Threat Advisories:
July 21, 2025

Weekly Threat Digest : 14 to 20 JULY 2025

For a detailed threat digest, download the PDF file here


HiveForce Labs has recently made significant advancements in identifying cybersecurity threats. Over the past week, detected eight attacks and reported four vulnerabilities. These findings underscore the relentless and escalating danger of cyber intrusions.

Recent, a critical flaw (CVE-2025-47812) in Wing FTP Server allows attackers to execute code via a null byte login exploit, with active attacks and a public PoC emerging just a day after disclosure. CVE-2025-25257 is a critical unauthenticated SQL injection flaw in Fortinet FortiWeb that allows attackers to execute SQL commands and achieve RCE; a public PoC is available, making immediate patching essential.

Additionally, NordDragonScan is a new .NET-based info-stealer spreading via malicious HTA scripts and deceptive links, designed to covertly harvest sensitive data in targeted cyber-espionage attacks. Interlock ransomware now uses a PHP-based RAT via fake CAPTCHA lures and Cloudflare Tunnel, enabling stealthy system access and advanced intrusion tactics. These rising threats pose significant and immediate dangers to users worldwide.


Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs