Weekly Threat Digest: JUNE 30 to JULY 06, 2025
For a detailed threat digest, download the PDF file here
Summary
HiveForce Labs has identified a surge in cyber threats, with five attacks executed, two vulnerabilities uncovered, and one active adversary exposed in the past week alone highlighting the relentless nature of cyberattacks.
One of the critical vulnerabilities, CVE-2025-6554, is a zero-day flaw in Google Chrome’s V8 JavaScript engine that enables attackers to corrupt memory and potentially execute arbitrary code. Google has confirmed that this bug is being actively exploited in the wild. Another high-severity flaw, CVE-2025-6463, affects the Forminator Forms WordPress plugin (used by over 600,000 websites), allowing unauthenticated attackers to delete arbitrary files from the server due to unsafe file path handling. Users are urged to update or disable the plugin until it’s secured.
On the threat actor front, Latin America is currently being targeted by Blind Eagle, a cybercriminal group deploying banking-themed phishing emails laced with remote access tools like Remcos and AsyncRAT. Simultaneously, a new ransomware variant called DEVMAN, derived from the DragonForce codebase, has surfaced with unique traits and a leak site called Devman’s Place. DEVMAN reflects the evolving complexity of ransomware-as-a-service (RaaS) ecosystems, where operators blur lines between independence and collaboration. These rising threats pose significant and immediate dangers to users worldwide.
Click here to Subscribe to receive our weekly threat digests and alerts directly in your inbox.