Network of hackers attacking connected devices and data

October 20, 2025 - Daily Cybersecurity News

TikTok Videos Exploited to Distribute Infostealer Malware via ClickFix Attacks

High

What happened

Cybercriminals are leveraging TikTok videos disguised as free activation guides for popular software to disseminate information-stealing malware. These videos instruct users to execute malicious PowerShell commands, leading to the installation of infostealers like Aura Stealer.

Who is affected

Individuals seeking free activation methods for software such as Windows, Microsoft 365, Adobe Premiere, Photoshop, CapCut Pro, and Discord Nitro are targeted.

Why it matters

The widespread use of TikTok amplifies the reach of these malicious campaigns, increasing the risk of credential theft, unauthorized access to personal accounts, and potential financial loss for a vast user base.

How it could have been prevented

Users should avoid executing commands from unverified sources, especially those obtained from social media platforms. Implementing robust endpoint protection and educating users about the risks of running unsolicited scripts can mitigate such threats.

Relevant professional terms

ClickFix Attack
A social engineering technique where attackers provide seemingly legitimate fixes or instructions that deceive users into executing malicious commands or scripts.
Infostealer
A type of malware designed to collect sensitive information from an infected system, such as login credentials, financial data, and personal information.

Recommended reading: BleepingComputer

China Accuses U.S. NSA of Cyberattacks on National Time Service Center

High

What happened

China's Ministry of State Security accused the U.S. National Security Agency (NSA) of conducting cyberattacks on the National Time Service Center. The NSA allegedly exploited vulnerabilities in a foreign mobile phone brand's messaging services to steal sensitive information from the center's staff in 2022 and used 42 types of cyberattack tools to target internal network systems between 2023 and 2024.

Who is affected

The National Time Service Center, responsible for generating and distributing China's standard time and providing timing services to critical industries such as communications, finance, power, transport, and defense.

Why it matters

Compromising the National Time Service Center could disrupt essential services and infrastructure, including network communications, financial systems, and power supply, posing significant risks to national security and public safety.

How it could have been prevented

Regular security audits and timely patching of known vulnerabilities in messaging services and network systems; implementing robust intrusion detection and prevention systems to monitor and mitigate unauthorized access attempts.

Relevant professional terms

Cyberattack
An attempt by hackers to damage or destroy a computer network or system.
Vulnerability
A weakness in a system that can be exploited by a threat actor to gain unauthorized access or perform unauthorized actions.

Recommended reading: How China Pinned University Cyberattacks on NSA Hackers

Europol Dismantles SIM Farm Network Enabling 49 Million Fake Accounts

High

What happened

Europol disrupted a cybercrime-as-a-service platform operating a SIM farm, leading to the arrest of seven individuals and the seizure of 1,200 SIM box devices containing 40,000 active SIM cards.

Who is affected

Authorities from Austria, Estonia, Finland, and Latvia collaborated in the operation, targeting a network responsible for over 3,200 cyber fraud cases in Austria and Latvia.

Why it matters

The dismantled infrastructure facilitated the creation of more than 49 million fake online accounts, enabling a wide range of cybercrimes, including phishing, smishing, financial fraud, extortion, and the distribution of illicit materials.

How it could have been prevented

Implementing stricter regulations on SIM card distribution and enhancing monitoring of telecommunications infrastructure could help prevent such large-scale fraudulent activities.

Relevant professional terms

SIM box
A device that houses multiple SIM cards, allowing for the routing of calls and messages through various networks, often used to bypass international call rates or for fraudulent activities.
Smishing
A form of phishing that involves sending fraudulent SMS messages to trick recipients into revealing personal information or downloading malicious software.

Recommended reading: Europol's Official Announcement on Operation SIMCARTEL

F5 Data Breach: Nation-State Attackers Compromise BIG-IP Source Code and Vulnerability Information

Critical

What happened

F5 Inc. disclosed that nation-state attackers gained unauthorized access to its internal systems, exfiltrating portions of the BIG-IP product source code and information on undisclosed vulnerabilities. ([threatmon.io](https://threatmon.io/f5-breach-inside-the-october-2025-incident-and-what-it-means-for-the-security-ecosystem/?utm_source=openai))

Who is affected

Organizations utilizing F5's BIG-IP products, including federal agencies and critical infrastructure operators, are potentially at risk due to the exposure of sensitive product information. ([securityboulevard.com](https://securityboulevard.com/2025/10/cybersecurity-snapshot-f5-breach-prompts-urgent-u-s-govt-warning-as-openai-details-disrupted-chatgpt-abuses/?utm_source=openai))

Why it matters

The breach exposes critical development data, including unreleased vulnerability patches, which could enable attackers to exploit F5’s cybersecurity products undetected. ([blog.rankiteo.com](https://blog.rankiteo.com/f50402304101625-f5-inc-breach-october-2025/?utm_source=openai))

How it could have been prevented

Implementing robust network segmentation to limit access to sensitive development environments and conducting regular security audits to detect unauthorized access could have mitigated the risk.

Relevant professional terms

Source Code
The original code written by developers that defines how a software program operates.
Zero-Day Vulnerability
A software vulnerability that is unknown to those who should be interested in its mitigation, including the vendor.

Recommended reading: securityboulevard.com