January 28, 2025

Weekly Threat Digest: 20 to 26 January 2025

For a detailed threat digest, download the PDF file here


Summary

HiveForce Labs has recently made significant advancements in identifying cybersecurity threats. Over the past week, detected three attacks, reported seven vulnerabilities, and identified five active adversaries. These findings underscore the relentless and escalating danger of cyber intrusions.

Additionally, the Russian threat actor Star Blizzard has launched a new spear-phishing campaign, using WhatsApp group invitations as lures to compromise accounts, marking a shift in their tactics. CVE-2024-55591, a zero-day in FortiOS and FortiProxy, allows attackers to bypass authentication and gain super-admin access.

Furthermore, this week, Ransomware gangs STAC5143 and STAC5777 combine email bombing with Microsoft Teams impersonation, posing as IT support to exploit default settings, gain remote access, and deploy malware and ransomware. These rising threats pose significant and immediate dangers to users worldwide.

Subscribe to receive our weekly threat digests and newsletters directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo