Hacker facing laptop displaying code surrounded by floating shields, locks, cloud, world map, and envelopes

Daily Dose of Cybersecurity News - August 15, 2025

Plex Urges Immediate Update to Address Security Vulnerability

High

What happened

Plex identified a security vulnerability in Plex Media Server versions 1.41.7.x to 1.42.0.x and released an update to address the issue. Users running affected versions have been notified to update their software immediately.

Who is affected

Users operating Plex Media Server versions 1.41.7.x to 1.42.0.x are impacted by this vulnerability.

Why it matters

Exploitation of this vulnerability could compromise the security and functionality of the media server, potentially leading to unauthorized access or data breaches.

How it could have been prevented

Regularly updating software to the latest versions and promptly applying security patches can mitigate such vulnerabilities.

Relevant professional terms

Vulnerability
A weakness in a system that can be exploited to gain unauthorized access or cause harm.
Patch
A software update designed to fix vulnerabilities or improve functionality.

Recommended reading: Plex Security Update Announcement

US Sanctions Grinex Crypto-Exchange, Successor to Garantex

High

What happened

The U.S. Department of the Treasury has imposed sanctions on Grinex, a cryptocurrency exchange identified as the successor to the previously sanctioned Russian exchange Garantex. Grinex was established shortly after U.S. authorities seized Garantex's domains in March 2025 due to its involvement in processing illicit transactions and facilitating money laundering for cybercriminals.

Who is affected

Entities and individuals utilizing Grinex for cryptocurrency transactions are directly impacted by these sanctions. Additionally, organizations monitoring financial transactions for compliance purposes should be aware of Grinex's designation.

Why it matters

The sanctioning of Grinex underscores the U.S. government's commitment to disrupting financial platforms that facilitate illicit activities, including money laundering and cybercrime. This action serves as a warning to other entities attempting to circumvent sanctions by rebranding or establishing successor platforms.

How it could have been prevented

Implementing stringent regulatory oversight and continuous monitoring of cryptocurrency exchanges can help identify and prevent the emergence of successor entities designed to circumvent sanctions. Enhanced international cooperation is also crucial in addressing such evasive tactics.

Relevant professional terms

Sanctions
Penalties or restrictive measures imposed by one or more countries against a targeted country, entity, or individual to influence behavior or policies.
Money Laundering
The process of concealing the origins of illegally obtained money, typically by means of transfers involving foreign banks or legitimate businesses.

Recommended reading: US Seizes Domain of Garantex Crypto Exchange Used by Ransomware Gangs

Crypto24 Ransomware Employs Custom EDR Evasion Tools to Target Large Organizations

High

What happened

The Crypto24 ransomware group has been targeting large organizations by utilizing custom utilities designed to evade Endpoint Detection and Response (EDR) systems, exfiltrate data, and encrypt files.

Who is affected

High-value organizations in the finance, manufacturing, entertainment, and technology sectors across the United States, Europe, and Asia have been impacted.

Why it matters

The use of sophisticated EDR evasion techniques by Crypto24 indicates a significant evolution in ransomware tactics, posing increased risks to organizations' data security and operational continuity.

How it could have been prevented

Implementing multi-factor authentication, regularly updating and patching systems, and conducting continuous monitoring for unusual activities can help mitigate such attacks.

Relevant professional terms

Endpoint Detection and Response (EDR)
Security solutions that monitor end-user devices to detect and respond to cyber threats.
Data Exfiltration
Unauthorized transfer of data from a computer or network.

Recommended reading: New "Bring Your Own Installer" EDR Bypass Used in Ransomware Attack

Pro-Russian Hackers Compromise Norwegian Dam Control Systems

High

What happened

In April 2025, pro-Russian hackers infiltrated the digital control systems of the Bremanger dam in Norway, remotely opening outflow valves and releasing approximately 7.2 million liters of water over a four-hour period.

Who is affected

The Norwegian Police Security Service (PST) and the National Criminal Investigation Service (Kripos) are investigating the incident, which targeted Norway's critical infrastructure.

Why it matters

This cyberattack demonstrates the vulnerability of critical infrastructure to remote cyber intrusions, highlighting the potential for significant disruptions and the need for enhanced cybersecurity measures.

How it could have been prevented

Implementing robust network segmentation, regular security audits, and multi-factor authentication could have mitigated the risk of unauthorized access to critical control systems.

Relevant professional terms

Network Segmentation
Dividing a computer network into smaller, isolated segments to enhance security and performance.
Multi-Factor Authentication (MFA)
A security process requiring multiple forms of verification to grant access to a system.

Recommended reading: CISA: Critical Infrastructure Security

Phishing Campaign Exploits Unicode Character to Mimic Booking.com

High

What happened

Cybercriminals are conducting a phishing campaign that uses the Japanese hiragana character "ん" to create URLs resembling legitimate Booking.com links, leading users to malicious websites that distribute malware.

Who is affected

Users and organizations interacting with Booking.com, particularly those in the hospitality industry, are at risk of being targeted by this phishing scheme.

Why it matters

This attack exploits visual similarities between characters to deceive users, potentially leading to unauthorized access, data breaches, and malware infections within affected systems.

How it could have been prevented

Implementing email filtering solutions to detect and block phishing attempts, educating users on identifying suspicious URLs, and maintaining up-to-date security software can mitigate such threats.

Relevant professional terms

Homoglyph
A character that appears similar to another character but belongs to a different script or character set, often used in phishing attacks to deceive users.
Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information or downloading malicious software.

Recommended reading: BleepingComputer