Threat Advisories:
New Report Critical Threat Research : The Iranian Cyber War Intensifies! Download the Report
November 26, 2025

Weekly Threat Digest : 17th NOVEMBER to 23rd NOVEMBER 2025

HiveForce Labs

HiveForce Labs

For a detailed threat digest, download the PDF file here




HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the increasing complexity and frequency of global cyber incidents. Over the past week, four major attacks were detected, seven critical vulnerabilities were publicly disclosed, and one active threat actor group was monitored, signaling a concerning escalation in malicious activity.

Five zero-day vulnerabilities were tracked and confirmed as exploited in the wild: CVE-2025-64446 (Fortinet FortiWeb), CVE-2025-20337 (Cisco Identity Services Engine), CVE-2025-13223 (Google Chrome), CVE-2025-58034 (Fortinet FortiWeb), and CVE-2025-5777, known as Citrix Bleed 2. The confirmation that Citrix Bleed 2 was abused before disclosure amplifies its overall risk impact.

Dragon Breath (APT-Q-27) continues a rapid, high-volume campaign using multi-stage loaders, brand imitation, and disposable domains to distribute modified Gh0st RAT variants to Chinese-speaking users. Current activity clusters under Campaign Trio and Campaign Chorus.

Eternidade Stealer expands Brazil’s WhatsApp-centered cybercrime landscape, underscoring the need for disciplined security updates and sustained monitoring in the face of fast-evolving attack methodologies.



Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo