News Roundup
NEWS ROUNDUP – 8th September 2025
Chinese threat actors impersonated a U.S. lawmaker in a spyware campaign, while a ransomware group disrupted operations at Ireland’s K Club. CISA flagged a critical Sitecore CVE under active exploitation. A U.S. bill to extend cyber intel sharing advanced. DFIR teams must prioritise patching, phishing defences, and policy tracking this week.
NEWS ROUNDUP – 6th September 2025
In the past 48 hours, defenders faced urgent patch mandates for Sitecore and SAP S/4HANA exploitation, while Google fixed two Android zero-days. Investigations revealed a Chess.com data breach and GhostRedirector SEO hijacks. Major disruptions hit Jaguar Land Rover, and policy shifts saw U.S. info-sharing reauthorization progress alongside EU and Czech regulatory actions.
NEWS ROUNDUP – 3rd September 2025
Ransomware disrupted Sweden’s municipal IT and Pennsylvania’s Attorney General’s office, while attackers abused Velociraptor and VS Code tunnels for stealthy access. New threats include WhatsApp zero-click exploits, TamperedChef malvertising, Brokewell Android malware, and ScarCruft’s RokRAT espionage. Indian police dismantled trafficking-to-scam pipelines and online fraud rings, underscoring cybercrime’s human dimension alongside technical threats.
NEWS ROUNDUP – 1st September 2025
Ransomware disrupted Sweden’s municipal IT and Pennsylvania’s Attorney General’s office, while attackers abused Velociraptor and VS Code tunnels for stealthy access. New threats include WhatsApp zero-click exploits, TamperedChef malvertising, Brokewell Android malware, and ScarCruft’s RokRAT espionage. Indian police dismantled trafficking-to-scam pipelines and online fraud rings, underscoring cybercrime’s human dimension alongside technical threats.
NEWS ROUNDUP – 29th August 2025
Salesforce OAuth token abuse, cloud-native ransomware, and NetScaler zero-day exploitation dominated the last 48 hours. Investigators tracked PRC router persistence, PlugX delivery, and major breaches at TransUnion and Nevada state services. Policy and law enforcement actions tightened around DPRK fraud and PRC laundering networks, while NIST issued new IoT behavior and control updates.
