Cybersecurity News Daily Recap highlights sophisticated phishing campaigns abusing trusted platforms like Google Apps Script and Firebase, alongside targeted state-sponsored attacks such as the ConnectWise breach and APT41 espionage operations. Recent developments also include ransomware threats like Qilin, critical vulnerabilities in Apache InLong and Argo CD, and emerging malware like EDDIESTEALER. #Firebase #APT41
Phishing & Social Engineering
- Threat actors are abusing Google Apps Script and Firebase in sophisticated phishing campaigns that leverage trusted platforms to bypass security and steal credentials β Firebase & Apps Script, Apps Script Abuse
- A phishing campaign exploited Nifty.com infrastructure to impersonate businesses and harvest credentials, demonstrating advanced evasion beyond email defenses β Nifty Phishing
- A new browser exploit called Fullscreen Browser-in-the-Middle (BitM) targets Safari by hiding malicious sites in fullscreen mode without warnings, enabling stealthy credential theft β Browser Exploit, Safari BitM
Ransomware & Cybercrime
- The Qilin ransomware gang demanded ransom from Botetourt County Schools after stealing 315 GB of sensitive data, emphasizing ongoing threats to education β Qilin Ransomware
- Australia has mandated certain ransomware victims to report extortion payments to improve threat visibility and tackle underreporting β Australia Ransomware Reporting
- Cybercriminals increasingly exploit AI-generated lures and fake installers to spread ransomware and malware, targeting business and marketing sectors via SEO poisoning and malvertising β AI Malware Campaigns, AI Ransomware
State-Sponsored Attacks & Nation-State Threats
- ConnectWise confirmed a targeted cyberattack by a nation-state actor exploiting a critical CVE-2025-3935 vulnerability in ScreenConnect, affecting a small number of customers; investigations with Mandiant and law enforcement are ongoing β ConnectWise Hack, ConnectWise Cyberattack, ScreenConnect Targeted, ConnectWise Nation-State, ConnectWise Breach, ConnectWise Confirmed Hack
- Chinese hacking group APT41 leveraged Google Calendar as a covert command-and-control channel in a cyberespionage campaign targeting governments, disrupted by Google β APT41 Google Calendar, APT41 TOUGHPROGRESS
- Chinese Earth Lamia group exploits SAP and SQL Server flaws across Asia and Brazil to launch espionage and persistent attacks on various industries β Earth Lamia Attacks, Earth Lamia Targets
- Meta disrupted multiple influence operations from China, Iran, and Romania, which used fake social media personas and AI-generated profiles to manipulate public discourse β Meta Influence Takedown, Meta Influence Ops
- A massive DDoS attack by the Ukrainian βIT Armyβ disrupted internet services for thousands in Moscow, targeting Russian provider ASVT amid ongoing cyber conflict β Moscow DDoS Attack
- Malaysia faces rising cyber threats from state-sponsored and criminal groups targeting critical sectors with ransomware and espionage β Malaysia Threat Report
- The UK Ministry of Defence is investing Β£1 billion in the βDigital Targeting Web,β an AI-driven battlefield system that enhances cyber and electromagnetic operations β UK Digital Targeting
Vulnerabilities & Exploits
- A critical CVE-2025-27522 vulnerability in Apache InLong versions 1.13.0 to 2.1.0 enables remote code execution via unsafe deserialization, with a patch available in version 2.2.0 β Apache InLong RCE, InLong Deserialization
- Argo CD suffers from a critical XSS vulnerability (CVE-2025-47933) that allows full Kubernetes resource manipulation and script injection β Argo CD XSS
- GreyNoise discovered a stealthy malware campaign backdooring over 9,000 ASUS routers via a previously patched command injection vulnerability linked to advanced attackers β ASUS Router Backdoors
- A new Windows RAT uses corrupted DOS and PE headers to evade detection for weeks, enabling persistent remote access via TLS-encrypted C2 communication β Windows RAT Evasion
Cybersecurity & Technology Developments
- MITRE and the Post-Quantum Cryptography Coalition released a comprehensive roadmap guiding organizations on transitioning to quantum-safe cryptography to counter emerging quantum threats β Post-Quantum Roadmap
- Mozilla Firefox 139 introduces new tab customization, translation improvements, and multiple security fixes, followed by a quick 139.0.1 update addressing graphical glitches on NVIDIA GPUs β Firefox 139, Firefox 139.0.1 Patch
- Microsoft Authenticator plans to retire its password autofill feature by August 2025, advising users to export passwords or switch to Microsoft Edgeβs autofill to avoid access disruption β Microsoft Authenticator Update
- Unbound raised $4 million in seed funding to enhance its AI security platform that protects data and controls access as organizations adopt generative AI tools β Unbound Funding
- MultiCare Health System improved healthcare delivery and cybersecurity by implementing identity-based microsegmentation, fostering collaboration and secure digital transformation β Healthcare Cybersecurity
- Attack Surface Management (ASM) tools like Sprocket ASM help organizations continuously map their external attack surface, increasing resilience by preventing unknown vulnerabilities from being exploited β Attack Surface Management
Sanctions & Cybercrime Infrastructure
- The US Treasury Department sanctioned Philippine firm Funnull Technology Inc. and administrator Liu Lizhi for enabling crypto scams causing over $200 million in losses via infrastructure laundering and cloud-enabled fraud β Funnull Sanctions SW, Funnull Sanctions THN, Funnull Sanctions Record, Funnull Sanctions BC
Cyber Incidents
- The Victoriaβs Secret website went offline following a security incident suspected to be linked to the Scattered Spider group and their deployment of DragonForce ransomware amid rising retail sector attacks β Victoriaβs Secret Incident
Malware Developments
- A new Rust-based info stealer called EDDIESTEALER spreads via fake CAPTCHA pages (ClickFix technique), stealing browser data with sophisticated evasion methods β EDDIESTEALER Malware