Cloud network with hazard warnings and security threats

October 30, 2025 - Daily Cybersecurity News

Malicious NPM Packages Deploy Infostealer Across Multiple Platforms

High

What happened

Ten malicious packages were uploaded to the npm registry, impersonating legitimate software projects. These packages downloaded an information-stealing component designed to collect sensitive data from Windows, Linux, and macOS systems.

Who is affected

Developers and organizations who downloaded and integrated these compromised npm packages into their projects are at risk of data theft.

Why it matters

The incident highlights the ongoing threat of supply chain attacks in open-source ecosystems, where malicious code can infiltrate widely-used packages, potentially compromising numerous systems and exposing sensitive information.

How it could have been prevented

Implementing strict package validation processes, utilizing automated tools to detect anomalies in dependencies, and regularly auditing third-party packages can help prevent such supply chain attacks.

Relevant professional terms

Typosquatting
A cyberattack method where attackers register domain names or package names that are similar to legitimate ones, exploiting typographical errors made by users.
Infostealer
A type of malware designed to gather sensitive information from a victim's system, such as login credentials, financial data, and personal information.

Recommended reading: Infostealer campaign compromises 10 npm packages, targets devs

WordPress Security Plugin Vulnerability (CVE-2025-11705) Exposes Private Data

Medium

What happened

A vulnerability in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress allows subscribers to read any file on the server, potentially exposing private information.

Who is affected

WordPress sites using the Anti-Malware Security and Brute-Force Firewall plugin, particularly versions 4.23.81 and earlier.

Why it matters

Exploitation of this vulnerability could lead to unauthorized access to sensitive data, including database credentials and user information, posing significant security risks.

How it could have been prevented

Implementing proper capability checks in the plugin's code to restrict access to sensitive functions based on user roles.

Relevant professional terms

AJAX (Asynchronous JavaScript and XML)
A web development technique for creating interactive web applications by exchanging data with a server in the background.
Nonce
A unique token used to verify the authenticity of a request, preventing unauthorized or duplicate submissions.

Recommended reading: Wordfence Blog

Hacktivists Breach Canadian Water and Energy Facilities

High

What happened

Hacktivists have infiltrated multiple critical infrastructure systems in Canada, manipulating industrial controls in water treatment, oil and gas, and agricultural facilities, leading to service disruptions and potential safety hazards.

Who is affected

Canadian water treatment facilities, oil and gas companies, and agricultural operations have been impacted by these breaches.

Why it matters

These incidents underscore the vulnerabilities in internet-exposed Industrial Control Systems (ICS), highlighting the urgent need for enhanced cybersecurity measures to protect critical infrastructure from opportunistic attacks.

How it could have been prevented

- Conduct comprehensive inventories of internet-accessible ICS devices and eliminate unnecessary exposures.- Implement Virtual Private Networks (VPNs) with two-factor authentication, intrusion prevention systems, and regular vulnerability assessments.

Relevant professional terms

Industrial Control Systems (ICS)
Integrated hardware and software designed to monitor and control industrial processes.
Hacktivists
Individuals or groups who use hacking techniques to promote political or social agendas.

Recommended reading: Cyber Threat to Canada's Oil and Gas Sector

Microsoft DNS Outage Disrupts Azure and Microsoft 365 Services

High

What happened

Microsoft experienced a DNS outage that disrupted access to Azure and Microsoft 365 services globally, preventing users from logging into company networks and accessing various platforms.

Who is affected

Organizations and individuals worldwide relying on Microsoft Azure and Microsoft 365 services, including healthcare institutions and transportation systems.

Why it matters

The outage highlights the critical dependency on DNS for service availability and underscores the potential widespread impact of DNS failures on essential services.

How it could have been prevented

Implementing redundant DNS configurations and robust failover mechanisms could mitigate the impact of such outages.

Relevant professional terms

DNS (Domain Name System)
A hierarchical system that translates human-readable domain names into IP addresses, enabling browsers and applications to locate web services.
Azure Front Door
A scalable and secure entry point for fast delivery of global applications, providing load balancing and security features.

Recommended reading: datacenterdynamics.com

PhantomRaven Campaign Targets npm with Credential-Stealing Packages

High

What happened

An active campaign named 'PhantomRaven' has been identified, involving the deployment of 126 malicious npm packages designed to steal authentication tokens, CI/CD secrets, and GitHub credentials. These packages have been downloaded over 86,000 times since August 2025.

Who is affected

JavaScript developers utilizing npm packages, particularly those relying on AI-generated package recommendations, are at risk of integrating these malicious packages into their projects.

Why it matters

The infiltration of malicious packages into the npm ecosystem poses a significant threat to software supply chains. Compromised credentials can lead to unauthorized access, data breaches, and the potential for widespread supply chain attacks.

How it could have been prevented

Developers should verify the authenticity of npm packages before integration, avoid relying solely on AI-generated package recommendations, and regularly audit their projects for unauthorized dependencies.

Relevant professional terms

Slopsquatting
The practice of exploiting AI-generated, non-existent package names that appear legitimate to distribute malicious code.
Remote Dynamic Dependencies (RDD)
A technique where packages declare no dependencies but fetch and execute code from external sources during installation.

Recommended reading: Koi Security's Analysis of PhantomRaven Attack

Data Leak Exposes Students of Iran's MOIS Training Academy

High

What happened

An anonymous data leak exposed a list of over 1,000 individuals associated with Ravin Academy, an Iranian cybersecurity school linked to the government's advanced persistent threat (APT) group APT34.

Who is affected

Individuals affiliated with Ravin Academy, including students and staff, have had their identities disclosed.

Why it matters

The exposure of these individuals could compromise Iran's cyber operations and intelligence activities, potentially leading to retaliatory actions and increased geopolitical tensions.

How it could have been prevented

Implementing robust data protection measures, conducting regular security audits, and ensuring strict access controls could have mitigated the risk of such data leaks.

Relevant professional terms

Advanced Persistent Threat (APT)
A prolonged and targeted cyberattack in which an intruder gains access to a network and remains undetected for an extended period.
Hacktivism
The use of hacking to promote a political or social agenda.

Recommended reading: The No Good, Very Bad Week for Iran's Nation-State Hacking Ops

Dentsu's Merkle Subsidiary Suffers Data Breach Exposing Employee Information

High

What happened

Dentsu's subsidiary, Merkle, experienced a data breach where unauthorized access led to the theft of files containing sensitive information of current and former employees.

Who is affected

Current and former employees of Merkle, a division of Dentsu UK Limited, are affected by this breach.

Why it matters

The exposure of personal and financial data increases the risk of identity theft and financial fraud for the affected individuals.

How it could have been prevented

Implementing robust network monitoring to detect unusual activity promptly and ensuring comprehensive data encryption could have mitigated the risk of data exfiltration.

Relevant professional terms

Data Exfiltration
The unauthorized transfer of data from a computer or network.
Incident Response Protocols
Predefined procedures to detect, respond to, and recover from security incidents.

Recommended reading: Dentsu's Official Statement on the Data Security Incident