The US Department of Justice, in collaboration with international partners, has executed a sweeping crackdown on North Korean IT worker schemes that infiltrated more than 100 US companies. These operatives used stolen or fictitious identities, “laptop farms,” and advanced techniques (including leveraging AI) to gain employment, steal sensitive company data and salaries, and funnel funds to the North Korean regime. The action included raids, arrests, and the seizure of millions of dollars, with the US warning organizations to review hiring and IT worker vetting processes.
Source: Bloomberg Cyber
Critical Citrix NetScaler Vulnerabilities (“CitrixBleed 2”) See Active Exploitation—Thousands Remain Unpatched
Researchers have confirmed that the critical Citrix NetScaler Gateway vulnerability (CVE-2025-5777, aka "CitrixBleed 2") is being actively exploited, allowing attackers to hijack user sessions, bypass MFA, and potentially compromise organizations' remote access infrastructure. Thousands of Citrix NetScaler instances remain unpatched despite federal alerts and urgent advisories, with CISA including the flaw in its Known Exploited Vulnerabilities catalog. Immediate patching and session invalidation are strongly recommended.
Source: SecurityWeek
Iranian Cyber Threats Escalate Against US Critical Infrastructure & Defense Sector
US intelligence and cybersecurity agencies have jointly warned of rising malicious cyber activity from Iranian state-linked groups post-ceasefire, targeting defense contractors and essential infrastructure. The latest warnings highlight Iranian actors exploiting outdated software, unpatched vulnerabilities, and weak/default passwords, making proactive patching and credential hardening critical for at-risk organizations. Researchers have also identified Iranian focus on exposed industrial control systems (ICS), calling for immediate risk assessments and mitigations.
Source: SecurityWeek
Chrome Zero-Day Bug Patched Amid Active Exploits—Emergency Update Required
Google has issued an emergency patch for Chrome (v138), closing a high-severity zero-day vulnerability in the V8 JavaScript engine (CVE-2025-6554) that is already being exploited in the wild. All users are urged to update their browsers immediately to mitigate the risk of remote code execution, as attacks are reportedly underway. Chrome’s broad usage in enterprises and government makes urgent patching a top priority.
Source: SecurityWeek
Ransomware Activity Update: Qilin Surges, Hospitals Linked to Fatalities
Qilin has reclaimed the top spot among ransomware groups in June, outpacing competitors and targeting a diverse set of industries and critical infrastructure. Recent reports also underscore the sobering reality of ransomware’s impact, with attacks on European hospitals directly linked to patient deaths due to care disruptions. These incidents highlight ransomware’s growing operational and human cost, not just financial.
Source: Cyble
AI Becomes Newest Cybercrime Weapon—and Weak Link in Security
Flashpoint and other threat intel experts warn that cybercriminals are using generative AI and large language models (LLMs) to orchestrate deepfake-powered social engineering attacks, including convincing executive impersonations that have resulted in multimillion-dollar thefts. Recent independent research suggests browser-based AI “agents” may be even riskier than human employees as they are susceptible to phishing and prompt injection, urging CISOs to reassess AI governance and mitigation strategies.
Source: Help Net Security
Canada Bans Hikvision Over National Security Concerns
Canada has ordered Hikvision, the Chinese surveillance equipment giant, to cease all operations in the country and banned its technology from government use, citing national security risks. The ban follows intelligence assessments and mirrors global moves against Chinese surveillance tech over concerns regarding data privacy and potential links to espionage.
Source: SecurityWeek
International Criminal Court Targeted in Sophisticated Cyberattack
The International Criminal Court (ICC) confirmed it was hit by a sophisticated and targeted cyberattack as global leaders gathered in the Hague for a NATO summit. While the attack has reportedly been contained, the incident underscores the persistent targeting of international institutions by advanced threat actors as geopolitical tensions rise.
Source: Politico Cyber
You May Also Be Interested In...