Weekly Threat Digest: January 27 to 02 February 2025
For a detailed threat digest, download the PDF file here
Summary
HiveForce Labs recently made several significant discoveries in the realm of cybersecurity threats. In just the past week, seven attacks were executed, and six vulnerabilities were uncovered, highlighting the persistent danger of cyberattacks.
HiveForce Labs identifies critical security threats, including two actively exploited zero-day vulnerabilities. CVE-2025-24085 affects Apple products, allowing malicious apps to escalate privileges on vulnerable devices, posing a significant risk of system compromise. Meanwhile, CVE-2024-40891 targets Zyxel CPE Series devices, which have remained unpatched since July 2024. This flaw has been exploited by botnets like Mirai, raising concerns over large-scale attacks.
Ransomware threats are also escalating. FunkSec, emerging in late 2024, has quickly become a major player, blending AI-driven tools with cybercrime and hacktivism. Their fast-evolving ransomware demands low ransoms but causes widespread disruption. Meanwhile, the Daixin Team continues to target healthcare, government, and enterprise sectors, focusing on VMware ESXi servers. They were recently seen in their June 2024 attack on Dubai Municipality, where they stole 80GB of sensitive data. These growing threats underscore the urgent need for robust security measures, including regular patching, strong authentication, and proactive monitoring.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.