Weekly Threat Digest: 24 to 30 MARCH 2025
For a detailed threat digest, download the PDF file here

Summary
HiveForce Labs has recently made significant advancements in identifying cybersecurity threats. Over the past week, detected nine attacks, reported four vulnerabilities, and identified three active adversaries. These findings underscore the relentless and escalating danger of cyber intrusions.
One major concern is CVE-2024-27564, an SSRF vulnerability in ChatGPT’s pictureproxy.php, which has been actively exploited in over 10,479 attacks within a week, primarily affecting U.S. financial and government institutions. Meanwhile, VanHelsing, a newly emerged RaaS operation launched on March 7, 2025, leverages double extortion tactics. Its ransom demands reach up to $500,000, and it targets multiple platforms, including Windows, Linux, BSD, ARM, and VMware ESXi.
In addition, UAT-5918, an APT group, is targeting Taiwan to establish long-term intelligence access. It uses web shells and open-source tools for persistence, credential theft, and post-compromise operations. Similarly, the China-linked threat actor Weaver Ant has infiltrated a major Asian telecom provider, relying on web shells and tunneling techniques to maintain access and facilitate long-term espionage. These rising threats pose significant and immediate dangers to users worldwide.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.