Cyber Security Week in Review: August 29, 2025
In brief: FreePBX zero-day, Citrix releases updates to fix an actively exploited flaw, the Salt Typhoon APT officially linked to Chinese companies, and more.
In brief: FreePBX zero-day, Citrix releases updates to fix an actively exploited flaw, the Salt Typhoon APT officially linked to Chinese companies, and more.
Using known flaws, attackers gained access to networks, altered security settings, created covert tunnels, and deployed custom tools to steal communications data.
Hackers are abusing ScreenConnect to launch follow-up attacks, such as stealing accounts and spreading phishing emails across organizations.
PromptLock dynamically crafts its attack logic using hard-coded prompts fed into the AI model.
There are no workarounds, so users are strongly advised to upgrade immediately.
The attackers were focused on harvesting credentials, specifically searching for AWS access keys, passwords, and Snowflake tokens.
Unlike typical phishing attacks, the threat actors behind ZipLine initiate contact through companies’ public “Contact Us” forms.
The files install UpCrypter, which helps hackers deploy RATs like PureHVNC, DCRat, and Babylon RAT.
Nearly 1,971 unique IP addresses were involved in what appears to be a coordinated reconnaissance campaign.
The attackers hijack web traffic by manipulating captive portal behavior to deliver the Staticplugin malware downloader.
Showing elements 441 - 450