Two hackers attacking laptop with malware and warnings

October 21, 2025 - Daily Cybersecurity News

Muji Halts Online Sales Following Ransomware Attack on Supplier

High

What happened

Japanese retailer Muji suspended its online sales due to a logistics disruption caused by a ransomware attack on its delivery partner, Askul.

Who is affected

Muji's online customers in Japan are affected, as the disruption impacts the company's Japan sales region.

Why it matters

This incident highlights the vulnerability of supply chains to cyberattacks, emphasizing the need for robust cybersecurity measures among third-party vendors to prevent operational disruptions.

How it could have been prevented

Implementing comprehensive cybersecurity protocols, including regular security audits and incident response plans, could mitigate the risk of such supply chain attacks.

Relevant professional terms

Ransomware
Malicious software that encrypts data and demands payment for its release.
Supply Chain Attack
A cyberattack targeting an organization through vulnerabilities in its supply chain.

Recommended reading: BleepingComputer

Critical RCE Vulnerability in WatchGuard Firebox Devices (CVE-2025-9242)

Critical

What happened

A critical out-of-bounds write vulnerability (CVE-2025-9242) was identified in WatchGuard Firebox devices, potentially allowing remote code execution without authentication.

Who is affected

Approximately 75,835 WatchGuard Firebox appliances worldwide, primarily in the United States, Germany, Italy, the United Kingdom, Canada, and France.

Why it matters

Exploitation of this vulnerability could grant attackers unauthorized access to network traffic, leading to data breaches, system compromises, and potential control over affected networks.

How it could have been prevented

Regularly updating Fireware OS to the latest versions and disabling IKEv2 VPN configurations with dynamic gateway peers when not in use.

Relevant professional terms

Out-of-bounds write
A programming error where data is written outside the allocated memory, potentially leading to system crashes or code execution.
IKEv2 (Internet Key Exchange version 2)
A protocol used to set up secure, authenticated communications channels, commonly for VPNs.

Recommended reading: WatchGuard Security Advisory

Active Exploitation of Windows SMB Vulnerability CVE-2025-33073

High

What happened

Threat actors are actively exploiting a high-severity Windows SMB privilege escalation vulnerability, identified as CVE-2025-33073, allowing them to gain SYSTEM privileges on unpatched systems.

Who is affected

All Windows Server and Windows 10 versions, as well as Windows 11 systems up to Windows 11 24H2, are impacted by this vulnerability.

Why it matters

Exploitation of this vulnerability can lead to unauthorized elevation of privileges, potentially allowing attackers to execute arbitrary code with SYSTEM-level access, compromising the integrity and security of affected systems.

How it could have been prevented

Applying Microsoft's security updates released during the June 2025 Patch Tuesday would have mitigated this vulnerability. Additionally, disabling unnecessary SMB services and implementing strict access controls can reduce exposure.

Relevant professional terms

Privilege Escalation
The process by which an attacker gains higher-level permissions on a system, allowing unauthorized actions.
Server Message Block (SMB)
A network protocol used for sharing files, printers, and other resources between computers.

Recommended reading: CISA Known Exploited Vulnerabilities Catalog

GlassWorm Malware Targets OpenVSX and VS Code Registries

High

What happened

A self-propagating malware named GlassWorm has infiltrated the OpenVSX and Microsoft Visual Studio Code extension registries, compromising multiple extensions and resulting in approximately 35,800 installations. The malware conceals its code using invisible Unicode characters and spreads by leveraging stolen account credentials.

Who is affected

Developers utilizing the OpenVSX and Visual Studio Code marketplaces, particularly those who have installed the compromised extensions, are at risk.

Why it matters

This attack underscores the vulnerabilities within software supply chains, especially in widely-used development environments. The use of blockchain for command-and-control operations complicates mitigation efforts, posing significant risks to developer systems and the integrity of software projects.

How it could have been prevented

Implementing rigorous code reviews to detect obfuscated or hidden code, enforcing multi-factor authentication to protect account credentials, and regularly monitoring extension repositories for unauthorized changes could have mitigated the risk.

Relevant professional terms

Supply Chain Attack
A cyberattack that targets less secure elements within an organization's supply network to compromise the end product or service.
Command-and-Control (C2)
Infrastructure used by attackers to maintain communications with compromised systems within a target network.

Recommended reading: Dark Reading: Self-Propagating GlassWorm Poisons VS Code Extensions

Detection of Malicious OAuth Applications in Microsoft 365 Using Cazadora

High

What happened

Security researchers have identified a significant presence of malicious OAuth applications, termed "Stealthware," within Microsoft 365 environments. These applications are custom-built by attackers to blend seamlessly into legitimate app ecosystems, making detection challenging. To assist in identifying such threats, an open-source script named Cazadora has been developed.

Who is affected

Organizations utilizing Microsoft 365 services are at risk, with studies indicating that approximately 10% of surveyed tenants had at least one malicious OAuth application installed.

Why it matters

Malicious OAuth applications can grant attackers unauthorized access to sensitive organizational data, including emails, files, and contacts. This access can lead to data breaches, financial loss, and reputational damage. The stealthy nature of these applications makes them particularly insidious, as they can operate undetected for extended periods.

How it could have been prevented

Regular audits of OAuth applications within Microsoft 365 environments can help identify and remove unauthorized or malicious apps. Implementing strict app consent policies and educating users about the risks associated with granting permissions to unknown applications are also crucial preventive measures.

Relevant professional terms

OAuth (Open Authorization)
An open standard for access delegation, commonly used to grant websites or applications limited access to user information without exposing credentials.
Stealthware
Malicious applications designed to operate undetected within a system, often by mimicking legitimate software.

Recommended reading: Cazadora GitHub Repository

AWS Outage Disrupts Major Services Including Amazon, Prime Video, and Fortnite

High

What happened

A significant outage in Amazon Web Services (AWS) led to widespread disruptions across numerous online platforms, including Amazon.com, Prime Video, Fortnite, and Perplexity AI. The incident originated in the US-EAST-1 region, causing increased error rates and latencies for multiple AWS services.

Who is affected

Organizations and users relying on AWS services, particularly those hosted in the US-EAST-1 region, experienced service interruptions. This includes major companies like Amazon, Epic Games (Fortnite), and Perplexity AI.

Why it matters

The outage underscores the critical dependency of numerous high-profile services on AWS infrastructure. Such disruptions can lead to significant operational and financial impacts, highlighting the need for robust contingency planning and diversified hosting strategies.

How it could have been prevented

Implementing multi-region or multi-cloud architectures can mitigate the impact of regional outages. Regular testing of failover mechanisms and maintaining up-to-date incident response plans are also crucial.

Relevant professional terms

DNS Resolution
The process of translating domain names into IP addresses, allowing browsers to locate and load websites.
Latency
The delay before a transfer of data begins following an instruction for its transfer.

Recommended reading: AWS Outage 2025: What Happened, Causes, Impact, & Recovery

ColdRiver Deploys New Malware in Espionage Campaign

High

What happened

The Russian state-sponsored threat actor ColdRiver launched a cyber espionage campaign targeting NATO governments, former diplomats, and high-profile NGO figures. Following the exposure of their previous malware, LOSTKEYS, in May 2025, ColdRiver rapidly developed and deployed new malware tools within five days to continue their operations.

Who is affected

NATO member governments, former diplomats, and prominent individuals within non-governmental organizations are the primary targets of this campaign.

Why it matters

The swift adaptation and deployment of new malware by ColdRiver underscore the persistent and evolving threat posed by state-sponsored cyber actors. This rapid development cycle enhances their ability to evade detection and maintain access to sensitive information, posing significant risks to national security and organizational integrity.

How it could have been prevented

Implementing robust email filtering to detect and block phishing attempts, conducting regular security awareness training for personnel, and maintaining up-to-date threat intelligence to recognize and respond to evolving tactics are essential measures to mitigate such threats.

Relevant professional terms

Advanced Persistent Threat (APT)
A prolonged and targeted cyberattack in which an intruder gains access to a network and remains undetected for an extended period.
Malware
Malicious software designed to disrupt, damage, or gain unauthorized access to computer systems.

Recommended reading: Google Cloud Blog: New Malware Attributed to Russia State-Sponsored COLDRIVER