Weekly Threat Digest: 19 to 25 MAY 2025
For a detailed threat digest, download the PDF file here

HiveForce Labs has observed a significant surge in cybersecurity threats, underscoring the growing complexity and frequency of cyber incidents. Over the past week, fifteen major attacks were detected, ten critical vulnerabilities were actively exploited, and seven threat actor groups were closely monitored, reflecting an alarming escalation in malicious activities.
Among the notable incidents, Operation RoundPress, Russian state-backed hackers APT28 exploited known vulnerabilities in email platforms like Roundcube, Horde, and Zimbra to conduct a covert webmail espionage campaign, compromising sensitive communications. Compounding these risks, Mozilla was forced to issue emergency updates after two critical vulnerabilities in Firefox were discovered to be under active exploitation before their public disclosure.
Adding to the growing list of cyber threats, the Chinese-speaking threat actor UAT-6382 exploited CVE-2025-0994, a zero-day in Trimble Cityworks, enabling remote code execution and deploying malware for persistent access in critical infrastructure. These escalating threats highlight the increasing sophistication of cyber adversaries and reinforce the urgent need for proactive, resilient cybersecurity measures to combat the rapidly evolving global threat landscape.
Subscribe to receive our weekly threat digests and alerts directly in your inbox.