Multiple hackers attacking connected devices and cloud network

October 31, 2025 - Daily Cybersecurity News

Massive Surge of NFC Relay Malware Stealing European Credit Cards

High

What happened

Over 760 malicious Android applications have been identified exploiting Near-Field Communication (NFC) relay techniques to steal payment card information across Eastern Europe. These apps misuse Android's Host Card Emulation (HCE) to emulate or capture contactless credit card data, enabling unauthorized transactions without the physical cardholder's presence.

Who is affected

Individuals and financial institutions in Eastern Europe, particularly in Poland, the Czech Republic, and Russia, are the primary targets of these NFC relay malware attacks.

Why it matters

The rapid proliferation of NFC relay malware poses a significant threat to the security of contactless payment systems, leading to potential financial losses for consumers and reputational damage for financial institutions. The sophistication of these attacks makes detection and prevention more challenging.

How it could have been prevented

Implementing robust security measures such as multi-factor authentication for transactions, educating users about the risks of downloading unverified applications, and enhancing monitoring systems to detect unusual transaction patterns could mitigate the impact of such malware.

Relevant professional terms

Near-Field Communication (NFC)
A short-range wireless technology that enables data exchange between devices in close proximity, commonly used for contactless payments.
Host Card Emulation (HCE)
A technology that allows software emulation of a payment card on a mobile device, enabling it to perform contactless transactions without needing a physical card.

Recommended reading: Kaspersky Blog on NFC Carding Theft

CISA Directs Federal Agencies to Patch Exploited VMware Tools Vulnerability (CVE-2025-41244)

High

What happened

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. federal agencies address a high-severity vulnerability (CVE-2025-41244) in VMware Aria Operations and VMware Tools, which has been actively exploited by Chinese state-sponsored hackers since October 2024.

Who is affected

Federal Civilian Executive Branch (FCEB) agencies utilizing VMware Aria Operations and VMware Tools are directly impacted. The exploitation has been attributed to the Chinese state-sponsored threat actor UNC5174.

Why it matters

The vulnerability allows local attackers with non-administrative privileges on a virtual machine to escalate their access to root, potentially leading to full system compromise. Given the active exploitation by a nation-state actor, the risk to sensitive government data and operations is significant.

How it could have been prevented

Timely application of security patches upon their release and continuous monitoring for unusual activity could have mitigated the risk associated with this vulnerability.

Relevant professional terms

Privilege Escalation
The process by which an attacker gains higher-level permissions on a system than were originally granted.
Zero-Day Vulnerability
A software flaw that is unknown to the vendor and for which no official patch or fix is available at the time of discovery.

Recommended reading: CISA Known Exploited Vulnerabilities Catalog

Nation-State Hackers Breach Ribbon Communications' IT Network

High

What happened

Nation-state hackers infiltrated Ribbon Communications' IT network, with unauthorized access potentially dating back to December 2024. The breach was detected in early September 2025. Investigations are ongoing to determine the full extent of the intrusion.

Who is affected

Ribbon Communications, a major provider of telecommunications services to entities such as the U.S. Department of Defense, Verizon, and Deutsche Telekom, is the primary victim. Three customers have been notified of potential data access.

Why it matters

The prolonged undetected access by state-sponsored actors poses significant risks, including potential espionage and disruption of critical communication infrastructures. The involvement of high-profile clients amplifies the potential impact.

How it could have been prevented

Implementing continuous network monitoring and anomaly detection systems could have identified unauthorized access sooner. Regular security audits and penetration testing might have uncovered vulnerabilities exploited by the attackers.

Relevant professional terms

Nation-State Actor
A government-sponsored group or individual engaged in cyber activities to achieve national objectives.
Penetration Testing
A simulated cyber attack against a computer system to check for exploitable vulnerabilities.

Recommended reading: SecurityWeek

Conduent Data Breach Exposes Personal Information of Over 10.5 Million Individuals

Critical

What happened

Conduent, a major business process outsourcing company, experienced a data breach where unauthorized access to their systems occurred from October 21, 2024, to January 13, 2025, leading to the exposure of sensitive personal information.

Who is affected

Over 10.5 million individuals across multiple U.S. states, including Texas, Oregon, Washington, and Maine, have had their personal data compromised.

Why it matters

The breach involves sensitive data such as Social Security numbers, medical information, and health insurance details, posing significant risks of identity theft and fraud for the affected individuals.

How it could have been prevented

Implementing robust network monitoring to detect unauthorized access promptly and conducting regular security audits to identify and mitigate vulnerabilities.

Relevant professional terms

Data Breach
An incident where unauthorized individuals gain access to confidential data.
Personally Identifiable Information (PII)
Information that can be used to identify an individual, such as name, Social Security number, and date of birth.

Recommended reading: therecord.media

Ex-L3Harris Executive Convicted for Selling Cyber Exploits to Russian Broker

Critical

What happened

Peter Williams, a former general manager at L3Harris Trenchant, admitted to stealing and selling confidential cybersecurity information, including at least eight sensitive cyber-exploit components, to a Russian vulnerability exploit broker between 2022 and 2025.

Who is affected

The U.S. government and its select allies, who were the intended recipients of the stolen cyber-exploit components.

Why it matters

The unauthorized sale of sensitive cyber-exploit components to foreign entities poses significant national security risks, potentially enabling adversaries to exploit vulnerabilities in critical systems.

How it could have been prevented

Implementing stringent access controls, continuous monitoring of sensitive data, and conducting regular audits to detect and prevent unauthorized data exfiltration.

Relevant professional terms

Cyber-exploit
A piece of code or technique that takes advantage of a vulnerability in software or hardware to execute unauthorized actions.
Data exfiltration
The unauthorized transfer of data from a computer or network, often with malicious intent.

Recommended reading: justice.gov

CISA and NSA Release Guidance on Securing Microsoft Exchange Servers

High

What happened

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have issued joint guidance to assist IT administrators in securing Microsoft Exchange servers against potential cyber threats.

Who is affected

Organizations utilizing on-premises or hybrid Microsoft Exchange servers are the primary audience for this guidance.

Why it matters

Microsoft Exchange servers are critical components of organizational communication infrastructure. Unsecured servers can be exploited by attackers, leading to data breaches, unauthorized access, and potential operational disruptions.

How it could have been prevented

Implementing the recommended security measures, such as restricting administrative access, enforcing multifactor authentication, and decommissioning outdated servers, can significantly reduce the risk of exploitation.

Relevant professional terms

Multifactor Authentication (MFA)
A security process that requires users to provide multiple forms of verification to access a system, enhancing security beyond just a password.
Zero Trust Security Model
A security concept that assumes threats could be internal or external and requires strict verification for every person and device attempting to access resources on a network.

Recommended reading: CISA Emergency Directive 25-02: Mitigate Microsoft Exchange Vulnerability

LinkedIn Phishing Campaign Targets Finance Executives with Fake Board Invitations

High

What happened

Cybercriminals are conducting a phishing campaign on LinkedIn, sending direct messages that impersonate invitations to join the executive board of a fictitious investment fund, aiming to steal Microsoft credentials.

Who is affected

Finance executives and professionals active on LinkedIn are the primary targets of this phishing scheme.

Why it matters

This attack exploits the trust associated with professional networking platforms, potentially leading to unauthorized access to sensitive corporate information and financial data.

How it could have been prevented

Implementing multi-factor authentication (MFA) for Microsoft accounts and conducting regular security awareness training can help prevent such phishing attacks.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Multi-Factor Authentication (MFA)
A security process that requires users to provide multiple forms of verification to gain access to a system.

Recommended reading: LinkedIn accounts hacked in widespread hijacking campaign