THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Operation ENDGAME Dismantles Global Ransomware Infrastructure **Date:** May 25, 2025 **Source:** [Security Affairs](https://securityaffairs.com/178245/cyber-crime/operation-endgame-disrupted-global-ransomware-infrastructure.html) **Summary:** In a sweeping crackdown, Operation ENDGAME, led by Europol and Eurojust, dismantled a significant portion of global ransomware infrastructure. This multinational initiative resulted in the takedown of 300 servers, 650 domains, and the issuance of 20 international arrest warrants. More than €21.2M in cryptocurrency was seized in the process. This operation demonstrates the concerted efforts of global law enforcement to tackle cybercrime on an international scale. ### Trojanized KeePass Used as a Springboard for Ransomware **Date:** May 25, 2025 **Source:** [HelpNet Security](https://www.helpnetsecurity.com/2025/05/25/week-in-review-trojanized-keepass-allows-ransomware-attacks-cyber-risks-of-ai-hallucinations/) **Summary:** Researchers at WithSecure have uncovered that a trojanized version of the open-source password manager KeePass is being used as an entry point for ransomware attacks. The threat actor, suspected to be an initial access broker, compromises this software to facilitate subsequent ransomware deployment, highlighting the dangers of tampered software distribution. ### Silent Ransom Group Continues to Target Law Firms **Date:** May 24, 2025 **Source:** [Security Affairs](https://securityaffairs.com/178239/malware/silent-ransom-group-targeting-law-firms-the-fbi-warns.html) **Summary:** The FBI has issued a warning regarding the ongoing activities of the Silent Ransom Group, also known as Luna Moth. Active since 2022, this group targets U.S. law firms with sophisticated phishing and social engineering strategies. Their tactics, including BazarCall campaigns, continue to pose significant threats to the legal sector’s cybersecurity posture. ### SK Telecom Exposes Two-Year Data Breach **Date:** May 24, 2025 **Source:** [HackRead](https://hackread.com/sk-telecom-malware-attack-leaking-26m-imsi-records/) **Summary:** A malware attack on South Korea's SK Telecom has been uncovered after two years, resulting in the leakage of over 26 million International Mobile Subscriber Identity (IMSI) records. The stealth and persistence of this attack underscore the challenges telecommunications companies face in safeguarding customer data. ### Zimbra XSS Vulnerability Exploitation **Date:** May 25, 2025 **Source:** [HackRead](https://hackread.com/zimbra-cve-2024-27443-xss-flaw-hit-sednit-servers/) **Summary:** A critical cross-site scripting (XSS) vulnerability identified as CVE-2024-27443 is actively being exploited in the Zimbra Collaboration Suite. The Sednit hacking group is suspected to be behind these attacks affecting 129,000 servers. This highlights the urgent need for organizations using Zimbra to apply patches and secure their systems against potential breaches. ### You May Also Be Interested In... - **Leader of Qakbot Cybercrime Network Indicted:** [Read more](https://securityaffairs.com/178232/uncategorized/leader-of-qakbot-cybercrime-network-indicted-in-u-s-crackdown.html) - **Microsoft Advises Reboot for Almost All Windows Users:** [Read more](https://www.forbes.com/sites/zakdoffman/2025/05/24/microsoft-tells-nearly-all-windows-users-you-must-reboot-your-pc/) - **The US Develops a Central Portal for Data Purchases:** [Read more](https://www.wired.com/story/us-spies-one-stop-shop-private-data/) - **Hackers Use Fake VPN to Spread Winos 4.0 Malware:** [Read more](https://thehackernews.com/2025/05/hackers-use-fake-vpn-and-browser-nsis.html)
Cybersecurity — May 25, 2025 | Briefing24