The Week in Vulnerabilities: 717 New Cybersecurity Flaws Reported! 

Cyble tracked 717 new vulnerabilities from July 30–Aug 5, 2025, including 222 with public PoCs, 17 in EOL products, one zero-day, and multiple exploits traded on underground forums. High-impact flaws affect vendors and products such as Trend Micro Apex One, D-Link, Microsoft SharePoint, Adobe AEM, SonicWall SMA, and Google/Apple browser engines. #TrendMicroApexOne #D-Link #CVE-2025-53770 #CVE-2025-54253

Read More
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender

Akira ransomware exploits legitimate Intel CPU tuning drivers, specifically ‘rwdrv.sys’ and ‘hlpdrv.sys,’ to disable Microsoft Defender and gain kernel-level access. This technique, part of a Bring Your Own Vulnerable Driver (BYOVD) attack, has been recurrent since July 2025 and is used to evade security tools during attacks, including those on SonicWall SSLVPNs. #AkiraRansomware #BYOVD

Read More
PyLangGhost RAT: Rising Data Stealer from Lazarus Group Targeting Finance and Technology 

North Korean Lazarus subgroup Famous Chollima has developed PyLangGhost RAT, a Python-based remote access trojan targeting technology, finance, and cryptocurrency sectors through fake job interviews and social engineering. The malware steals browser-stored credentials and cryptocurrency wallet data by exploiting privilege escalation and sophisticated decryption methods. #PyLangGhostRAT #FamousChollima #LazarusGroup #GoLangGhostRAT…

Read More

The Bumblebee malware campaign used trojanized IT management tools distributed via SEO poisoning to gain initial access, ultimately leading to Akira ransomware deployment in July 2025. Multiple organizations were affected, with attackers leveraging privileged IT accounts for lateral movement, credential dumping, and data exfiltration. #Bumblebee #AkiraRansomware #SEOpoisoning #ManageEngineOpManager

Read More
CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization

CISA and USCG conducted a proactive hunt engagement at a U.S. critical infrastructure organization, finding no malicious activity but identifying significant cybersecurity risks including shared local admin credentials and insufficient network segmentation between IT and OT environments. The advisory provides detailed recommendations and mitigations to improve cybersecurity posture, aligning with CISA,…

Read More
Unmasking Interlock Group’s Evolving Malware Arsenal

The eSentire Threat Response Unit (TRU) uncovered a sophisticated multi-stage attack by the Interlock Group ransomware gang using PHP backdoors, PowerShell, and LOLBins for system reconnaissance and payload deployment. They provided detailed analysis, Python scripts for detection, and guidance to enhance threat hunting and incident response efforts. #InterlockGroup #InterlockRAT #ClickFix

Read More
CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization

Scattered Spider is a cybercriminal group that targets large companies using sophisticated social engineering techniques, malware, and ransomware such as DragonForce to exfiltrate data and encrypt systems for extortion. This advisory outlines the group’s evolving tactics, techniques, and procedures (TTPs), and provides mitigation strategies recommended by multiple international cybersecurity organizations. #ScatteredSpider…

Read More