
October 24, 2025 - Daily Cybersecurity News
Toys "R" Us Canada Data Breach Exposes Customer Information
MediumWhat happened
Toys "R" Us Canada experienced a data breach where unauthorized parties accessed and leaked customer records containing personal information.
Who is affected
Customers of Toys "R" Us Canada whose personal information was stored in the company's database.
Why it matters
Exposure of personal information increases the risk of identity theft, phishing attacks, and other forms of fraud targeting affected individuals.
How it could have been prevented
Implementing robust data encryption, regular security audits, and continuous monitoring of systems for unauthorized access.
Relevant professional terms
- Data Breach
- Unauthorized access and retrieval of sensitive information from a system.
- Phishing
- A cyber attack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Recommended reading: BleepingComputer
HP Update Causes Microsoft Entra ID Authentication Failures on AI PCs
HighWhat happened
HP released an update for its OneAgent software on Windows 11 AI PCs that inadvertently deleted critical Microsoft certificates, leading to authentication failures with Microsoft Entra ID.
Who is affected
Organizations using HP AI PCs running Windows 11 that received the HP OneAgent version 1.2.50.9581 update.
Why it matters
The deletion of essential certificates disrupted access to Microsoft Entra ID, potentially disconnecting affected devices from their organization's cloud environments and hindering productivity.
How it could have been prevented
Implementing thorough testing protocols for update scripts to identify and mitigate unintended certificate deletions before deployment.
Relevant professional terms
- Microsoft Entra ID
- Microsoft's cloud-based identity and access management service, formerly known as Azure Active Directory.
- Certificate Store
- A centralized repository in Windows operating systems that stores security certificates.
Recommended reading: Troubleshoot Microsoft Entra hybrid joined devices
Critical Vulnerability CVE-2025-61932 in Lanscope Endpoint Manager Exploited in Attacks
CriticalWhat happened
A critical vulnerability (CVE-2025-61932) in Motex Lanscope Endpoint Manager is being actively exploited by attackers to execute arbitrary code on affected systems.
Who is affected
Organizations using Lanscope Endpoint Manager versions 9.4.7.2 and earlier are at risk.
Why it matters
Exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising sensitive data and system integrity.
How it could have been prevented
Timely application of security patches and updates as released by the vendor.
Relevant professional terms
- Remote Code Execution (RCE)
- A type of vulnerability that allows an attacker to run arbitrary code on a target system remotely.
- Unauthenticated Attacker
- An individual who can exploit a system without needing to provide credentials or authentication.
Recommended reading: Motex Security Bulletin
Microsoft Disables File Explorer Preview for Downloaded Files to Prevent NTLM Hash Theft
HighWhat happened
Microsoft has updated File Explorer to automatically disable the preview pane for files downloaded from the internet, aiming to prevent credential theft attacks that exploit NTLM hash vulnerabilities.
Who is affected
Users of Windows 11 and Windows Server systems who have installed the October 2025 security updates.
Why it matters
This change addresses a security vulnerability where attackers could steal NTLM hashes by embedding malicious HTML tags in files. Disabling the preview pane for such files reduces the risk of credential theft without requiring user interaction.
How it could have been prevented
Users should avoid previewing or opening files from untrusted sources and ensure their systems are updated with the latest security patches.
Relevant professional terms
- NTLM Hash
- A cryptographic representation of a user's password used in Windows authentication processes.
- Mark of the Web (MotW)
- A security feature that tags files downloaded from the internet to indicate their origin and apply appropriate security measures.
Recommended reading: support.microsoft.com
Zero Trust Has a Blind Spot-Your AI Agents
HighWhat happened
The integration of autonomous AI agents into organizational systems has exposed a significant security gap in Zero Trust architectures, as these agents often operate without proper identity governance, leading to potential unauthorized access and actions.
Who is affected
Organizations deploying AI agents that act autonomously within their infrastructure.
Why it matters
Without proper identity management, AI agents can become ungoverned entities, posing risks such as unauthorized data access, system manipulation, and challenges in auditing and accountability.
How it could have been prevented
Implementing identity governance frameworks for AI agents, ensuring each has a unique, managed identity, clear ownership, and appropriate permissions aligned with their intended functions.
Relevant professional terms
- Zero Trust Architecture
- A security model that requires strict verification for every user and device attempting to access resources, assuming no implicit trust.
- Identity Governance
- The policies and processes that ensure proper management of user identities and their access rights within an organization.
Recommended reading: NIST AI Risk Management Framework
Spoofed AI Sidebars in Atlas and Comet Browsers Pose Security Risks
HighWhat happened
Researchers discovered that malicious browser extensions can overlay fake AI sidebars in OpenAI's Atlas and Perplexity's Comet browsers, potentially leading users to execute harmful actions.
Who is affected
Users of OpenAI's Atlas and Perplexity's Comet browsers are at risk.
Why it matters
This vulnerability can be exploited to steal sensitive information, such as cryptocurrency, or to gain unauthorized access to users' Gmail and Google Drive accounts.
How it could have been prevented
Implementing stricter extension permissions and enhancing browser security measures to detect and block unauthorized overlays.
Relevant professional terms
- Agentic AI Browser
- A browser that integrates AI models to assist users with tasks like summarizing content or executing commands.
- OAuth Attack
- A method where attackers exploit the OAuth protocol to gain unauthorized access to user accounts.
Recommended reading: BleepingComputer
North Korean Lazarus Group Targets European Defense Firms with 'Operation DreamJob'
HighWhat happened
The North Korean state-sponsored Lazarus Group executed a cyber-espionage campaign known as 'Operation DreamJob,' targeting three European defense companies involved in unmanned aerial vehicle (UAV) technology. The attackers posed as recruiters offering high-profile job opportunities to employees, leading them to download malicious files that compromised their systems.
Who is affected
Three European defense firms engaged in UAV technology development were targeted. These companies manufacture military equipment currently deployed in Ukraine as part of their countries' military assistance.
Why it matters
This campaign underscores the persistent threat posed by nation-state actors to the defense sector, particularly in areas of strategic military technology like UAVs. The successful compromise of such firms can lead to the theft of sensitive information, potentially undermining national security and technological advantages.
How it could have been prevented
- Implementing robust employee training programs to recognize and report social engineering attempts, such as unsolicited job offers from unknown sources.- Enforcing strict policies against downloading and executing files from unverified sources, especially in sensitive sectors like defense.
Relevant professional terms
- Social Engineering
- The psychological manipulation of individuals into performing actions or divulging confidential information.
- Remote Access Trojan (RAT)
- A type of malware that provides an attacker with unauthorized remote control over a victim's computer.
Recommended reading: North Korean hackers target defense industry with custom malware