Weekly Threat Digest: JUNE 23 to 29, 2025
For a detailed threat digest, download the PDF file here

Summary
HiveForce Labs has recently made significant advancements in identifying cybersecurity threats. Over the past week, detected nine attacks, reported eight vulnerabilities, and identified two active adversaries. These findings underscore the relentless and escalating danger of cyber intrusions.
Recent Citrix NetScaler flaws, CVE-2025-6543 (memory overflow) and CVE-2025-5777 (CitrixBleed 2), pose severe threats like DoS, session hijacking, and MFA bypass. CVE-2025-6543 is actively exploited, CVE-2025-5777 may soon be weaponized. Google patched CVE-2025-2783, a Chrome flaw exploited by TaxOff in Operation ForumTroll. The group uses the Trinper backdoor for data theft and control.
Additionally, APT28 targeted government agencies using spear-phishing via Signal to deploy BEARDSHELL and COVENANT malware. Using fileless techniques and cloud services, they achieved stealthy, persistent access. BERT ransomware, active since March 2025, is a multi-platform threat using REvil code and demanding Bitcoin via Session messenger. Its double-extortion tactics and rapid spread across critical sectors pose a growing risk to global enterprises. These rising threats pose significant and immediate dangers to users worldwide.
Click here to Subscribe to receive our weekly threat digests and alerts directly in your inbox.