
Daily Dose of Cybersecurity News - August 20, 2025
Oregon Man Arrested for Operating 'Rapper Bot' DDoS Service
CriticalWhat happened
Ethan J. Foltz, a 22-year-old from Springfield, Oregon, was arrested for allegedly operating "Rapper Bot," a botnet comprising tens of thousands of compromised Internet of Things (IoT) devices. This botnet was utilized to launch massive distributed denial-of-service (DDoS) attacks, including a significant attack in March 2025 that disrupted Twitter/X services. Foltz and an unidentified co-conspirator reportedly rented out the botnet to online extortionists.
Who is affected
Organizations targeted by the DDoS attacks, notably Twitter/X, which experienced service disruptions in March 2025. Additionally, numerous online businesses, including gambling operations in China, were extorted using the botnet.
Why it matters
The operation of large-scale botnets like Rapper Bot poses significant threats to online services, leading to service outages, financial losses, and potential data breaches. The arrest highlights the ongoing challenges in combating cybercriminal activities that exploit IoT vulnerabilities to orchestrate widespread attacks.
How it could have been prevented
Implementing robust security measures on IoT devices, such as changing default passwords and regularly updating firmware, can reduce the risk of device compromise. Additionally, organizations should employ comprehensive DDoS mitigation strategies to protect against large-scale attacks.
Relevant professional terms
- Botnet
- A network of private computers infected with malicious software and controlled as a group without the owners' knowledge, often used to send spam or launch DDoS attacks.
- Distributed Denial-of-Service (DDoS) Attack
- A cyber-attack in which multiple compromised systems are used to target a single system, causing a denial of service for users of the targeted system.
Recommended reading: KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS
PyPI Implements Measures to Prevent Domain Resurrection Attacks
HighWhat happened
The Python Package Index (PyPI) has introduced new security measures to prevent domain resurrection attacks, where attackers exploit expired domain names to hijack accounts via password resets.
Who is affected
PyPI account holders, particularly those using email addresses associated with custom domains.
Why it matters
This initiative enhances the security of the Python ecosystem by mitigating a significant supply-chain attack vector, thereby protecting both package maintainers and end-users from potential malicious code injections.
How it could have been prevented
Regular monitoring of domain status and implementing two-factor authentication (2FA) can significantly reduce the risk of such attacks.
Relevant professional terms
- Domain Resurrection Attack
- A type of attack where an expired domain is re-registered by an attacker to gain control over associated accounts.
- Supply-Chain Attack
- A cyber-attack that targets less secure elements in the supply chain to compromise a system.
Recommended reading: PyPI Blog: Preventing Domain Resurrection Attacks
Inotiv Ransomware Attack Disrupts Operations
HighWhat happened
Inotiv, a U.S.-based pharmaceutical company, experienced a ransomware attack on August 8, 2025, leading to the encryption of certain systems and data, which disrupted business operations.
Who is affected
Inotiv's internal systems and data were compromised, impacting the company's operations and potentially its clients in the pharmaceutical and medical device industries.
Why it matters
The attack highlights the vulnerability of critical sectors like pharmaceuticals to cyber threats, emphasizing the need for robust cybersecurity measures to protect sensitive research data and maintain operational continuity.
How it could have been prevented
Implementing comprehensive cybersecurity protocols, including regular system updates, employee training on phishing attacks, and maintaining secure, offline backups of critical data.
Relevant professional terms
- Ransomware
- Malicious software designed to block access to a computer system until a sum of money is paid.
- Encryption
- The process of converting data into a code to prevent unauthorized access.
Recommended reading: Recorded Future News
Microsoft August 2025 Security Updates Disrupt Windows Recovery and Reset Functions
HighWhat happened
Microsoft's August 2025 security updates have introduced a bug that disrupts the 'Reset my PC' and recovery operations on Windows 10 and certain Windows 11 systems.
Who is affected
Users of Windows 10 and Windows 11 versions 22H2 and 23H2 who have installed the August 2025 security updates.
Why it matters
The inability to perform system resets or recoveries can hinder troubleshooting and system restoration efforts, potentially leading to prolonged downtime and data loss.
How it could have been prevented
Thorough pre-release testing of security updates, especially focusing on system recovery features, could have identified and mitigated this issue before deployment.
Relevant professional terms
- Reset my PC
- A Windows feature that reinstalls the operating system, allowing users to choose whether to keep or remove personal files.
- RemoteWipe CSP
- A configuration service provider in Windows that enables remote device reset or wipe operations.
Recommended reading: Reset your PC
Business Council of New York State Data Breach Exposes Sensitive Information of 47,000 Individuals
HighWhat happened
The Business Council of New York State (BCNYS) experienced a data breach between February 24 and 25, 2025, during which unauthorized individuals accessed and exfiltrated personal, financial, and health information of over 47,000 individuals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/business-council-of-new-york-state-discloses-data-breach-affecting-47-000-people/?utm_source=openai))
Who is affected
Approximately 47,329 individuals associated with BCNYS, including members and affiliates, had their sensitive information compromised. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/business-council-of-new-york-state-discloses-data-breach-affecting-47-000-people/?utm_source=openai))
Why it matters
The breach exposed a wide range of sensitive data, including Social Security numbers, financial account details, and medical information, increasing the risk of identity theft, financial fraud, and privacy violations for the affected individuals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/business-council-of-new-york-state-discloses-data-breach-affecting-47-000-people/?utm_source=openai))
How it could have been prevented
Implementing robust multi-factor authentication (MFA) protocols, conducting regular security audits, and ensuring timely detection and response to unauthorized access could have mitigated the risk of such a breach.
Relevant professional terms
- Multi-Factor Authentication (MFA)
- A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity for a login or other transaction.
- Data Exfiltration
- The unauthorized transfer of data from a computer or other device, often conducted by cybercriminals to steal sensitive information.
Recommended reading: Protecting Consumers' Personal Information