Team monitoring multiple screens with security alerts

October 28, 2025 - Daily Cybersecurity News

Decline in Ransomware Payments as Victims Resist Extortion

Medium

What happened

Recent data indicates that only 23% of organizations targeted by ransomware attacks are complying with ransom demands, marking a significant decrease in payment rates.

Who is affected

Organizations across various sectors facing ransomware attacks are increasingly choosing not to pay ransoms.

Why it matters

The decline in ransom payments suggests enhanced cybersecurity measures and a collective effort to disrupt the profitability of ransomware operations, potentially leading to a decrease in such attacks.

How it could have been prevented

Implementing robust cybersecurity protocols, conducting regular employee training on phishing awareness, and maintaining up-to-date backups can mitigate the impact of ransomware attacks.

Relevant professional terms

Double Extortion
A ransomware tactic where attackers encrypt data and threaten to release stolen information publicly if the ransom is not paid.
Ransomware-as-a-Service (RaaS)
A business model where ransomware developers lease their malware to affiliates, who then carry out attacks and share profits.

Recommended reading: Ransomware payments on record-breaking trajectory for 2023

Critical ASP.NET Core Vulnerability (CVE-2025-55315) Affects QNAP's NetBak PC Agent

Critical

What happened

A critical security bypass vulnerability (CVE-2025-55315) was identified in the Kestrel ASP.NET Core web server, affecting QNAP's NetBak PC Agent, a Windows backup utility. This flaw allows attackers with low privileges to hijack user credentials or bypass security controls through HTTP request smuggling.

Who is affected

Users of QNAP's NetBak PC Agent on Windows systems that have not updated their ASP.NET Core components are at risk.

Why it matters

Exploitation of this vulnerability could lead to unauthorized access to sensitive data, modification of server files, or limited denial-of-service conditions, posing significant security risks to affected systems.

How it could have been prevented

Regularly updating ASP.NET Core components and promptly applying security patches can mitigate such vulnerabilities.

Relevant professional terms

HTTP Request Smuggling
A technique where an attacker sends specially crafted HTTP requests to bypass security controls or manipulate server behavior.
ASP.NET Core
An open-source, cross-platform framework for building modern, cloud-based, internet-connected applications.

Recommended reading: .NET 8.0 download page

Chrome Zero-Day Exploited by Italian Spyware Vendor Memento Labs

High

What happened

A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783, was exploited in Operation ForumTroll to deliver malware associated with Italian spyware vendor Memento Labs.

Who is affected

Russian organizations, including media outlets, universities, research centers, government bodies, and financial institutions, were targeted through phishing emails containing malicious links.

Why it matters

The exploitation of a Chrome zero-day by a commercial spyware vendor underscores the increasing sophistication of cyber threats and the potential risks to organizations worldwide.

How it could have been prevented

Regularly updating software to the latest versions and educating users to recognize and avoid phishing attempts can mitigate such threats.

Relevant professional terms

Zero-day vulnerability
A software flaw unknown to the vendor, leaving systems vulnerable until a fix is developed.
Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.

Recommended reading: Google: Spyware vendors behind 50% of zero-days exploited in 2023

CISA Directs Immediate Patching of Critical WSUS Vulnerability (CVE-2025-59287)

Critical

What happened

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to patch a critical remote code execution (RCE) vulnerability, identified as CVE-2025-59287, in Windows Server Update Services (WSUS). This flaw allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges on affected servers.

Who is affected

Organizations utilizing Windows servers with the WSUS Server role enabled, particularly those with WSUS instances exposed on default ports (8530/TCP and 8531/TCP), are at risk.

Why it matters

Exploitation of this vulnerability can lead to full system compromise, enabling attackers to deploy malware, exfiltrate sensitive data, and disrupt critical services. Given the widespread use of WSUS for managing Windows updates, the potential impact is significant.

How it could have been prevented

Regularly applying security patches and updates promptly upon release. Disabling unnecessary services and roles, such as the WSUS Server role if not in use, to minimize attack surfaces.

Relevant professional terms

Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to run arbitrary code on a target system remotely.
WSUS (Windows Server Update Services)
A Microsoft tool that enables administrators to manage the distribution of updates and patches for Windows operating systems.

Recommended reading: Critical WSUS flaw in Windows Server now exploited in attacks

'Jingle Thief' Gift Card Fraud Campaign Targets Retailers

High

What happened

A Morocco-based cybercrime group conducted a large-scale gift card fraud campaign, dubbed "Jingle Thief," infiltrating cloud-based systems of global retailers to generate and resell high-value gift cards.

Who is affected

Global retailers and consumer services organizations utilizing cloud infrastructure are the primary targets of this campaign.

Why it matters

The attackers' ability to maintain undetected access for extended periods poses significant financial and reputational risks to affected organizations, especially during the high-traffic holiday season.

How it could have been prevented

Implementing robust access controls, regularly monitoring cloud environments for unusual activity, and conducting frequent security audits could mitigate such threats.

Relevant professional terms

Cloud Infrastructure
The collection of hardware and software components-such as servers, storage, networking, and virtualization software-that are needed to support the computing requirements of a cloud computing model.
Credential Theft
The act of stealing authentication credentials, such as usernames and passwords, to gain unauthorized access to systems or data.

Recommended reading: Retail Sector Prepares for Annual Holiday Cybercrime Onslaught

Qilin Ransomware Group Deploys Linux-Based Ransomware on Windows Hosts

High

What happened

The Qilin ransomware group executed attacks on Windows systems using a Linux-based ransomware binary. They exploited legitimate remote management and file transfer tools, including AnyDesk, ATERA Networks' RMM platform, and ScreenConnect, to deploy the ransomware.

Who is affected

Organizations across various sectors, particularly those utilizing Windows systems with remote management tools, are at risk. Qilin has impacted over 700 organizations in 62 countries since January, with significant activity in the US, France, Canada, and the UK.

Why it matters

This attack demonstrates the evolving tactics of ransomware groups, highlighting the need for cross-platform threat detection. Traditional Windows-centric security solutions may be inadequate against such sophisticated methods, increasing the risk of successful breaches.

How it could have been prevented

Implementing strict access controls and monitoring the use of remote management tools can help prevent unauthorized deployment of malicious binaries. Additionally, enhancing endpoint detection and response systems to recognize cross-platform threats is crucial.

Relevant professional terms

Ransomware-as-a-Service (RaaS)
A business model where ransomware developers lease their malware to affiliates, who then carry out attacks and share profits.
Endpoint Detection and Response (EDR)
Security solutions focused on detecting, investigating, and responding to suspicious activities on endpoint devices.

Recommended reading: Linux Ransomware Poses Significant Threat to Critical Infrastructure

Massive China-Linked Smishing Campaign Leveraged 194,000 Domains

High

What happened

A Chinese-speaking threat actor known as the Smishing Triad has conducted a large-scale smishing campaign since April 2024, utilizing over 194,000 domains to impersonate various services and collect sensitive information.

Who is affected

Users globally, with a primary focus on the United States, have been targeted, including individuals in Argentina, Australia, Canada, France, Germany, and other countries.

Why it matters

The campaign's extensive reach and decentralized nature make detection challenging, posing significant risks to personal and financial data security worldwide.

How it could have been prevented

Implementing robust SMS filtering solutions and educating users to verify unsolicited messages through official channels can mitigate such threats.

Relevant professional terms

Smishing
A form of phishing that uses SMS messages to deceive recipients into providing personal information.
Phishing-as-a-Service (PhaaS)
A model where cybercriminals offer phishing tools and services to others, facilitating large-scale phishing campaigns.

Recommended reading: unit42.paloaltonetworks.com