Monthly Threat Digest JULY 2025
For a detailed threat digest, download the pdf file here

In July, the cybersecurity arena drew significant attention due to the active exploitation of seven zero-day vulnerabilities. Among them, Google Chrome patched a zero-day vulnerability (CVE-2025-6554). It is a critical flaw in Chrome’s V8 engine that allows memory corruption and remote code execution, and was actively exploited in the wild before a patch was released.
During this period, ransomware attacks surged, with variants such as DEVMAN, Dire Wolf, Interlock, GLOBAL, and Bert aggressively targeting victims. Among the key developments, Dire Wolf, a sophisticated ransomware group first identified in May 2025, is targeting sectors across 13 countries using double extortion tactics. Interlock ransomware now leverages a PHP-based RAT delivered via fake CAPTCHA lures and Cloudflare Tunnel, enabling stealthy system access and advanced intrusion techniques.
Concurrently, eleven threat actors have engaged in various campaigns. The financially motivated group Scattered Spider launched a campaign in mid-2025 targeting VMware vSphere environments, using social engineering to infiltrate Active Directory and subsequently exploiting vCenter and ESXi for credential theft and ransomware deployment. In Latin America, the cybercriminal group Blind Eagle is deploying banking-themed phishing emails laced with remote access tools such as Remcos and AsyncRAT. As the cybersecurity landscape evolves, organizations must remain vigilant and proactively address emerging threats.