Weekly Threat Digest: MAY 26 to JUNE 01, 2025
For a detailed threat digest, download the PDF file here

HiveForce Labs has observed a significant surge in cybersecurity threats, underscoring the growing complexity and frequency of cyber incidents. Over the past week, five major attacks were detected, three critical vulnerabilities were actively exploited, and three threat actor groups were closely monitored, reflecting an alarming escalation in malicious activities.
Among the notable incidents, a sophisticated malware campaign is leveraging AI-generated TikTok videos to lure victims into executing malicious PowerShell commands, cleverly disguised as software activation instructions. Meanwhile, a new Dero cryptocurrency mining operation targets exposed Docker APIs, hijacking containers and transforming them into zombie nodes to silently spread the infection across environments.
In the world of zero-day exploits, Mimo, a financially driven hacking group, rapidly weaponized a critical remote code execution flaw (CVE-2025-32432) in Craft CMS just days after its disclosure in April 2025. Additionally, a severe vulnerability (CVE-2025-47577) in the TI WooCommerce Wishlist WordPress plugin is placing over 100,000 active websites at immediate risk. With no official patch available, we are advising security experts to disable the plugin to mitigate exposure. These escalating threats highlight the increasing sophistication of cyber adversaries and reinforce the urgent need for proactive, resilient cybersecurity measures to combat the rapidly evolving global threat landscape.
Click here to Subscribe to receive our weekly threat digests and alerts directly in your inbox.