April 23, 2025

Weekly Threat Digest: 14 to 20 APRIL 2025



For a detailed threat digest, download the PDF file here


Summary

HiveForce Labs has identified a surge in cyber threats, with nine attacks executed, five vulnerability uncovered, and two active adversaries exposed in the past week alone highlighting the relentless nature of cyberattacks.

HiveForce Labs has uncovered a fresh wave of cyber threats, headlined by two actively exploited zero-day vulnerabilities in Apple products CVE-2025-31200 and CVE-2025-31201 used in a highly targeted and sophisticated attack. Simultaneously, CVE-2025-24054, a Windows flaw that leaks NTLMv2-SSP hashes through malicious .library-ms files, has seen rapid exploitation despite a patch issued on March 11, with threat actors targeting entities in Poland and Romania.

Adding to the growing list of concerns, APT29 has launched a deceptive phishing campaign leading to the deployment of a new malware loader, GRAPELOADER, using DLL side-loading to gain persistence and contact C2 servers. Meanwhile, a new ransomware strain dubbed “DOGE BIG BALLS” a bizarre rebrand of Fog ransomware has emerged, delivered via finance-themed ZIP files. It leverages PowerShell scripting, geolocation, and the old Intel driver bug CVE-2015-2291, and comes with an outrageous ransom note. These fast-evolving threats underscore the critical need for swift patching, vigilant defenses, and cybersecurity awareness.


Subscribe to receive our weekly threat digests and newsletters directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo