Threat Advisories:
July 29, 2025

Weekly Threat Digest : 21 to 27 JULY 2025

For a detailed threat digest, download the PDF file here


HiveForce Labs has observed a significant surge in cybersecurity threats, underscoring the growing complexity and frequency of cyber incidents. Over the past week, six major attacks were detected, nine critical vulnerabilities were actively exploited, and seven threat actor groups were closely monitored, reflecting an alarming escalation in malicious activities.

Among the most notable threats is CVE-2025-54309, a zero-day vulnerability in CrushFTP, a widely used enterprise file transfer solution. This flaw allows attackers to gain full administrative control via the web interface in deployments that don’t use the DMZ proxy. Another critical zero-day, CVE-2025-53770, is being actively exploited in Microsoft SharePoint Servers, with China-backed groups Linen Typhoon, Violet Typhoon, and Storm-2603 leveraging it to infiltrate vulnerable systems.

Financially motivated and espionage-driven threats are also on the rise. The Greedy Sponge cybercriminal group has been targeting Mexican organizations using tailored variants of the AllaKore RAT to steal financial data and commit fraud. Separately, UNG0901 launched Operation CargoTalon, a cyber-espionage campaign against Russia’s aerospace and defense sector. The attackers use malicious .LNK files to deliver a lightweight implant called EAGLET, enabling stealthy data theft and long-term access. Together, these incidents reflect a global escalation in cyber operations, reinforcing the urgent need for robust, adaptive cybersecurity strategies.

These rising threats represent an immediate and global cybersecurity risk.


Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs