Hooded hacker at laptop surrounded by floating hexagonal shields, locks, warning icons, and code displays

Daily Dose of Cybersecurity News - August 20, 2025

Oregon Man Arrested for Operating 'Rapper Bot' DDoS Service

Critical

What happened

Ethan J. Foltz, a 22-year-old from Springfield, Oregon, was arrested for allegedly operating "Rapper Bot," a botnet comprising tens of thousands of compromised Internet of Things (IoT) devices. This botnet was utilized to launch massive distributed denial-of-service (DDoS) attacks, including a significant attack in March 2025 that disrupted Twitter/X services. Foltz and an unidentified co-conspirator reportedly rented out the botnet to online extortionists.

Who is affected

Organizations targeted by the DDoS attacks, notably Twitter/X, which experienced service disruptions in March 2025. Additionally, numerous online businesses, including gambling operations in China, were extorted using the botnet.

Why it matters

The operation of large-scale botnets like Rapper Bot poses significant threats to online services, leading to service outages, financial losses, and potential data breaches. The arrest highlights the ongoing challenges in combating cybercriminal activities that exploit IoT vulnerabilities to orchestrate widespread attacks.

How it could have been prevented

Implementing robust security measures on IoT devices, such as changing default passwords and regularly updating firmware, can reduce the risk of device compromise. Additionally, organizations should employ comprehensive DDoS mitigation strategies to protect against large-scale attacks.

Relevant professional terms

Botnet
A network of private computers infected with malicious software and controlled as a group without the owners' knowledge, often used to send spam or launch DDoS attacks.
Distributed Denial-of-Service (DDoS) Attack
A cyber-attack in which multiple compromised systems are used to target a single system, causing a denial of service for users of the targeted system.

Recommended reading: KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS

PyPI Implements Measures to Prevent Domain Resurrection Attacks

High

What happened

The Python Package Index (PyPI) has introduced new security measures to prevent domain resurrection attacks, where attackers exploit expired domain names to hijack accounts via password resets.

Who is affected

PyPI account holders, particularly those using email addresses associated with custom domains.

Why it matters

This initiative enhances the security of the Python ecosystem by mitigating a significant supply-chain attack vector, thereby protecting both package maintainers and end-users from potential malicious code injections.

How it could have been prevented

Regular monitoring of domain status and implementing two-factor authentication (2FA) can significantly reduce the risk of such attacks.

Relevant professional terms

Domain Resurrection Attack
A type of attack where an expired domain is re-registered by an attacker to gain control over associated accounts.
Supply-Chain Attack
A cyber-attack that targets less secure elements in the supply chain to compromise a system.

Recommended reading: PyPI Blog: Preventing Domain Resurrection Attacks

Inotiv Ransomware Attack Disrupts Operations

High

What happened

Inotiv, a U.S.-based pharmaceutical company, experienced a ransomware attack on August 8, 2025, leading to the encryption of certain systems and data, which disrupted business operations.

Who is affected

Inotiv's internal systems and data were compromised, impacting the company's operations and potentially its clients in the pharmaceutical and medical device industries.

Why it matters

The attack highlights the vulnerability of critical sectors like pharmaceuticals to cyber threats, emphasizing the need for robust cybersecurity measures to protect sensitive research data and maintain operational continuity.

How it could have been prevented

Implementing comprehensive cybersecurity protocols, including regular system updates, employee training on phishing attacks, and maintaining secure, offline backups of critical data.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system until a sum of money is paid.
Encryption
The process of converting data into a code to prevent unauthorized access.

Recommended reading: Recorded Future News

Microsoft August 2025 Security Updates Disrupt Windows Recovery and Reset Functions

High

What happened

Microsoft's August 2025 security updates have introduced a bug that disrupts the 'Reset my PC' and recovery operations on Windows 10 and certain Windows 11 systems.

Who is affected

Users of Windows 10 and Windows 11 versions 22H2 and 23H2 who have installed the August 2025 security updates.

Why it matters

The inability to perform system resets or recoveries can hinder troubleshooting and system restoration efforts, potentially leading to prolonged downtime and data loss.

How it could have been prevented

Thorough pre-release testing of security updates, especially focusing on system recovery features, could have identified and mitigated this issue before deployment.

Relevant professional terms

Reset my PC
A Windows feature that reinstalls the operating system, allowing users to choose whether to keep or remove personal files.
RemoteWipe CSP
A configuration service provider in Windows that enables remote device reset or wipe operations.

Recommended reading: Reset your PC

Business Council of New York State Data Breach Exposes Sensitive Information of 47,000 Individuals

High

What happened

The Business Council of New York State (BCNYS) experienced a data breach between February 24 and 25, 2025, during which unauthorized individuals accessed and exfiltrated personal, financial, and health information of over 47,000 individuals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/business-council-of-new-york-state-discloses-data-breach-affecting-47-000-people/?utm_source=openai))

Who is affected

Approximately 47,329 individuals associated with BCNYS, including members and affiliates, had their sensitive information compromised. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/business-council-of-new-york-state-discloses-data-breach-affecting-47-000-people/?utm_source=openai))

Why it matters

The breach exposed a wide range of sensitive data, including Social Security numbers, financial account details, and medical information, increasing the risk of identity theft, financial fraud, and privacy violations for the affected individuals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/business-council-of-new-york-state-discloses-data-breach-affecting-47-000-people/?utm_source=openai))

How it could have been prevented

Implementing robust multi-factor authentication (MFA) protocols, conducting regular security audits, and ensuring timely detection and response to unauthorized access could have mitigated the risk of such a breach.

Relevant professional terms

Multi-Factor Authentication (MFA)
A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity for a login or other transaction.
Data Exfiltration
The unauthorized transfer of data from a computer or other device, often conducted by cybercriminals to steal sensitive information.

Recommended reading: Protecting Consumers' Personal Information