Threat Advisories:
Highlights of Our CISO Dinner
Upgrading struggling vulnerability management programs to Threat Exposure Management, with Host, CISO Al Lindseth formerly from Plains All American Pipeline and PWC - 6 minute podcast
0:00
0:00
👥 Play Count: Loading...
November 4, 2025

Weekly Threat Digest : 27th OCTOBER to 2nd NOVEMBER 2025

HiveForce Labs

HiveForce Labs

For a detailed threat digest, download the PDF file here



HiveForce Labs has reported a striking surge in global cyber threats, underscoring how attacks are not only growing in number but also in complexity. In just one week, we detected seven major attacks, tracked four active threat actor groups, and confirmed the active exploitation of four vulnerabilities. This rapid escalation highlights an increasingly volatile landscape where attackers relentlessly probe for weak points, from exposed systems to minor misconfigurations, to secure a foothold in targeted environments.

Among the most critical findings, attackers are actively exploiting three major flaws, CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972, in the GutenKit and Hunk Companion WordPress plugins, enabling full site compromise through malicious plugin installations and remote code execution. Meanwhile, Qilin (Agenda) ransomware has emerged as one of 2025’s most aggressive operations, amassing over 700 victims, including nearly 200 in October alone. This surge reflects an alarming rise in the scale and tempo of ransomware activity, with threat actors accelerating their attacks across industries and geographies.

Nation-states and financially motivated actors are also intensifying their operations. Transparent Tribe (APT36) has been targeting Indian military and government entities using spear-phishing emails to deploy DeskRAT, a Golang-based remote access tool tailored for Linux systems. In parallel, CL-CRI-1032’s Jingle Thief campaign exploits Microsoft 365 environments for large-scale gift card fraud via phishing and smishing lures. Elsewhere, SideWinder is spearheading a stealthy espionage campaign across Asia, using fake Adobe Reader updates to deliver ClickOnce-based payloads, while Vietnam’s UNC6229 deceives marketing professionals through fraudulent job listings. Collectively, these operations serve as a stark reminder that cyber resilience now hinges on proactive defense, timely patching, and unwavering vigilance in an era of relentless digital warfare.



Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo