Weekly Threat Digest: 14 to 20 APRIL 2025
For a detailed threat digest, download the PDF file here

Summary
HiveForce Labs has identified a surge in cyber threats, with nine attacks executed, five vulnerability uncovered, and two active adversaries exposed in the past week alone highlighting the relentless nature of cyberattacks.
HiveForce Labs has uncovered a fresh wave of cyber threats, headlined by two actively exploited zero-day vulnerabilities in Apple products CVE-2025-31200 and CVE-2025-31201 used in a highly targeted and sophisticated attack. Simultaneously, CVE-2025-24054, a Windows flaw that leaks NTLMv2-SSP hashes through malicious .library-ms files, has seen rapid exploitation despite a patch issued on March 11, with threat actors targeting entities in Poland and Romania.
Adding to the growing list of concerns, APT29 has launched a deceptive phishing campaign leading to the deployment of a new malware loader, GRAPELOADER, using DLL side-loading to gain persistence and contact C2 servers. Meanwhile, a new ransomware strain dubbed “DOGE BIG BALLS” a bizarre rebrand of Fog ransomware has emerged, delivered via finance-themed ZIP files. It leverages PowerShell scripting, geolocation, and the old Intel driver bug CVE-2015-2291, and comes with an outrageous ransom note. These fast-evolving threats underscore the critical need for swift patching, vigilant defenses, and cybersecurity awareness.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.