Weekly Threat Digest: JUNE 16 to 22 2025
For a detailed threat digest, download the PDF file here

Summary
HiveForce Labs has recently made significant advancements in identifying cybersecurity threats. Over the past week, detected eleven attacks, reported four vulnerabilities, and identified three active adversaries. These findings underscore the relentless and escalating danger of cyber intrusions.
Gunra ransomware, written in C/C++ and based on leaked Conti code, emerged in April 2025. It has since compromised 13 high-profile organizations using aggressive double-extortion tactics. CVE-2025-3248 is a critical RCE flaw in Langflow due to unsafe use of Python’s exec(), allowing unauthenticated code execution. It’s actively exploited, including by the Flodrix botnet, targeting exposed instances.
Additionally, PylangGhost, a Python-based RAT used by the North Korea-linked group Famous Chollima, targets crypto job seekers. The campaign blends social engineering with technical skill to infiltrate the high-value crypto sector. Katz Stealer, a new malware-as-a-service, enables easy credential theft via phishing and fake software. It hides in images, abuses trusted tools, and steals data from browsers, crypto wallets, and apps like Discord. These rising threats pose significant and immediate dangers to users worldwide.
Click here to Subscribe to receive our weekly threat digests and alerts directly in your inbox.