Researchers at Cyble have uncovered an expansive, ongoing phishing campaign dubbed "Scanception" leveraging QR codes in PDFs to deliver credential-harvesting URLs and Adversary-in-the-Middle (AITM) phishing pages. This global operation abuses trusted cloud and redirect services (like YouTube, Google, Bing, and Cisco), targets unmanaged mobile devices, and features advanced evasion tactics to bypass security measures and multi-factor authentication. The campaign has already distributed over 600 unique phishing PDFs in just three months, with a marked focus on high-value sectors such as Technology, Healthcare, and Financial Services.
Source: Cyble
Critical Cisco ISE Vulnerability Enables Full Remote System Takeover
Cisco has patched a critical vulnerability (CVE-2025-20337, CVSS 10) in its Identity Services Engine (ISE) and Passive Identity Connector, which allows unauthenticated, remote attackers to execute arbitrary code with root privileges. This marks the third maximum-severity ISE flaw in a month, raising serious concerns about the resilience of widely trusted Cisco systems. Exploitation could lead to complete system compromise; organizations are urged to patch immediately.
Source: Bleeping Computer
AI Drives Next-Generation Cyberattacks: Quishing, Deepfakes, and Enhanced Malware
Attackers are increasingly utilizing artificial intelligence to automate and enhance cyberthreats, with tactics ranging from malicious GPT-powered phishing, deepfake-enabled social engineering, to LLM-assisted malware such as the new LameHug family. These AI-driven attacks optimize spear-phishing campaigns, bypass security controls, and craft real-time commands for data theft, making them harder to detect and stop.
Source: ReliaQuest
China-Backed APT Maintained US Army National Guard Access for Nine Months
Chinese state-backed threat group "Salt Typhoon" exfiltrated data from a US Army National Guard network undetected for nearly a year, stealing network configurations and admin credentials with potential lateral movement implications for other government organizations. This incident highlights persistent weaknesses in defending critical infrastructure against advanced nation-state actors.
Source: Bleeping Computer
Malware-as-a-Service Leverages GitHub to Target Ukraine with Stealthy InfoStealers
Security researchers from Cisco Talos revealed a coordinated Malware-as-a-Service (MaaS) campaign distributing Emmenhtal, Amadey, Lumma, and Redline infostealers via rogue GitHub accounts to Ukrainian entities. This operation bypasses standard web filtering and leverages public code repositories for payload delivery, with the potential for rapid global spread and widespread phishing.
Source: Cisco Talos
Record Crypto Thefts in H1 2025 Driven by North Korean and Lazarus Group Attacks
Cryptocurrency thefts exceeded $2 billion in the first half of 2025, already surpassing last year’s tally, according to Chainalysis and other sources. The majority of high-value breaches, including a single $1.5 billion hack, have been attributed to North Korea’s Lazarus Group, underscoring the growing nexus of state-sponsored cybercrime and digital finance.
Source: Bloomberg Cyber
Google Takes Legal Action Against BadBox 2.0 Botnet Operators Infecting 10 Million Devices
Google has filed a lawsuit targeting 25 unnamed individuals behind the BadBox 2.0 botnet, responsible for infecting over 10 million Android devices globally through malicious apps and ad fraud schemes. The case spotlights escalating abuse of Android ecosystems for mass-scale cybercrime and the importance of securing mobile endpoints in both consumer and enterprise environments.
Source: SecurityWeek
You May Also Be Interested In...