Team working on laptop with malware and virus threats

October 24, 2025 - Daily Cybersecurity News

Toys "R" Us Canada Data Breach Exposes Customer Information

Medium

What happened

Toys "R" Us Canada experienced a data breach where unauthorized parties accessed and leaked customer records containing personal information.

Who is affected

Customers of Toys "R" Us Canada whose personal information was stored in the company's database.

Why it matters

Exposure of personal information increases the risk of identity theft, phishing attacks, and other forms of fraud targeting affected individuals.

How it could have been prevented

Implementing robust data encryption, regular security audits, and continuous monitoring of systems for unauthorized access.

Relevant professional terms

Data Breach
Unauthorized access and retrieval of sensitive information from a system.
Phishing
A cyber attack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.

Recommended reading: BleepingComputer

HP Update Causes Microsoft Entra ID Authentication Failures on AI PCs

High

What happened

HP released an update for its OneAgent software on Windows 11 AI PCs that inadvertently deleted critical Microsoft certificates, leading to authentication failures with Microsoft Entra ID.

Who is affected

Organizations using HP AI PCs running Windows 11 that received the HP OneAgent version 1.2.50.9581 update.

Why it matters

The deletion of essential certificates disrupted access to Microsoft Entra ID, potentially disconnecting affected devices from their organization's cloud environments and hindering productivity.

How it could have been prevented

Implementing thorough testing protocols for update scripts to identify and mitigate unintended certificate deletions before deployment.

Relevant professional terms

Microsoft Entra ID
Microsoft's cloud-based identity and access management service, formerly known as Azure Active Directory.
Certificate Store
A centralized repository in Windows operating systems that stores security certificates.

Recommended reading: Troubleshoot Microsoft Entra hybrid joined devices

Critical Vulnerability CVE-2025-61932 in Lanscope Endpoint Manager Exploited in Attacks

Critical

What happened

A critical vulnerability (CVE-2025-61932) in Motex Lanscope Endpoint Manager is being actively exploited by attackers to execute arbitrary code on affected systems.

Who is affected

Organizations using Lanscope Endpoint Manager versions 9.4.7.2 and earlier are at risk.

Why it matters

Exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising sensitive data and system integrity.

How it could have been prevented

Timely application of security patches and updates as released by the vendor.

Relevant professional terms

Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to run arbitrary code on a target system remotely.
Unauthenticated Attacker
An individual who can exploit a system without needing to provide credentials or authentication.

Recommended reading: Motex Security Bulletin

Microsoft Disables File Explorer Preview for Downloaded Files to Prevent NTLM Hash Theft

High

What happened

Microsoft has updated File Explorer to automatically disable the preview pane for files downloaded from the internet, aiming to prevent credential theft attacks that exploit NTLM hash vulnerabilities.

Who is affected

Users of Windows 11 and Windows Server systems who have installed the October 2025 security updates.

Why it matters

This change addresses a security vulnerability where attackers could steal NTLM hashes by embedding malicious HTML tags in files. Disabling the preview pane for such files reduces the risk of credential theft without requiring user interaction.

How it could have been prevented

Users should avoid previewing or opening files from untrusted sources and ensure their systems are updated with the latest security patches.

Relevant professional terms

NTLM Hash
A cryptographic representation of a user's password used in Windows authentication processes.
Mark of the Web (MotW)
A security feature that tags files downloaded from the internet to indicate their origin and apply appropriate security measures.

Recommended reading: support.microsoft.com

Zero Trust Has a Blind Spot-Your AI Agents

High

What happened

The integration of autonomous AI agents into organizational systems has exposed a significant security gap in Zero Trust architectures, as these agents often operate without proper identity governance, leading to potential unauthorized access and actions.

Who is affected

Organizations deploying AI agents that act autonomously within their infrastructure.

Why it matters

Without proper identity management, AI agents can become ungoverned entities, posing risks such as unauthorized data access, system manipulation, and challenges in auditing and accountability.

How it could have been prevented

Implementing identity governance frameworks for AI agents, ensuring each has a unique, managed identity, clear ownership, and appropriate permissions aligned with their intended functions.

Relevant professional terms

Zero Trust Architecture
A security model that requires strict verification for every user and device attempting to access resources, assuming no implicit trust.
Identity Governance
The policies and processes that ensure proper management of user identities and their access rights within an organization.

Recommended reading: NIST AI Risk Management Framework

Spoofed AI Sidebars in Atlas and Comet Browsers Pose Security Risks

High

What happened

Researchers discovered that malicious browser extensions can overlay fake AI sidebars in OpenAI's Atlas and Perplexity's Comet browsers, potentially leading users to execute harmful actions.

Who is affected

Users of OpenAI's Atlas and Perplexity's Comet browsers are at risk.

Why it matters

This vulnerability can be exploited to steal sensitive information, such as cryptocurrency, or to gain unauthorized access to users' Gmail and Google Drive accounts.

How it could have been prevented

Implementing stricter extension permissions and enhancing browser security measures to detect and block unauthorized overlays.

Relevant professional terms

Agentic AI Browser
A browser that integrates AI models to assist users with tasks like summarizing content or executing commands.
OAuth Attack
A method where attackers exploit the OAuth protocol to gain unauthorized access to user accounts.

Recommended reading: BleepingComputer

North Korean Lazarus Group Targets European Defense Firms with 'Operation DreamJob'

High

What happened

The North Korean state-sponsored Lazarus Group executed a cyber-espionage campaign known as 'Operation DreamJob,' targeting three European defense companies involved in unmanned aerial vehicle (UAV) technology. The attackers posed as recruiters offering high-profile job opportunities to employees, leading them to download malicious files that compromised their systems.

Who is affected

Three European defense firms engaged in UAV technology development were targeted. These companies manufacture military equipment currently deployed in Ukraine as part of their countries' military assistance.

Why it matters

This campaign underscores the persistent threat posed by nation-state actors to the defense sector, particularly in areas of strategic military technology like UAVs. The successful compromise of such firms can lead to the theft of sensitive information, potentially undermining national security and technological advantages.

How it could have been prevented

- Implementing robust employee training programs to recognize and report social engineering attempts, such as unsolicited job offers from unknown sources.- Enforcing strict policies against downloading and executing files from unverified sources, especially in sensitive sectors like defense.

Relevant professional terms

Social Engineering
The psychological manipulation of individuals into performing actions or divulging confidential information.
Remote Access Trojan (RAT)
A type of malware that provides an attacker with unauthorized remote control over a victim's computer.

Recommended reading: North Korean hackers target defense industry with custom malware