organisations can stop attacks before they happen.

5. Apply Real-Time Risk Scoring with Adaptive Defences

Modern security tools do not rely on a simple allow or block model. Instead, they score agent behaviour in real time, using context and risk signals to guide their response.

Low-risk agents might be allowed to proceed without any obstacles. Medium-risk agents could be challenged with additional verification steps. High-risk agents may be blocked or referred to a security analyst.

This flexible approach helps reduce friction for genuine users while staying alert to evolving threats.

6. Combine AI and Human Expertise Through Continuous Learning

The best defences today are built using a mix of automation and human insight. AI can simulate threats, stress-test systems, and flag suspicious activity. Human analysts then review the findings, investigate edge cases, and refine detection systems.

This ongoing feedback loop helps improve accuracy, reduce false positives, and ensure defences keep up with changing threats. However, this approach only works if teams across fraud, security, and DevOps have access to shared, real-time insights.

The Future: Balancing Opportunity with Risk

AI agents will soon be making legitimate decisions on behalf of users, whether through purchases or account actions. That means organisations must put controls in place to ensure agent activity is properly authorised and monitored.

These agents will not just be a threat. They will also represent a new way for businesses to engage with customers. That makes it even more important to understand the intent behind their actions, fast and accurately.

To succeed in this new environment, businesses must align their technology and people. It is no longer just about defending against threats. It is about understanding how AI is changing the landscape and preparing accordingly.

The battle between malicious and legitimate AI agents has already begun. Winning that battle means combining the strengths of both human and machine intelligence.

Stealthy Malware Campaign Uses Trusted Websites to Spread Remote Access Trojan

15th July 2025

A newly discovered cyber threat campaign is quietly spreading a sophisticated remote access trojan (RAT) through trusted websites, in an effort to gain control of victims’ devices. The malware in question is a new variant linked to the Interlock ransomware group, which has been known for its aggressive double-extortion tactics, encrypting data and threatening to leak it unless a ransom is paid.

This latest campaign, uncovered by security researchers, shows that Interlock is stepping up its game. The group is now deploying an updated version of its RAT via web-inject techniques, relying on compromised, legitimate websites to lure users into unknowingly launching malicious code.

More Advanced, More Stealthy

Unlike previous iterations that used JavaScript, this version of the RAT has moved to a PHP-based backdoor making it even harder to detect. PHP is a widely used scripting language, particularly for websites, which helps the malware blend in more easily and remain hidden from traditional security tools.

Once the malware is activated, it carries out detailed reconnaissance on the victim’s device. It gathers system information, lists running processes and services, checks available drives, scans the local network, and even determines the user’s privilege level (whether they’re running as USER, ADMIN, or SYSTEM). This allows attackers to understand exactly what they’ve compromised and plan their next move accordingly.

The Web-Inject Trick

The campaign, part of a broader web-inject threat cluster, involves injecting a tiny malicious script into the HTML of legitimate websites. When someone visits the site, they’re prompted to complete what looks like a routine CAPTCHA verification. Behind the scenes, this trick leads to a malicious PowerShell command being pasted and executed triggering the download and installation of the Interlock RAT.

This tactic is especially dangerous because it doesn’t rely on fake or suspicious-looking websites. Instead, it hijacks genuine ones, making it far more likely that users will fall for the lure without raising any red flags.

How Attackers Stay Hidden

After infection, the malware connects to a command-and-control (C2) server using a legitimate cloud tunnelling service, giving attackers a direct line into the victim’s system. From there, they can move laterally across the network using Remote Desktop Protocol (RDP), maintain persistence, and potentially deliver further payloads depending on the value of the target.

This particular campaign has been active since May, with the PHP variant appearing more recently. While there’s no evidence that specific industries are being singled out, researchers say the campaign is largely opportunistic, casting a wide net and picking off targets that look promising.

Advice for Defenders

To help defend against this evolving threat, organisations should:

  • Raise user awareness around phishing and social engineering tactics especially those that mimic “Click to verify” prompts.

  • Disable or restrict the Win + R shortcut (used to open the Run command) where possible.

  • Limit Remote Desktop access to authorised users and monitor for unusual activity.

  • Enforce least privilege access and multi-factor authentication (MFA) across systems.

  • Regularly update endpoint security and monitor for unusual script execution patterns.

Indicators of compromise (IOCs) from this campaign have been published by researchers and can be integrated into your threat detection systems to bolster defences.

To Sum Up

This campaign is yet another reminder of how cybercriminals are evolving their methods, blending into legitimate web infrastructure and relying heavily on social engineering. Staying ahead requires a mix of user awareness, technical controls, and proactive monitoring.

If you’d like help reviewing your security posture or want to understand how threats like this could affect your business, speak to one of our experts today.

Why Call-Back Phishing Is the Latest Threat to Watch – And What Your Business Can Do About It

4th July 2025

Cybercriminals are increasingly turning to a new phishing method that ditches suspicious-looking links and fake websites in favour of something more subtle, getting victims to pick up the phone and call them.

By impersonating well-known brands like Microsoft, PayPal, DocuSign, and others, attackers are launching so-called callback phishing attacks, or “TOAD” (telephone-oriented attack delivery) campaigns. The goal? To convince victims that they’re contacting a legitimate customer support line, when in fact, they’re dialling straight into a scam.

How Callback Phishing Works

Unlike traditional phishing emails that rely on malicious links or attachments, these scams trick people into calling a phone number that appears to be for a trusted organisation. The attacker, posing as a representative of that company, then uses social engineering techniques to manipulate the caller into handing over sensitive information or even providing remote access to their device.

Rather than chasing the victim, this tactic cleverly reverses the dynamic: the user initiates the contact, which often lowers their guard. After all, many of us are conditioned to treat phone communication as more secure than clicking a suspicious link.

These phishing emails often look like legitimate invoices, purchase confirmations or account notices. A recent surge in such attacks has seen a rise in fake PDFs urging recipients to call a support number if they don’t recognise a charge. In one example, users received messages about a supposed PayPal or antivirus software charge, with a number provided for disputes which, of course, routes straight to the attacker.

Why It’s Effective and Dangerous

One of the key advantages for attackers is the real-time interaction a phone call offers. It allows scammers to read emotions, respond dynamically and apply pressure in ways a phishing link never could. Victims may be persuaded to reveal login details, provide payment information or download remote access tools often without realising they’ve been duped until it’s too late.

Importantly, this isn’t the same as “vishing” (voice phishing), where attackers call victims out of the blue. In callback phishing, the victim makes the call, genuinely believing they are dealing with a reputable company.

To make detection even trickier, attackers often use VoIP (Voice over Internet Protocol) numbers that are harder to trace than traditional landlines or mobiles. Some phone numbers are even reused over multiple days, as phone-based threat intelligence tends to lag behind the detection of malicious URLs or email addresses.

Multiple Variants, Same Goal

Callback phishing isn’t limited to emails. Some attackers have been found embedding QR codes in messages, which when scanned, redirect users to phishing sites. Others use legitimate services like Adobe PDF to send seemingly trustworthy documents that replicate the same scam.

No matter the delivery method, the common theme is brand impersonation. Scammers rely on the familiarity of trusted companies to exploit users’ trust and it’s working.

What Organisations Can Do

While user training remains important, research continues to show that traditional cyber awareness programmes alone aren’t enough to stop these increasingly clever social engineering attacks.

Instead, organisations should prioritise technological defences, such as:

  • Brand impersonation detection tools within email security platforms

  • Advanced email filtering that flags suspicious content, even when no links or attachments are present

  • Monitoring for unusual phone-based activity, especially around helpdesk interactions

It’s also wise to provide tailored, scenario-based training to users most likely to be targeted, such as finance teams or senior leadership, to raise awareness of these more sophisticated techniques.

To Sum Up

As phishing tactics evolve, so must our defences. Callback phishing is a reminder that trust, not just technology, is being exploited. It’s essential for businesses to adapt accordingly. Investing in the right mix of preventative tools and context-aware training will go a long way in keeping your organisation secure from these increasingly human-centric threats.

If your organisation is concerned about callback phishing or how easily attackers can exploit trusted brand names to bypass your defences, our team at CybaVerse is here to help. Get in touch here to learn how we can assess your risk and strengthen your protection against evolving social engineering threats.

Zero-Click Exploit ‘EchoLeak’ Found in Microsoft Copilot Could Lead to Data Breaches

13th June 2025

A significant vulnerability affecting Microsoft Copilot has been disclosed, which could have allowed attackers to exfiltrate sensitive data from Microsoft 365 (M365) users via prompt injection attacks. The flaw, named “EchoLeak” and tracked as CVE-2025-32711, was discovered by a security research team and has now been patched by Microsoft. Fortunately, the issue was addressed before it could be exploited in the wild, and there have been no reports of actual breaches.

EchoLeak is a zero-click vulnerability that targeted the AI-driven features within M365 Copilot. Copilot is a suite of tools integrated into M365 that allows users to draft documents, analyse data, and even deploy agents using advanced AI. Although typically used by members within an organisation, this vulnerability had the potential to let attackers execute an attack by simply sending an email—no direct user action required.

How EchoLeak Worked

The vulnerability allowed attackers to use prompt injection to trick Copilot into revealing confidential information. By crafting an email with specific instructions, an attacker could bypass security measures and get Copilot to send sensitive data back to an external server under their control. The attacker’s email would include a link containing a query string that Copilot would mistakenly process as a legitimate request for data.

Normally, AI systems are protected by various security features, including classifiers that block malicious injections. However, EchoLeak was able to circumvent these protections by making the email appear as though it was meant for the user instead of the Copilot AI. This deception allowed the email to bypass the filter and reach the recipient’s inbox. Once delivered, the email would instruct Copilot to provide data from the M365 environment, potentially exposing proprietary and sensitive information.

The exploitation of this vulnerability also leveraged Markdown formatting tricks. While Copilot typically redacts unsafe markdown links, the attack used a reference-style markdown, which at the time bypassed these safeguards.

Microsoft’s Response

Upon discovering the flaw, Microsoft swiftly issued a patch and stated that no customer action was required. The company also noted that they had not seen any instances where the vulnerability had been exploited. As part of the fix, Microsoft added additional security layers to strengthen their defenses against similar future attacks.

A Microsoft spokesperson emphasised the importance of the security team’s collaboration with researchers, saying, “We appreciate the responsible reporting of this issue, which allowed us to address it before any harm could be done. We have already updated our products to mitigate this vulnerability, and we are also implementing further defensive measures.”

A Growing Concern for AI Systems

Although this particular vulnerability has been addressed, the discovery of EchoLeak highlights the ongoing challenges posed by prompt injection flaws in AI systems. These types of attacks, while still relatively new, are increasingly relevant to AI-driven tools across various industries. Researchers have already identified similar vulnerabilities in other platforms, pointing to the need for continued vigilance as AI technology evolves.

As AI products become more integrated into business operations, ensuring their security will be crucial in preventing future exploits. It remains to be seen whether other systems could be vulnerable to similar attack vectors, and it’s clear that AI security needs to be a priority for vendors across the board.

While Microsoft has acted to fix the issue, organisations using AI-powered tools should remain cautious and stay up to date with the latest security patches to protect their sensitive data from potential threats.

New Mirai Botnet Campaigns Exploit Vulnerability in Wazuh Platform

12th June 2025

Botnet operators are exploiting newly discovered vulnerabilities faster than ever before, demonstrating an alarming trend in the speed with which attacks are carried out following public vulnerability disclosures. Two separate campaigns using Mirai botnet variants have targeted an unexpected system: the Wazuh cyber security platform.

A recently identified vulnerability, CVE-2025-24016, allows remote code execution within Wazuh, which is an open-source security platform used for log analysis and intrusion detection. This vulnerability, with a critical CVSS score of 9.9, results from an unsafe deserialisation issue and affects Wazuh versions 4.4.0 to 4.9.1. First disclosed in February 2025, a proof-of-concept (PoC) exploit was soon published, and by March, exploitation attempts were already underway.

This situation highlights a growing trend of “time-to-exploit” shrinking, with cybercriminals jumping on public vulnerabilities almost immediately after they are made known. The Mirai botnet, a notorious piece of malware known for its devastating distributed denial-of-service (DDoS) attacks, has evolved significantly since its creation nearly a decade ago. Originally developed by hackers to target gaming servers, Mirai’s source code was released to the public, allowing other cybercriminal groups to adapt it and launch their own botnet attacks. Since then, Mirai botnets have been used in widespread attacks against critical infrastructure globally.

In this case, the Mirai botnet campaigns focused on exploiting the Wazuh platform. The first of these campaigns targeted Wazuh servers using LZRD Mirai variants. Beginning in March, these attacks were aimed at exploiting the Wazuh vulnerability through various IoT device architectures, much like other Mirai campaigns. However, unlike previous Mirai campaigns that focused primarily on IoT devices, this one targeted a cyber security platform, marking a shift in the botnet’s approach.

In May, a second campaign, dubbed “Resbot,” followed suit. This variant also exploited vulnerable Wazuh instances but used different code to target specific endpoints. The campaign displayed interesting characteristics, including the use of Italian-language domains to spread malware, potentially pointing to Italian-speaking threat actors. Despite these differences, both campaigns appear to be unconnected, though it is possible that the second group was simply opportunistically leveraging the public PoC code from the first attack.

While these campaigns represent the latest phase of Mirai botnet activity, they also highlight a broader issue in cyber security: the dangers of releasing PoC exploits. Although PoCs help researchers illustrate the impact of vulnerabilities and encourage organisations to take action, they also provide attackers with ready-made tools for exploitation. As seen here, once a PoC is published, it doesn’t take long for malicious actors to adapt it and launch attacks, underscoring the importance of timely patching.

As part of the response, cyber security experts strongly advise all Wazuh users to upgrade to version 4.9.1 or later to mitigate the risk of exploitation. This situation also serves as a stark reminder that organisations must act quickly to patch vulnerabilities, especially those that become publicly known, to avoid becoming the next victim of a botnet attack.

Botnet operators continue to exploit a wide range of vulnerabilities, not just in IoT devices but in critical cyber security products as well. This emphasises the need for constant vigilance and the importance of regularly updating and patching systems to stay one step ahead of cybercriminals.

Microsoft Patch Tuesday June 2025

11th June 2025

This month’s Patch Tuesday has been released, which addresses a total of 66 vulnerabilities across various products. Among these, one actively exploited vulnerability and another publicly disclosed flaw are being patched, alongside several other critical issues.

The June update includes fixes for 10 “Critical” vulnerabilities, which comprise eight remote code execution (RCE) vulnerabilities and two elevation of privilege (EoP) flaws. This round of patches also covers a range of other security risks, such as information disclosure, denial of service, and spoofing vulnerabilities. Here’s a breakdown of the categories:

  • 13 Elevation of Privilege Vulnerabilities
  • 3 Security Feature Bypass Vulnerabilities
  • 25 Remote Code Execution Vulnerabilities
  • 17 Information Disclosure Vulnerabilities
  • 6 Denial of Service Vulnerabilities
  • 2 Spoofing Vulnerabilities

It’s worth noting that this count does not include vulnerabilities fixed earlier in the month for Mariner, Microsoft Edge, and Power Automate.

Zero-Day Vulnerabilities Addressed

This month’s updates fix two notable zero-day vulnerabilities—one that is actively being exploited and another that was publicly disclosed before a fix was made available.

Actively Exploited Zero-Day: WEBDAV RCE Vulnerability (CVE-2025-33053)

The first critical zero-day patched today is a remote code execution vulnerability in Web Distributed Authoring and Versioning (WEBDAV), tracked as CVE-2025-33053. Discovered by Check Point Research, this flaw allows attackers to execute arbitrary code on affected systems if a user clicks on a specially crafted WebDav URL.

Check Point Research uncovered this vulnerability during a cyberattack attempt in March 2025, attributed to the APT group “Stealth Falcon.” The attackers used an undisclosed technique to execute malicious files hosted on a WebDAV server they controlled. Microsoft has now patched the vulnerability, thanks to responsible disclosure from the researchers.

Publicly Disclosed Zero-Day: SMB Elevation of Privilege (CVE-2025-33073)

The second zero-day fixed in the June Patch Tuesday updates is an elevation of privilege vulnerability in Windows SMB, tracked as CVE-2025-33073. This flaw allows attackers to escalate privileges to SYSTEM-level access on vulnerable devices.

To exploit this vulnerability, an attacker could trick the victim machine into connecting to their system via SMB and execute a specially crafted script, resulting in elevated privileges. While the flaw was publicly disclosed by DFN-CERT earlier this month, Microsoft has since released a patch to fix it. Additionally, enforcing server-side SMB signing via Group Policy can mitigate the risk of exploitation.

Multiple security researchers, including those from CrowdStrike, Synacktiv, and RedTeam Pentesting, contributed to the discovery and responsible disclosure of this flaw.

Other Security Updates and Vendor Patches

In addition to the vulnerabilities addressed in Microsoft’s updates, several other vendors also released critical patches in June 2025:

  • Adobe released patches for a variety of products, including InCopy, Experience Manager, Acrobat Reader, and Substance 3D tools.
  • Cisco patched three vulnerabilities with known exploits in its Identity Services Engine (ISE) and Customer Collaboration Platform (CCP) products.
  • Fortinet fixed an OS command injection vulnerability impacting its FortiManager and FortiAnalyzer products
  • Google issued security updates for Android, including a fix for a Chrome zero-day vulnerability actively being exploited in the wild.
  • Hewlett Packard Enterprise (HPE) released patches for vulnerabilities in its StoreOnce systems.
  • Qualcomm addressed three zero-day flaws in the Adreno Graphics Processing Unit (GPU) driver.
  • SAP released critical updates for SAP NetWeaver and other products.

Stay Protected

As always, it’s essential to apply these security updates as soon as possible to protect your systems from potential exploitation. Regular patching is a crucial step in safeguarding your infrastructure against known vulnerabilities, especially those actively targeted by cybercriminals.

For a full description of each vulnerability and the systems affected, please refer to the complete report from Microsoft’s security update guide.

If you need assistance with vulnerability management or want to learn how these threats might impact your organisation, reach out to our team or discover how our platform can streamline patching and help minimise cyber risk.

Millions of Android Devices Compromised by BADBOX 2.0 Malware

6th June 2025

The FBI has issued a warning about the resurgence of the BADBOX 2.0 malware campaign, which has infected over 1 million consumer devices globally. The malware turns compromised Android-based smart TVs, streaming boxes, projectors, and tablets, mostly manufactured in China, into residential proxies used for cybercriminal activity.

These devices are either preloaded with malware at the point of sale or infected during setup via malicious firmware updates or backdoored Android apps, sometimes even downloaded from Google Play or third-party stores. Once connected to a home network, infected devices are enrolled into the BADBOX botnet and communicate with attacker-controlled command-and-control servers.

The FBI notes that cybercriminals are exploiting these devices in a number of ways:

Residential proxy services – Routing malicious traffic through victims’ home IP addresses.

Ad fraud – Generating illegitimate ad revenue via hidden ad clicks.

Credential stuffing – Using stolen credentials to attempt logins across other services.

BADBOX originally appeared in 2023 in cheap, unbranded Android TV boxes like the T95. Despite a successful takedown by Germany’s BSI in 2024, infections surged again in 2025, even spreading to better-known brands such as Hisense and Yandex.

Security researchers at HUMAN’s Satori Threat Intelligence team have renamed the botnet “BADBOX 2.0” and estimate that it now spans 222 countries. The highest infection rates have been observed in Brazil, the US, Mexico, and Argentina. Over 500,000 devices were blocked from accessing attacker infrastructure following a joint disruption effort involving HUMAN, Google, Trend Micro, and others—but the malware continues to spread via new device sales.

Affected devices are generally uncertified Android Open Source Project (AOSP) devices and not covered by Google’s Play Protect. Red flags for infection include:

Suspicious or alternative app stores pre-installed

Disabled Play Protect

Promises of “free content” or unlocked streaming

Unknown or off-brand manufacturers

Strange or unexpected internet traffic

FBI Recommendations: Audit your home IoT devices for unusual behaviour.

Avoid sideloading or using unofficial app stores.

Monitor your home network traffic.

Keep devices updated with the latest firmware.

If you suspect infection, disconnect the device from the internet immediately.

A full list of affected models includes many variants of the X96, MX, KM, and other low-cost Android devices.

The North Face Alerts Customers to April Cyber Attack

4th June 2025

Outdoor retail giant The North Face has notified customers of a data breach stemming from a credential stuffing attack that took place in April 2025, once again exposing sensitive personal information.

The brand, a subsidiary of VF Corporation—also the parent company of Vans, Timberland, and Dickies—detected suspicious activity on its website, thenorthface.com, on April 23. After immediate investigation, the company confirmed that cybercriminals had launched a credential stuffing campaign, successfully breaching a number of user accounts.

Credential stuffing involves using stolen login credentials, often obtained from previous breaches, to access user accounts through automated login attempts. These attacks are especially effective when individuals reuse the same email and password combinations across multiple platforms. However, multi-factor authentication (MFA) can often stop such attacks—even when passwords are compromised.

In this incident, attackers were able to access customer data including:

Full names

Purchase history

Shipping addresses

Email addresses

Dates of birth

Telephone numbers

Fortunately, no payment information was compromised. The North Face clarified that all transactions are processed by a third-party payment provider, and only encrypted tokens are stored on their systems.

Affected individuals have started receiving breach notification letters, with a sample submitted to the Vermont Attorney General’s Office. The notification describes the attack as “small scale,” but details on the total number of impacted accounts have not yet been disclosed.

An Ongoing Security Problem

This latest breach marks the fourth credential stuffing incident The North Face has experienced since 2020, raising concerns about the company’s ongoing security practices—particularly its failure to enforce MFA across all accounts.

Just one month prior, in March 2025, VF Corporation disclosed another credential stuffing attack that affected both thenorthface.com and timberland.com, exposing 15,700 accounts. Previous attacks in November 2020 and September 2022 impacted more than 200,000 users combined.

Beyond credential stuffing, the company faced its most severe cyber incident in December 2023, when a ransomware attack compromised the data of 35 million customers.

As of now, The North Face has not provided further comment on the April incident or the number of users affected. BleepingComputer has reached out to the company for clarification and is awaiting a response.

Cartier Among Latest Victims in Wave of Cyberattacks Targeting Fashion Labels

3rd June 2025

Cartier has confirmed a data breach that resulted in unauthorised access to some customer information, becoming the latest high-profile fashion brand to fall victim to cybercriminals.

In notification letters sent out today — some of which have surfaced on social media — the luxury jeweler informed affected individuals that attackers temporarily gained access to its internal systems and accessed limited personal data.

“An unauthorised party briefly infiltrated our system and retrieved certain client details,” the company wrote in its customer notice. “The breach was promptly contained, and we’ve since reinforced our cyber security measures to prevent future incidents.”

Cartier stated that the exposed data includes customers’ names, email addresses, and country of residence. The company emphasised that no financial data, login credentials, or sensitive account information were accessed during the breach.

Still, Cartier has urged customers to remain cautious, advising them to be on the lookout for phishing attempts or unexpected communications that may leverage the stolen information.

“As a precaution, we encourage you to be vigilant about unsolicited messages or any activity that appears suspicious,” the notification said.

The company has reported the incident to law enforcement and brought in a third-party cyber security firm to assist with the investigation and ongoing remediation efforts.

BleepingComputer reached out to Cartier for further details, including the timeline of the breach and the scope of those affected, but has yet to receive a response.

Cyberattacks Target Fashion Industry

Cartier’s disclosure comes amid a broader wave of cyberattacks hitting global fashion brands.

Earlier in May, Dior reported a breach that compromised customer contact information, purchase histories, and preferences. Around the same time, Adidas confirmed a breach linked to a third-party provider, which exposed customer contact details but did not affect payment or account security.

More recently, Victoria’s Secret was forced to temporarily shut down its website and certain in-store services due to a cyber security incident that remains under investigation. Like Cartier, the company is working with external experts to assess the damage and secure its infrastructure.

These incidents highlight a growing trend of cybercriminals targeting the retail and luxury sectors, prompting renewed calls for enhanced cyber security across the industry.

MathWorks, Maker of MATLAB, Discloses Ransomware Incident

28th May 2025

MathWorks, the Massachusetts-based developer behind MATLAB and Simulink, has confirmed it was the target of a ransomware attack that disrupted both customer-facing and internal systems. The incident began on Sunday, May 18, and was disclosed via a website update on Monday.

The attack affected several online services, including account login systems, cloud applications, and MATLAB Mobile. Over the following days, updates from MathWorks revealed ongoing technical issues and efforts to restore functionality. As of May 21, the company had restored Single Sign-On (SSO) and multi-factor authentication (MFA), although some services—like Cloud Center and ThingSpeak—remained impacted.

By May 23, further complications had emerged, including degraded performance of MathWorks Account services and login issues for users who hadn’t accessed their accounts since October 2024. Two-step verification was also reported to be unreliable during this period.

With the help of cyber security experts, MathWorks is working to recover systems and fully investigate the breach. The company has notified federal authorities but has not disclosed the ransomware group responsible, nor whether any data was exfiltrated. So far, no known cybercrime group has claimed responsibility.

APT41 Hides C2 in Google Calendar

29th May 2025

The Chinese state-backed threat group APT41 is back in the spotlight after researchers uncovered a new malware strain, ToughProgress, which cleverly uses Google Calendar as a command-and-control (C2) channel.

Discovered by Google’s Threat Intelligence team, the campaign hides communication within trusted Google services—making it difficult for security tools to detect. ToughProgress polls hidden calendar events for instructions and reports back by creating new events, using Google’s infrastructure to quietly operate under the radar.

The attack starts with a phishing email linking to a ZIP file hosted on a compromised government site. Inside: a fake PDF, a disguised JPG (actually a payload), and a DLL file that decrypts and launches the malware. Once running, the malware injects itself into a legitimate Windows process (svhost.exe) and begins its covert C2 activity.

This isn’t the first time APT41 has misused Google tools. In 2023, they were caught using Google Sheets and Drive in another campaign. They’re also not alone—other threat actors have recently abused Google Calendar and NPM packages in similar ways.

Google has shut down the attacker-controlled calendar accounts, terminated related Workspace access, and added malicious domains to Safe Browsing blocklists to prevent further damage. Although no specific victims were named, Google confirmed affected organisations have been notified and provided with malware samples and indicators of compromise.

Adidas Impacted by Data Breach Through Third-Party Vendor

27th May 2025

Adidas has confirmed it was impacted by a data breach stemming from a compromise of a third-party customer service provider. The incident exposed customer contact information collected during past interactions with the brand’s support channels. Crucially, no passwords, financial data, or payment details were involved.

Details: While Adidas has not disclosed the name of the vendor involved or the identity of the threat actor, the company stated it is actively investigating the breach. It is working alongside cyber security experts and has begun notifying affected customers, as well as regulatory and law enforcement authorities, in line with data protection laws.

Security Implications: This breach highlights the persistent and growing risk associated with third-party vendors in the digital supply chain. As organiastions expand their use of outsourced services, their attack surface increases—often beyond their direct control. Fletcher Davis, Senior Security Research Manager at BeyondTrust, emphasised this point, noting:

_“Third-party breaches swiftly become your organization’s breaches. Businesses must enforce security assessments, multifactor authentication, and zero-trust policies for all vendors. Real-time identity monitoring is also essential to reduce incident response times from days to minutes.” _ Context & Industry Trend: Adidas joins a growing list of major retailers affected by cyber security incidents. Recently, UK brands including Co-op Group, Harrods, and Marks & Spencer have also faced ransomware attacks. In the case of Marks & Spencer, the attack—believed to have been conducted by the Scattered Spider group using DragonForce ransomware—led to the theft of customer data and operational disruptions, with financial losses projected at $400 million.

M&S Confirms Customer Data Stolen in Recent Cyber Attack

15th May 2025

Marks & Spencer (M&S), one of the UK’s leading retailers, has confirmed that a recent cyber attack has resulted in the theft of personal customer information. The breach compromised details such as phone numbers, home addresses, and dates of birth, although the company has reassured customers that account passwords were not affected.

Initially reported as a “cyber incident,” M&S had stated that the attack caused only temporary disruptions to store operations. However, the company later revealed that it had to pause online orders temporarily while it worked to contain the breach and recover affected systems.

In a statement released on May 13, M&S updated customers via the London Stock Exchange, reassuring them that no action was required at that time. However, to provide added security, the retailer announced that customers would be prompted to reset their passwords the next time they accessed their M&S accounts. They also provided advice on staying safe online in the wake of the breach.

While M&S has stressed that no payment information was compromised and no account passwords were stolen, it remains important for customers to stay vigilant. The stolen data primarily consisted of contact details, and M&S has not provided evidence that the information has been shared or misused. Customers are being urged to remain cautious about any unsolicited communication that may attempt to exploit the stolen data.

The attack on M&S is part of a wider trend affecting UK retailers. The National Cyber Security Centre (NCSC) has acknowledged a series of attacks on major retailers, including Co-Op and Harrods. The group behind these attacks, DragonForce, has taken responsibility for the incidents. This ransomware gang, which emerged in 2023, operates using a ransomware-as-a-service (RaaS) model, allowing its affiliates to create unique brand identities while using variants of DragonForce’s ransomware.

Although the full financial impact of the breach on M&S is still unclear, the company faces potential consequences, particularly as a significant portion of its clothing and home sales are made online. As the retail sector continues to face increasing cyber risks, this breach highlights the growing need for businesses to invest in robust cyber security measures to protect both their own data and their customers’ information.

Cyber security experts are warning that businesses must be prepared for more targeted attacks, as cybercriminals increasingly focus on stealing data rather than directly accessing payment systems. As the threat landscape continues to evolve, organisations must prioritise protecting sensitive customer information to avoid significant reputational and financial damage.

Critical Windows Server Flaw Exposes Active Directory to Privilege Escalation Attacks

22nd May 2025

A recently discovered vulnerability in Windows Server 2025 could potentially allow attackers to escalate privileges and assume any Active Directory (AD) user’s permissions. The flaw, which is tied to the delegated Managed Service Account (dMSA) feature, occurs due to mishandling of permissions during account migration — a process that was designed to ensure seamless transitions from legacy service accounts to newer dMSAs.

What Is the dMSA Vulnerability?

The vulnerability arises from a feature introduced in Windows Server 2025, which allows dMSAs to migrate existing non-managed service accounts into a more modern dMSA format. This migration process is intended to be seamless, transferring all permissions from the old account to the new one. However, a flaw in the design of this process has left it vulnerable to exploitation, as permissions are improperly granted by the Key Distribution Center (KDC), the system that handles authentication and permission assignment.

The flaw is present by default in any domain with at least one Windows Server 2025 domain controller, even if the organisation doesn’t actively use dMSAs. Attackers who can obtain benign permissions on any organisational unit (OU) in the domain can exploit this vulnerability to escalate their privileges, bypassing security measures and potentially compromising the entire network.

How Attackers Can Exploit the Flaw

An attacker who controls the permissions of a dMSA object could effectively gain control over the entire domain. This could allow them to access sensitive information, take control of critical systems, and move laterally within the network. In some cases, this type of privilege escalation could serve as an initial step before more severe attacks, such as deploying ransomware or stealing data across the network.

While the flaw was first discovered in April, and Microsoft has since been notified, a formal patch has not yet been released, and Microsoft has classified the vulnerability as “moderate severity” for now. However, organisations should not wait for a patch and should take proactive steps to reduce their exposure.

What Can You Do to Mitigate the Risk?

Given that this vulnerability is tied to permissions handling in a fundamental part of Windows Server, it is essential for organisations to take immediate action to secure their systems. Microsoft has recommended several mitigation strategies until a patch becomes available:

1. Tighten Permissions for dMSA Management Organisations should ensure that permissions for creating or managing dMSAs are strictly controlled. Only trusted administrators should have the ability to manage these accounts, and all changes should be regularly monitored and audited.

2. Audit and Monitor dMSA Activity Active Directory configurations should be audited for dMSA-related activities. This includes tracking the creation of dMSAs, monitoring any changes to the associated attributes, and reviewing the permissions granted to these accounts.

3. Limit Creation of dMSAs Limiting who can create dMSAs across the domain will reduce the attack surface. Administrators should use PowerShell scripts to identify all users or groups with permissions to create dMSAs and limit that ability to trusted personnel only.

Until a patch is released, organisations should be especially cautious of overly permissive systems and take additional steps to reduce their exposure. A formal patch from Microsoft is expected, but it’s important for businesses to stay vigilant and review their security practices now.

This flaw highlights a critical lesson: even well-designed migration processes can introduce significant vulnerabilities if not carefully implemented. As long as this flaw remains unpatched, organisations should treat dMSA management with the highest level of scrutiny, ensuring that only trusted personnel can make changes and that all actions are carefully monitored.

Stay Secure and Proactive

Active Directory remains a prime target for cybercriminals, and vulnerabilities like this show how even minor misconfigurations can lead to major security breaches. Now is the time for IT teams to assess their environments, implement tighter controls, and ensure that permissions are aligned with best practices.

Fraudulent AI Tools Conceal Malware Threat, Exploiting Users for Data Theft

13th May 2025

In an emerging scam, cybercriminals are deceiving users with fake generative AI platforms, leading to the installation of credential-stealing malware. These attackers advertise seemingly legitimate AI tools on social media platforms, only to hijack personal data once victims interact with their supposed services.

The campaign primarily targets users in social media groups, offering “generative AI” tools that promise to create images, videos, logos, websites, and more. However, the so-called “tools” are nothing more than malware delivery systems designed to steal sensitive information.

How the Scam Works

Cybercriminals are using platforms like Facebook to promote fraudulent generative AI websites. These fake sites are made to look credible, often mimicking well-known services like Luma AI’s Dream Machine product. Once users upload a reference image or media file to the site, they are encouraged to download the “processed” version. Unfortunately, the download is actually malware in disguise.

At this point, the attacker’s malware, known as Noodlophile Stealer, is silently installed on the user’s device. This sophisticated malware steals browser credentials, cookies, and even cryptocurrency data, sending it back to a bot on the messaging app Telegram. Noodlophile is not just a simple data thief—it also opens doors for further exploits, including remote access to infected devices.

Who’s at Risk?

This scam doesn’t only affect individuals. Small businesses and freelancers looking for affordable or free marketing tools are prime targets. With many businesses operating under tight budgets, the temptation to use these seemingly legitimate AI tools can be strong, but users often end up paying a far greater price when their devices are compromised.

Researchers have found that the campaign has successfully infiltrated several medium-sized businesses as well, where the malware is sometimes blocked before it can fully execute. However, it highlights the vulnerability of businesses that might not have the necessary training or cyber security awareness to spot these threats.

Defending Against AI-Driven Malware

The rise of such targeted attacks calls for heightened vigilance. Here are key takeaways for individuals and businesses:

1. Avoid Free or Unverified AI Tools: Steer clear of using AI platforms that aren’t from well-known or trusted sources. Scammers often pose as legitimate services, so caution is essential.

2. Keep Personal and Business Activities Separate: Ensure strict boundaries between personal and business-related digital activities. This reduces the likelihood of falling for scams that blur the line between the two.

3. Be Cautious with Downloads: Pay extra attention when downloading archive files (.zip, .rar, etc.), especially from unknown sources. Malware often hides in these files.

4. User Education is Crucial: Regularly educate employees and users on the risks of phishing, how to spot suspicious links, and the importance of only using verified tools.

Cyber security awareness is an ongoing necessity, and as malware campaigns evolve, businesses and individuals alike must stay vigilant. With the growing use of generative AI, it’s vital to know how to recognise and defend against these emerging threats.

Data Breach at Legal Aid Agency: Important Information for Lawyers and Clients

20th May 2025

The Legal Aid Agency (LAA) has announced that it was the victim of a cyberattack on April 23, 2025, which affected its online services. While the digital platform has been taken offline as a result of the breach, the agency has reassured the public that individuals in need of legal assistance will still have access to support.

Based in London, the LAA provides legal aid services to individuals across England and Wales, helping them with civil and criminal legal matters. Sponsored by the Ministry of Justice, the agency works closely with various government departments to ensure that individuals facing legal challenges have access to the help they need.

The cyberattack compromised the agency’s online services, which are used by legal aid providers to log their work and receive government payments. According to the agency, attackers managed to access a significant amount of sensitive data, including personal details from legal aid applicants.

While the breach is still being investigated, researchers have estimated that over 2 million pieces of personal data may have been exposed. Given that 360,000 applications for legal aid were processed during the 2023–24 period, the breach appears to have been extensive.

Since learning of the attack, the LAA has informed all affected legal aid providers, advising them that their personal and financial information may have been compromised. The agency has also reported the incident to the Information Commissioner and is cooperating with the National Crime Agency (NCA) and the National Cyber Security Centre (NCSC) as part of the ongoing investigation.

By May 16, the LAA discovered that the breach was more extensive than initially thought. The attackers had accessed and downloaded large volumes of personal data related to legal aid applicants dating back to 2010. Compromised data includes sensitive information such as addresses, dates of birth, national ID numbers, criminal histories, employment status, and financial details.

Experts have pointed out that the legal sector is a prime target for cybercriminals due to the vast amount of highly sensitive and confidential client data it holds. The breach is particularly damaging to the trust that clients place in legal services, as they expect their personal information to be securely protected. Following the attack, clear communication and actionable steps are crucial for affected individuals, ensuring they know how to protect themselves and mitigate any further risk.

The LAA is advising those who have applied for legal aid since 2010 to take immediate steps to secure their personal information. This includes being vigilant for any suspicious activity, updating passwords, and taking other precautionary measures to safeguard against potential fallout.

While the online services remain unavailable, the agency has implemented contingency plans to ensure that individuals in urgent need of legal support can continue to receive assistance during this time. The LAA is committed to providing the necessary help and guidance to affected parties, working to resolve the situation as swiftly as possible.

This incident serves as a reminder of the importance of securing sensitive data, particularly in sectors that handle personal, financial, and legal information. It also highlights the growing threat of cyberattacks in the public sector, underlining the need for constant vigilance and robust cyber security measures to prevent similar incidents in the future.