A coordinated campaign by Russia-linked APT "Secret Blizzard" (aka Turla) has been uncovered, targeting foreign embassies in Moscow using advanced adversary-in-the-middle (AiTM) tactics at the internet service provider level. Microsoft researchers revealed that the attackers are implanting custom ApolloShadow malware through ISP-level manipulation, allowing deep access to sensitive diplomatic communications and device traffic.
Source: Microsoft MMPC
Surge in Vulnerabilities: 1 in 5 Exploited Within First Week of Disclosure
Cyble researchers reported that out of 737 vulnerabilities tracked last week, more than 145 already have public exploits, marking a nearly 21% exploitation rate within the first week. Critical vulnerabilities like those in Node-SAML, Pandora FMS, SonicWall SMA, and Honeywell Experion PKS highlight the urgent need for robust, risk-based vulnerability management as attackers accelerate their exploitation timelines.
Source: Cyble
Ransomware Attackers Move Beyond Encryption; Physical Threats and Data Extortion Surge
Q2 2025 ransomware trends reveal a significant shift as threat actors increasingly abandon encryption in favor of multi-layered extortion—stealing and leaking data to exert payment pressure. Groups like Qilin are deploying new tools, while a worrying trend sees gangs threatening physical harm to executives and families in up to 46% of reported US ransomware incidents, signaling an unprecedented escalation in criminal tactics.
Source: Checkpoint Blog
AI-Powered Attacks, LLM Abuse, and the 'Man-in-the-Prompt' Threat to Enterprise Security
Malicious actors increasingly leverage generative AI and large language models (LLMs) to lower entry barriers for advanced cyberattacks, including social engineering and deepfake-driven scams. A recent disclosure by LayerX demonstrated "Man-in-the-Prompt" attacks, using browser extensions to silently exfiltrate data from AI chatbots like ChatGPT and Gemini, making LLM deployments a potent new attack surface for organizations.
Source: Security Week
Record-Breaking $1 Million Prize for WhatsApp Exploits at Pwn2Own Ireland
The upcoming Pwn2Own Ireland 2025 hacking contest offers an unprecedented $1 million reward for zero-click WhatsApp exploits that achieve remote code execution. Co-sponsored by Meta, the event also expands bounty categories for messaging apps, smartphones, wearables, and IoT devices, aiming to uncover critical vulnerabilities that could impact billions of global users.
Source: ZeroDayInitiative
CISA Launches Open-Source Thorium Platform for Automated Malware and Forensic Analysis
The US Cybersecurity and Infrastructure Security Agency (CISA) has announced the public release of Thorium, a scalable, open-source platform to enhance automated malware analysis and forensics. Built in collaboration with Sandia National Laboratories, Thorium is aimed at accelerating incident response and analysis workflows for defenders in government and the private sector alike.
Source: Bleeping Computer
Critical Zero-Day Vulnerability in Alone WordPress Theme Under Active Exploit
Attackers are actively exploiting CVE-2025-5394, a severe zero-day (CVSS 9.8) in the Alone WordPress theme, to hijack vulnerable sites via remote plugin installation. The ongoing campaign underscores persistent risks to web infrastructure, especially for nonprofit and charity organizations relying on WordPress for their digital platforms. Immediate patching or mitigation is advised.
Source: Security Affairs
You May Also Be Interested In...
Phishing and Account Compromise Still Top Initial Access VectorsNorth Korean Malware Campaign Targets Open-Source Repos
Senate Seeks National Strategy for Quantum-Safe Encryption