May 20, 2025

Weekly Threat Digest : 12 to 15 MAY 2025

For a detailed threat digest, download the PDF file here


HiveForce Labs has made significant advancements in identifying cybersecurity threats. Over the past week, the team detected seven attacks, reported thirteen vulnerabilities, and identified two active adversaries—highlighting the relentless and escalating danger of cyber intrusions.

Ivanti patched two critical zero-day vulnerabilities in Endpoint Manager Mobile, enabling remote code execution and authentication bypass. Meanwhile, CVE-2025-4664, a medium-severity Chrome zero-day, leaks cross-origin data through crafted web pages, exposing sensitive tokens. Exploitation requires user interaction—update Chrome immediately.

APT36 has escalated its cyber-espionage efforts against India, using geopolitical tensions to launch precision phishing attacks. Their campaigns combine advanced malware with psychological manipulation. In parallel, CVE-2025-4632, a critical path traversal vulnerability in Samsung MagicINFO 9 Server, is being actively exploited to gain system access and deploy the Mirai botnet.

These rising threats represent an immediate and global cybersecurity risk.


Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo