IT Security Weekend Catch Up – July 19, 2025

Comments

19.07.2025 | 13:07

IT Security Weekend Catch Up – July 19, 2025
avatar

badcyber

comments

IT Security Weekend Catch Up – July 19, 2025

Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!

For the less technical

  1. Doxing: When private data becomes a Russian weapon
  2. Global operation targets NoName057(16) pro-Russian cybercrime network
  3. Armenian national extradited to the United States faces federal charges for ransomware extortion conspiracy
  4. Operation Overload’s underwhelming influence and evolving tactics
  5. Digital occupation: Pro-Russian bot networks target Ukraine’s occupied territories on Telegram
  6. How China’s patriotic ‘Honkers’ became the nation’s elite cyberspies
  7. Cloudflare starts blocking pirate sites for UK users – that’s a pretty big deal
  8. Steam introduces vague new rules banning 'certain kinds of adult content' to appease credit card companies

For the more technical

  1. Beyond the surface – Digging into CVE-2024-10864 & CVE-2024-10865 in NetIQ Advanced Authentication
  2. Pre-auth SQL injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
  3. GPUHammer: Rowhammer attacks on GPU memories are practical
  4. Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot
  5. Malware identified in attacks exploiting Ivanti Connect Secure vulnerabilities
  6. Ongoing SonicWall Secure Mobile Access (SMA) exploitation campaign using the Overstep backdoor
  7. PoisonSeed downgrading FIDO key authentications to ‘fetch’ user accounts
  8. FileFix: The new social engineering attack building on ClickFix tested in the wild
  9. KongTuke FileFix leads to new Interlock RAT variant
  10. Fix the click: Preventing the ClickFix attack vector
  11. Phishing for Gemini
  12. Tracking protestware spread: 28 npm packages affected by payload targeting Russian-language users
  13. June 2025 Infostealer Trend Report
  14. Signed and stealing: uncovering new insights on Odyssey infostealer
  15. Katz stealer: Powerful MaaS on the prowl for credentials and crypto assets
  16. Unmasking AsyncRAT: Navigating the labyrinth of forks
  17. Threat analysis: SquidLoader - still swimming under the radar
  18. From a Teams call to a ransomware threat: Matanbuchus 3.0 MaaS levels up
  19. KAWA4096’s ransomware Tide: Rising threat with borrowed styles
  20. Global Group: Emerging Ransomware-as-a-Service, supporting AI driven negotiation and mobile control panel for their affiliates
  21. BlackSuit: A hybrid approach with data exfiltration and encryption
  22. Konfety returns: Classic mobile threat with new evasion techniques
  23. Evolving tactics of Slow Tempest: A deep dive into advanced malware techniques
  24. The cost of a call: From voice phishing to data extortion
  25. UNG0002: Regional threat operations tracked across multiple Asian jurisdictions
  26. Phish and chips: China-aligned espionage actors ramp up Taiwan semiconductor industry targeting
  27. Behind the clouds: Attackers targeting governments in Southeast Asia implement novel covert C2 communication

Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.


Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy! For the less technical Doxing: When private data becomes a Russian weapon Global operation targets NoName057(16) pro-Rus 2025-07-19T13:07:41+02:00

Comments