Microsoft extends Windows 10 Extended Security Updates until 2026, providing additional time for users to maintain security features. Recent updates include bug fixes for Windows 10 and improvements to Windows 11, alongside significant data breaches and geopolitical cyber threats highlighting ongoing risks in the cybersecurity landscape. #Windows10ESU #BreachForums #Qilin #SonicWall #Hy-Vee #NorthKorea #APT28
Microsoft Windows Updates
- Microsoft extends Windows 10 Extended Security Updates (ESU) until October 2026, offering free and affordable enrollment options for individuals and businesses to maintain security post EOS in 2025 β Windows 10 Extended Updates, Windows 10 ESU Extension, Windows 10 ESU via Rewards
- Microsoft releases June 2025 preview update KB5061087 for Windows 10 fixing bugs and improves system features, while also addressing update failures on Windows 11 with KB5062324 β Windows 10 KB5061087, Windows 11 Update Fix
Data Breaches & Cybercrime Arrests
- French police arrested several suspects operating the BreachForums hacking forum involved in selling stolen data, striking a blow to major cybercrime marketplaces β BreachForums Arrests, BreachForums Arrests Follow-up
- Mainline Health and Select Medical disclosed data breaches impacting over 100,000 individuals each, with ransomware gang INC claiming responsibility for sensitive patient data theft highlighting persistent healthcare threats β Mainline Health Breach, Healthcare Data Breaches
- A pro-Iranian hacktivist group leaked thousands of personal records from the 2024 Saudi Games, illustrating cyber operations intertwined with geopolitical conflicts in the Middle East β Saudi Games Data Leak
- A large-scale data breach in Paraguay exposed 7.4 million citizensβ records via info-stealing malware infecting government employees, attributed to threat actor Brigada Cyber PMC β Paraguay Infostealer Breach
Ransomware & Malware Campaigns
- A ransomware attack by the Qilin group disrupted UK NHS blood testing services, exposing data of 900K+ individuals and contributing to a patient death, demonstrating severe impacts of cyberattacks on healthcare β NHS Qilin Ransomware
- Threat actors are abusing ConnectWise remote access tools via Authenticode stuffing and distributing a trojanized version of SonicWall NetExtender VPN signed with fake certificates to steal credentials β ConnectWise Malware Abuse, SonicWall NetExtender Trojan, SonicWall & ConnectWise Campaign, NetExtender Credential Theft
- Stormous ransomware group exploited infostealer malware to breach retail giant Hy-Vee, compromising 53GB of internal data and highlighting the role of infostealers in major attacks β Hy-Vee Data Heist
- Hackers are poisoning Google search results related to AI tools to distribute info-stealer malware families like Vidar, Lumma, and Legion Loader through black hat SEO and fake AI websites β AI Tool Search Result Poisoning
- Androxgh0st botnet expanded by exploiting U.S. university servers including UC San Diego with remote code execution and web shells, leveraging legitimate domains for malicious activity β Androxgh0st Botnet Expansion
- An advanced malware campaign targeting WordPress and WooCommerce sites deploys hidden skimmers across 20+ variants to steal credit card and credentials in real-time β WordPress Skimmer Campaign
- North Korea-linked supply chain attack delivered via 35 malicious npm packages exfiltrates data and installs malware like BeaverTail and InvisibleFerret, targeting developers β North Korea npm Attack
Critical Vulnerabilities & Security Patches
- Citrix released emergency patches for actively exploited vulnerabilities including CVE-2025-6543 memory overflow and the CitrixBleed 2 flaw allowing session hijacking in NetScaler ADC and Gateway systems β Citrix Emergency Patches, CitrixBleed 2 Flaw, SAP GUI Vulnerabilities
- A critical remote code execution vulnerability CVE-2025-52562 was found in Performave Convoy KVM server panel allowing unauthenticated attackers to fully compromise servers β Convoy RCE Flaw
- Significant vulnerabilities impact millions of Brother and other vendor printers enabling remote unauthorized access and reconfiguration without authentication β Brother Printer Vulnerabilities
- A new privilege escalation vulnerability (CVE-2025-36537) in TeamViewer Remote Management for Windows allows local users to gain SYSTEM access and delete files, prompting urgent patches β TeamViewer Privilege Escalation
- Xiaomi Mi Connect Service App vulnerability (CVE-2024-45347) allows remote attackers on the same network to control smart devices without user permission β Xiaomi Mi Connect Flaw
- A critical WinRAR vulnerability enables remote code execution via malicious archives; users encouraged to update to version 7.12 Beta 1 or newer to mitigate risks β WinRAR RCE Vulnerability
Phishing & Social Engineering
- A sophisticated phishing campaign impersonating the U.S. Social Security Administration compromised over 2,000 devices via weaponized emails and fake sites, highlighting risks from social engineering β SSA Phishing Campaign
- A coordinated SMS phishing scam impersonating U.S. DMV agencies exploits victimsβ trust to steal personal and financial data, attributed to Chinese threat actors β DMV Phishing Scam
- Trezorβs support platform is abused by phishing attackers sending deceptive emails to steal cryptocurrency seed phrases, urging caution among users β Trezor Phishing Abuse
- A new U.S. visa rule requires applicants to set social media profiles to public for identity verification, raising privacy and security considerations β US Social Media Visa Rule
Geopolitical & Nation-State Threats
- Russian APT28 targets Ukrainian government using malware delivered via Signal messages including backdoors BeardShell and SlimAgent for espionage β APT28 Signal Malware
- Iranian hacktivists conducted DDoS attacks against U.S. organizations following military strikes, part of wider ongoing Middle East cyber conflicts β Iranian Hacktivist DDoS
- The Middle East cyberwar escalates with operations including GPS spoofing, fake alerts, crypto hacks, and IP camera spying, signaling a new era of cyber-kinetic warfare β Middle East Cyberwar
- The U.S. FBI warns ongoing espionage threats by Chinaβs Typhoon groups continue despite Mideast distractions, highlighting persistent strategic cyber risks β China Typhoon Espionage
- APT36 launched advanced phishing against Indian defense personnel using anti-analysis malware and NIC impersonation, demonstrating sophisticated tactical espionage efforts β APT36 Advanced Phishing
Organizational Cyber Incidents
- Glasgow City Council suffered a cyber incident disrupting online services and raising concerns about possible customer data theft from third-party managed servers β Glasgow Cyber Incident
- Security risks arise from guest user permissions in Microsoft Entra ID, allowing attackers to escalate privileges and manipulate tenant policies covertly β Entra Guest User Risk