Weekly Threat Digest: JULY 07 to JULY 13 2025
For a detailed threat digest, download the PDF file here

Summary
HiveForce Labs has observed a significant surge in cybersecurity threats, underscoring the growing complexity and frequency of cyber incidents. Over the past week, four major attacks were detected, five critical vulnerabilities were actively exploited, and two threat actor groups were closely monitored, reflecting an alarming escalation in malicious activities.
Among the key developments, Dire Wolf, a sophisticated ransomware group first identified in May 2025, is targeting sectors across 13 countries using double extortion tactics. A newly uncovered botnet campaign, RondoDox, is actively exploiting critical vulnerabilities in TBK DVRs and Four-Faith devices, allowing attackers to compromise systems and repurpose them for malicious operations covertly.
APT36, a Pakistan-based threat group, has resumed cyber-espionage activity against India’s defense sector, this time focusing on Linux systems, particularly those running BOSS Linux. An Initial Access Broker group, Gold Melody, has been linked to a high-impact campaign targeting ASP.NET applications by exploiting leaked machine keys to gain unauthorized access and enable further exploitation. These escalating threats highlight the increasing sophistication of cyber adversaries and reinforce the urgent need for proactive, resilient cybersecurity measures to combat the rapidly evolving global threat landscape.
Click here to Subscribe to receive our weekly threat digests and alerts directly in your inbox.