April 30, 2025

Weekly Threat Digest: 21 to 27 APRIL 2025

For a detailed threat digest, download the PDF file here


Summary

HiveForce Labs has observed a significant surge in cybersecurity threats, underscoring the growing complexity and frequency of cyber incidents. Over the past week, fifteen major attacks were detected, five critical vulnerabilities were actively exploited, and four threat actor groups were closely monitored, reflecting an alarming escalation in malicious activities.

A newly uncovered flaw, CVE-2025-32433, in the Erlang/OTP SSH server allows unauthenticated remote code execution, exposing systems to complete takeover. Meanwhile, North Korea-linked Kimsuky is targeting South Korea’s critical sectors, leveraging old but effective vulnerabilities like CVE-2017-11882 and CVE-2019-0708 (BlueKeep) to breach networks.

Adding to the growing list of cyber threats, an active exploit, CVE-2025-42599, affecting Active! mail by QUALITIA CO., LTD., puts educational and enterprise email servers at serious risk. China-based Billbug is ramping up cyber espionage campaigns against Southeast Asian government and infrastructure systems. These developments spotlight the rising sophistication of cyber adversaries and reinforce the urgent need for agile, proactive cybersecurity defenses to navigate an increasingly hostile digital landscape.


Subscribe to receive our weekly threat digests and newsletters directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo