Monthly Threat Digest MAY 2025
For a detailed threat digest, download the pdf file here

In May, the cybersecurity landscape saw heightened activity with the exploitation of 27 zero-day vulnerabilities. One of the most critical among them was CVE-2025-31324 a flaw in SAP NetWeaver that is being actively exploited to drop web shells and execute malicious code on vulnerable servers. Several cybercriminal groups, including the Russian ransomware gang BianLian and the operators behind RansomExx, have shown significant interest in leveraging this vulnerability.
Ransomware activity surged during the same period, with threat actors deploying aggressive variants such as DragonForce, Agenda, Interlock, Nitrogen, Qilin, BianLian, and RansomExx. As these attacks become more sophisticated, organizations are urged to strengthen their defenses. This includes implementing robust backup and disaster recovery plans, alongside employee training programs focused on recognizing and mitigating phishing attempts.
In parallel, Operation RoundPress a stealthy espionage campaign conducted by Russian state-sponsored group APT28 targeted webmail platforms including Roundcube, Horde, and Zimbra. By exploiting unpatched vulnerabilities, the attackers gained unauthorized access to communications. This operation underscores the risks of outdated webmail infrastructure, where even a single missed patch can lead to serious security breaches.
Moreover, at least 15 known threat actors were active throughout May, each conducting various cyber campaigns. Notably, Void Blizzard a Russian-backed espionage group operational since 2024 continued its relentless targeting of NATO members, Ukraine, and sectors such as defense, aviation, and government. Rather than relying on advanced exploits, Void Blizzard primarily leverages stolen credentials to breach systems, highlighting the persistent threat posed by credential theft. As the threat landscape continues to evolve, organizations must remain vigilant, prioritize patch management, and adopt proactive threat detection and response strategies to stay ahead of emerging threats.
Subscribe to keep up on a weekly basis with our weekly threat digests and newsletters.