Weekly Threat Digest : 12 to 15 MAY 2025
For a detailed threat digest, download the PDF file here

HiveForce Labs has made significant advancements in identifying cybersecurity threats. Over the past week, the team detected seven attacks, reported thirteen vulnerabilities, and identified two active adversaries—highlighting the relentless and escalating danger of cyber intrusions.
Ivanti patched two critical zero-day vulnerabilities in Endpoint Manager Mobile, enabling remote code execution and authentication bypass. Meanwhile, CVE-2025-4664, a medium-severity Chrome zero-day, leaks cross-origin data through crafted web pages, exposing sensitive tokens. Exploitation requires user interaction—update Chrome immediately.
APT36 has escalated its cyber-espionage efforts against India, using geopolitical tensions to launch precision phishing attacks. Their campaigns combine advanced malware with psychological manipulation. In parallel, CVE-2025-4632, a critical path traversal vulnerability in Samsung MagicINFO 9 Server, is being actively exploited to gain system access and deploy the Mirai botnet.
These rising threats represent an immediate and global cybersecurity risk.
Subscribe to receive our weekly threat digests and alerts directly in your inbox.