Daily Recap, The latest cybersecurity updates highlight a surge in ransomware like HybridPetya leveraging CVE-2024-7344 to bypass UEFI Secure Boot, plus Akira actively exploiting CVE-2024-40766 in SonicWall SSLVPNs. Also noted are ToneShell anti-analysis tricks and AsyncRAT drops, a Panama Ministry breach, and broader patching efforts across DELMIA Apriso, Cisco IOS XR, Samsung Android, and Adobe AV25-583.
#HybridPetya #CVE-2024-40766 #ToneShell #AsyncRAT #PanamaBreaches #DELMIA #IOSXR #SamsungCVE-2025-21043 #CISAProgram #C2PA
#HybridPetya #CVE-2024-40766 #ToneShell #AsyncRAT #PanamaBreaches #DELMIA #IOSXR #SamsungCVE-2025-21043 #CISAProgram #C2PA
Daily Cybersecurity Recap
Ransomware & Malware
- Researchers warn of the HybridPetya bootkit-installer ransomware that can bypass UEFI Secure Boot via CVE-2024-7344 to encrypt systems. â HybridPetya, In Other News
- The Akira gang is actively exploiting CVE-2024-40766 in SonicWall SSLVPNsâauthorities urge immediate patching, MFA and password resets. â Akira Ransom
- New espionage and RAT campaigns identified: fileless EggStreme targets the Philippine military, ToneShell (Mustang Panda) adds anti-analysis tricks in Myanmar operations, and attackers abuse ConnectWise ScreenConnect to drop AsyncRAT. â EggStreme, ToneShell, AsyncRAT
- INC Ransom claims a theft of over 1.5 TB from Panamaâs Ministry of Economy though core systems remain operational. â Panama Breach
Vulnerabilities & Patching
- A critical deserialization flaw CVE-2025-5086 in Dassault Systèmes DELMIA Apriso is being actively exploited and added to CISAâs KEV catalog; organizations are urged to patch now. â DELMIA Flaw, DELMIA Coverage
- Cisco released patches for three high-severity IOS XR flaws affecting image verification, ARP processing and ACLs that could enable RCE or bypasses. â Cisco Patches
- Samsung fixed an actively exploited Android RCE (CVE-2025-21043) and WhatsApp patched a zero-click flaw (CVE-2025-55177) linked to spyware campaigns. â Samsung Fixes
- Adobe published security advisory AV25-583 covering multiple products (Acrobat, After Effects, Premiere Pro, ColdFusion); admins should review and patch. â Adobe Advisory
- CISA outlines plans to modernize the CVE Program with a focus on improving vulnerability data quality and partnerships to strengthen global cyber defense. â CVE Program
- New microarchitectural Spectre-BTI variant VMScape can break cloud VM isolation and leak keys on some AMD Zen and older Intel CPUsâcloud operators should apply mitigations. â VMScape
- Payment vendor KioSoft delayed patching a critical NFC stored-value card flaw that enabled infinite top-ups, exposing weaknesses in RFID systems and vendor response. â KioSoft Hack
Cloud & AI Security
- F5 will acquire CalypsoAI for $180 million to bolster AI security and runtime defenses for enterprise AI deployments. â F5 Acquires
- Security bug in the Cursor AI code editor can enable silent code execution from malicious repositoriesâenable Workspace Trust and audit repos. â Cursor Flaw
- Cloud-native security trends for 2025 emphasize runtime visibility, AI-assisted triage and platform consolidation to secure hybrid environments. â Cloud-Native
- A large NPM supply-chain compromise of packages like ansi-styles and chalk primarily sought cryptojacking rewards and netted only $600, yet propagated rapidly. â NPM Attack
- Google Pixel 10 adds C2PA support to verify AI-generated media provenance, improving content transparency. â Pixel C2PA
- Researchers and vendors offer LLM penâtesting guidance (Adversarial Prompt Exploitation); tune defenses and attend briefings such as todayâs webinar on LLM redâteaming. â LLM Webinar
- The FTC opened inquiries into AI âcompanionâ chatbots for children to assess emotional risks, privacy and COPPA compliance. â FTC AI Probe, FTC Inquiry
Incidents & Breaches
- French regional healthcare agencies reported breaches that exposed patient data via impersonation/phishing tactics and are implementing containment measures. â France Healthcare
- UK train operator LNER notified customers of a breach exposing contact and travel history from a thirdâparty supplier; payment data was not impacted. â LNER Breach
- Former Vastaamo breach perpetrator Aleksanteri Kivimäki was released from custody during appeal proceedings in a highâprofile Finnish extortion case. â Vastaamo Case
- A Memphis man was sentenced to 57 months for stealing and selling unreleased movies, underscoring ongoing digital piracy enforcement. â Movie Seller
Microsoft: Outages & Oversight
- Microsoft is investigating a widespread Exchange Online outage across North America that disrupted email and related services while rolling fixes are deployed. â Exchange Outage
- Microsoft will add malicious link warnings to Teams private chats, rolling out in September and broadly in November 2025 to reduce phishing and malware clicks. â Teams Warnings
- Senator Ron Wyden urged the FTC to investigate Microsoft over alleged âgross cybersecurity negligenceâ tied to ransomware incidents and deprecated crypto defaults (e.g., RC4). â Wyden Accusation, Wyden Probe
Policy & Regulation
- A CISA official urged Congress to renew the Cybersecurity Information Sharing Act (CISA 2015) to avoid disrupting publicâprivate threat intelligence sharing. â CISA Renewal
- California passed a bill requiring browsers to offer an automatic optâout for thirdâparty data sharing to strengthen consumer privacy (awaiting the governorâs signature). â CA Opt-Out
- Switzerlandâs proposed law to force ID collection, retention and encryption backdoors drew criticism as a massâsurveillance risk and prompted privacy firms to relocate infrastructure. â Swiss Privacy
- The UK again delayed introducing the Cyber Security and Resilience Bill (CSRB), slowing regulatory updates amid rising industry incidents. â UK CSRB Delay
- ASEAN adopted a 10âyear action plan to combat cybercrime and online scams through regional cooperation through 2035. â ASEAN Plan
Education & Insider Risk
- The UK ICO warns that student insiders now cause over half of school cyber incidentsâprompting calls for improved technical controls and cultural safeguards in schools. â Student Threats, Student Hackers
Industry Guidance & Training
- New training helps CISOs translate technical risk into boardâlevel language with practical guidance for risk reporting and strategic alignment. â CISO Course