July 9, 2025

Weekly Threat Digest: JUNE 30 to JULY 06, 2025

For a detailed threat digestdownload the PDF file here

Summary

HiveForce Labs has identified a surge in cyber threats, with five attacks executed, two vulnerabilities uncovered, and one active adversary exposed in the past week alone highlighting the relentless nature of cyberattacks.

One of the critical vulnerabilities, CVE-2025-6554, is a zero-day flaw in Google Chrome’s V8 JavaScript engine that enables attackers to corrupt memory and potentially execute arbitrary code. Google has confirmed that this bug is being actively exploited in the wild. Another high-severity flaw, CVE-2025-6463, affects the Forminator Forms WordPress plugin (used by over 600,000 websites), allowing unauthenticated attackers to delete arbitrary files from the server due to unsafe file path handling. Users are urged to update or disable the plugin until it’s secured.

On the threat actor front, Latin America is currently being targeted by Blind Eagle, a cybercriminal group deploying banking-themed phishing emails laced with remote access tools like Remcos and AsyncRAT. Simultaneously, a new ransomware variant called DEVMAN, derived from the DragonForce codebase, has surfaced with unique traits and a leak site called Devman’s Place. DEVMAN reflects the evolving complexity of ransomware-as-a-service (RaaS) ecosystems, where operators blur lines between independence and collaboration. These rising threats pose significant and immediate dangers to users worldwide.


Click here to Subscribe to receive our weekly threat digests and alerts directly in your inbox.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs