Cybersecurity News | Daily Recap [02 Jul 2025]

Cybersecurity News | Daily Recap [02 Jul 2025]

This cybersecurity recap highlights major recent incidents, including the Qantas data breach attributed to the Scattered Spider group and the ransomware attack on Deutsche Welthungerhilfe. It underscores ongoing threats from threat actors like Qilin and Aeza Group, as well as emerging vulnerabilities and sophisticated social engineering tactics. #ScatteredSpider #Qilin #AezaGroup #ForminatorVulnerability

Cyberattacks & Breaches

  • Qantas airline confirmed a cyberattack on a third-party contact center platform affecting 6 million customers, attributed to the Scattered Spider cybercriminal group using social engineering โ€“ Qantas Breach, Qantas Data Breach, Qantas Confirmed, Qantas Discloses
  • Spanish authorities arrested two suspects for leaking and selling sensitive data of government officials and journalists using cryptocurrency, linked to far-right Telegram channels โ€“ Spain Data Leak Arrests
  • German charity Deutsche Welthungerhilfe was hit by ransomware, with stolen data offered for sale, but humanitarian operations continue while defenses are reinforced โ€“ Charity Ransomware
  • International Criminal Court detected and contained a sophisticated espionage cyberattack, emphasizing the ongoing risks to global institutions โ€“ ICC Cyberattack
  • Ahold Delhaize US operations disclosed a ransomware attack that exposed personal data of over 2.2 million employees, underlining ransomware risks in retail โ€“ Ahold Delhaize Breach
  • Kelly & Associates Insurance Group revealed a data breach impacting over 550,000 customers, exposing personal and medical information and raising identity theft concerns โ€“ Kelly Benefits Breach
  • Cyberattack on Russian independent media found linked to a US-sanctioned institute using high-risk infrastructure for disinformation and DoS attacks โ€“ Russian Media Attack

Ransomware & Threat Actors

  • Ransomware group Qilin claimed over 86 victims in June, maintaining dominance with high-value targets through Ransomware-as-a-Service operations โ€“ Qilin Ransomware
  • US sanctioned Russian bulletproof hosting company Aeza Group and its affiliates for supporting ransomware and cybercriminal infrastructure used by groups including BianLian, BlackSprut, and RomCom RAT โ€“ Aeza Sanctions 1, Aeza Sanctions 2, Aeza Sanctions 3
  • Threat groups TA829 and UNK_GreenSec share tactics and infrastructure, deploying malware like TransferLoader using compromised MikroTik routers and encrypted C2 communications โ€“ TA829 & UNK_GreenSec

Cryptocurrency & Fraud

  • Over 40 fake crypto wallet extensions impersonating MetaMask and Phantom flooded the Firefox store, stealing seed phrases and data in a campaign linked to Russian-speaking threat actors โ€“ Fake Wallet Extensions
  • Crypto theft losses in H1 2025 have surpassed all 2024 totals due to major breaches like ByBit and Cetus Protocol hacks, emphasizing urgent need for advanced security โ€“ Crypto Loss Surge
  • US DOJ and Microsoft dismantled North Korean cyber operations using stolen US identities to enable remote IT worker scams and funnel cryptocurrency, highlighting sophisticated state-linked cybercrime โ€“ North Korean IT Scams, North Korean ID Theft

Vulnerabilities & Exploits

  • Critical vulnerability CVE-2025-6463 in the Forminator WordPress plugin risks takeover of over 400,000 websites via arbitrary file deletion; patch 1.44.3 is released โ€“ Forminator Vulnerability
  • US CISA warned of multiple exploited vulnerabilities in TeleMessage app exposing credentials and chat logs, urging immediate patching of CVE-2025-47729, CVE-2025-48927, and CVE-2025-48928 โ€“ TeleMessage Flaws
  • A critical remote code execution vulnerability CVE-2025-49596 in Anthropicโ€™s MCP Inspector threatens developer systems with full control, aggravating risks in AI development environments โ€“ Anthropic Vulnerability
  • A new FileFix attack uses saved HTML files to run malicious JScript bypassing Windows Mark of the Web alerts, exploiting social engineering and mshta.exe execution โ€“ FileFix Attack
  • French agency ANSSI exposed Chinese MSS-linked group UNC5174 โ€œHoukenโ€ exploiting Ivanti CSA zero-days and deploying Linux rootkits targeting strategic sectors โ€“ Houken Exposure

Phishing & Social Engineering

  • New phishing campaigns impersonate Microsoft, DocuSign, and PayPal using PDF callbacks, QR codes, and AI-powered VoIP spoofing to steal information in advanced targeted attacks โ€“ Callback Phishing
  • Generative AI tool Vercelโ€™s v0 has been weaponized to rapidly create large-scale fake login pages, lowering entry barriers for phishing attacks โ€“ AI-Powered Phishing
  • Nearly 80% of modern cyber threats mimic legitimate network traffic, driving SOCs to adopt multi-layered Network Detection and Response (NDR) tools for improved threat detection โ€“ Evasive Threats

Microsoft & Windows Updates

  • Microsoft fixed the Windows 11 24H2 update bug that disabled the โ€˜Print to PDFโ€™ feature in KB5060829 preview, with wider rollout planned for July โ€“ Print to PDF Fix
  • Microsoft resolved a DNS misconfiguration issue that blocked delivery of Exchange Online OTP codes, restoring secure access for encrypted emails โ€“ Exchange OTP Fix
  • Microsoft open-sourced the GitHub Copilot Chat extension for VS Code under MIT license, promoting transparency and community AI development โ€“ Copilot Chat Open Source

Security Enhancements & Industry Trends

  • AT&T launched โ€œWireless Lockโ€ to block SIM swap attacks by locking account changes including number porting, reinforcing mobile security โ€“ AT&T Wireless Lock
  • Cybersecurity M&A activity continues strong in June 2025 with 41 deals, contributing to over 400 deals in 2024 amid industry consolidation โ€“ Cybersecurity M&A
  • Article stresses that organizational preparedness and continuous incident response training build muscle memory critical for effective ransomware defense โ€“ Ransomware Response
  • ASEANโ€™s rapid digital growth faces cybersecurity challenges; experts recommend security-by-design, AI threat detection, legal cooperation, and workforce development for resilience โ€“ ASEAN Cybersecurity
  • Insider threat illustrated as a former IT worker was jailed for over seven months after deliberately disrupting his former employerโ€™s network, underscoring access control importance โ€“ Insider Threat Sentenced

Cybersecurity News | Daily Recap โ€“ hendryadrian.com