Large team around central tablet with data streams surrounded by shields, locks, warning icons, and malware

Daily Dose of Cybersecurity News - August 16, 2025

Mobile Phishers Exploit Brokerage Accounts in 'Ramp and Dump' Scheme

High

What happened

Cybercriminals are using sophisticated phishing kits to compromise brokerage accounts, executing coordinated trades to manipulate stock prices in a scheme known as 'ramp and dump'.

Who is affected

Customers of brokerage services are targeted, with their compromised accounts used to artificially inflate stock prices.

Why it matters

This scheme can lead to significant financial losses for investors and undermine trust in financial markets.

How it could have been prevented

Implementing multi-factor authentication beyond one-time passcodes and educating users on recognizing phishing attempts can mitigate such attacks.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to steal sensitive information.
Multi-Factor Authentication (MFA)
A security process requiring multiple forms of verification to access an account.

Recommended reading: FBI Public Service Announcement on Ramp and Dump Schemes

Colt Telecom Cyberattack Exploits SharePoint Vulnerability (CVE-2025-53770)

High

What happened

Colt Technology Services, a UK-based telecommunications provider, experienced a cyberattack starting on August 12, 2025, leading to multi-day outages of services such as hosting, porting, Colt Online, and Voice API platforms. The WarLock ransomware group claimed responsibility, alleging the theft of one million documents and offering them for sale.

Who is affected

Colt Technology Services and its customers relying on the affected services are impacted by this incident.

Why it matters

The attack underscores the critical vulnerabilities in widely used platforms like Microsoft SharePoint and highlights the potential for significant operational disruptions and data breaches in the telecommunications sector.

How it could have been prevented

Regularly applying security patches and updates, especially for known vulnerabilities like CVE-2025-53770, and implementing robust monitoring to detect unauthorized access could have mitigated the risk.

Relevant professional terms

Zero-day vulnerability
A software flaw unknown to the vendor, exploited by attackers before a fix is available.
Web shell
A malicious script uploaded to a web server, allowing remote administration by attackers.

Recommended reading: Microsoft SharePoint Security Update – July 2025

Critical RCE Vulnerability in Cisco Secure Firewall Management Center (CVE-2025-20265)

Critical

What happened

Cisco disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-20265) in the RADIUS subsystem of its Secure Firewall Management Center (FMC) software, allowing unauthenticated remote attackers to execute arbitrary shell commands with elevated privileges.

Who is affected

Organizations using Cisco Secure Firewall Management Center versions 7.0.7 and 7.7.0 with RADIUS authentication enabled for web-based or SSH management interfaces.

Why it matters

Exploitation of this vulnerability could grant attackers full control over affected devices, potentially leading to network compromise, data exfiltration, and disruption of firewall operations.

How it could have been prevented

Implementing thorough input validation during the authentication phase and conducting regular security audits to identify and mitigate such vulnerabilities.

Relevant professional terms

Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to execute arbitrary code on a remote system.
RADIUS (Remote Authentication Dial-In User Service)
A networking protocol providing centralized Authentication, Authorization, and Accounting (AAA) management for users connecting to a network service.

Recommended reading: Cisco Security Advisory on CVE-2025-20265

Plex Urges Immediate Update to Patch Security Vulnerability

High

What happened

Plex identified a security vulnerability in Plex Media Server versions 1.41.7.x to 1.42.0.x and released an update to address the issue. Users running affected versions were notified to update their software immediately.

Who is affected

Users operating Plex Media Server versions 1.41.7.x to 1.42.0.x are impacted by this vulnerability.

Why it matters

Unpatched vulnerabilities can be exploited by attackers to compromise systems, potentially leading to unauthorized access or data breaches. Prompt updates are crucial to maintain system security.

How it could have been prevented

Regularly updating software to the latest versions and promptly applying security patches can prevent exploitation of known vulnerabilities.

Relevant professional terms

Vulnerability
A weakness in a system that can be exploited to gain unauthorized access or cause harm.
Patch
A software update designed to fix vulnerabilities or bugs in a program.

Recommended reading: BleepingComputer

US Sanctions Grinex Crypto-Exchange, Successor to Garantex

High

What happened

The U.S. Department of the Treasury has imposed sanctions on Grinex, a cryptocurrency exchange identified as the successor to the previously sanctioned Russian exchange Garantex. Grinex was established shortly after U.S. authorities seized Garantex's domains in March 2025 due to its involvement in laundering illicit funds for cybercriminals.

Who is affected

Entities and individuals utilizing Grinex for cryptocurrency transactions, particularly those involved in illicit activities, are directly impacted by these sanctions.

Why it matters

The sanctions underscore the U.S. government's commitment to disrupting financial platforms that facilitate cybercrime and money laundering. Organizations should be vigilant about the platforms they engage with to avoid inadvertent involvement in illicit financial activities.

How it could have been prevented

Implementing stringent regulatory compliance measures and conducting thorough due diligence on cryptocurrency exchanges can help prevent associations with illicit financial activities.

Relevant professional terms

Sanctions
Official penalties imposed by one country or a group of countries on another, often to deter certain behaviors or activities.
Money Laundering
The process of concealing the origins of illegally obtained money, typically by means of transfers involving foreign banks or legitimate businesses.

Recommended reading: US Seizes Domain of Garantex Crypto Exchange Used by Ransomware Gangs