Team at computers protected by shield with lock against hackers, chains, malware, and email threats

Daily Dose of Cybersecurity News - October 4, 2025

Signal Enhances Encryption with Sparse Post-Quantum Ratchet (SPQR)

High

What happened

Signal has introduced the Sparse Post-Quantum Ratchet (SPQR), a new cryptographic component designed to enhance the app's resistance against potential future quantum computing attacks.

Who is affected

All users of the Signal messaging application are impacted by this update, as it strengthens the security of their communications.

Why it matters

The advent of quantum computing poses a significant threat to current encryption methods. By implementing SPQR, Signal proactively safeguards user communications against future quantum-based decryption capabilities.

How it could have been prevented

While quantum computing threats are emerging, proactive adoption of post-quantum cryptographic methods, as demonstrated by Signal, is essential to mitigate potential future risks.

Relevant professional terms

Post-Quantum Cryptography
Cryptographic algorithms designed to be secure against the potential capabilities of quantum computers.
Forward Secrecy
A security feature ensuring that session keys will not be compromised even if long-term keys are compromised in the future.

Recommended reading: signal.org

Renault and Dacia UK Customer Data Breach via Third-Party Provider

High

What happened

A cyberattack on a third-party data processing provider resulted in the unauthorized access and theft of personal data belonging to Renault and Dacia UK customers.

Who is affected

Customers of Renault and Dacia in the United Kingdom who shared personal information with the carmaker.

Why it matters

The exposed data includes sensitive personal information, increasing the risk of targeted phishing attacks and identity theft for affected individuals.

How it could have been prevented

Implementing stringent security measures and regular audits for third-party providers to ensure compliance with data protection standards.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Third-Party Risk Management
The process of assessing and mitigating risks associated with outsourcing to external service providers.

Recommended reading: autocar.co.uk

Asahi Group Holdings Suffers Ransomware Attack Leading to Operational Disruptions

High

What happened

Asahi Group Holdings, Japan's largest beer producer, experienced a ransomware attack that disrupted its IT systems, leading to the suspension of operations at its domestic factories and affecting order processing, shipments, and call center services.

Who is affected

The attack impacted Asahi's domestic operations in Japan, affecting its employees, customers, and business partners. International operations remain unaffected.

Why it matters

The disruption has led to potential shortages of popular Asahi products, including Asahi Super Dry beer, across major retailers in Japan. This incident underscores the vulnerability of critical supply chains to cyberattacks and highlights the potential for significant economic and consumer impact.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system updates, network segmentation, employee training on phishing attacks, and comprehensive incident response plans, could have mitigated the risk and impact of such an attack.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system or data until a sum of money is paid.
Network Segmentation
The practice of dividing a computer network into smaller, isolated segments to improve security and performance.

Recommended reading: CISA Stop Ransomware

ShinyHunters Launches Data Leak Site to Extort 39 Companies

Critical

What happened

The cyber extortion group ShinyHunters has launched a data leak site to publicly extort 39 companies, leaking samples of data stolen from their Salesforce instances.

Who is affected

High-profile companies including FedEx, Disney/Hulu, Home Depot, Marriott, Google, Cisco, Toyota, Gap, McDonald's, Walgreens, Instacart, Cartier, Adidas, Saks Fifth Avenue, Air France & KLM, TransUnion, HBO MAX, UPS, Chanel, and IKEA.

Why it matters

The exposure of sensitive customer and corporate data can lead to financial losses, reputational damage, and regulatory penalties for the affected organizations.

How it could have been prevented

Implementing robust multi-factor authentication (MFA) for all access points, conducting regular security audits, and providing comprehensive employee training on recognizing and responding to social engineering attacks.

Relevant professional terms

Data Leak Site
A website used by cybercriminals to publicly release stolen data, often to pressure victims into paying ransoms.
Social Engineering
Manipulative tactics used by attackers to deceive individuals into divulging confidential information or granting unauthorized access.

Recommended reading: darkreading.com

CometJacking Attack Exploits Comet AI Browser to Steal Emails

High

What happened

A new attack method named 'CometJacking' exploits URL parameters to inject hidden instructions into Perplexity's Comet AI browser, enabling unauthorized access to sensitive data from connected services like email and calendar.

Who is affected

Users of Perplexity's Comet AI browser who have integrated it with their email and calendar services are at risk.

Why it matters

This vulnerability allows attackers to access and exfiltrate sensitive personal and organizational information without user credentials or interaction, posing significant privacy and security risks.

How it could have been prevented

Implementing strict input validation to sanitize URL parameters and enhancing security measures to detect and block prompt-injection attacks could mitigate such vulnerabilities.

Relevant professional terms

Prompt-Injection Attack
A type of attack where malicious instructions are embedded into inputs that are processed by AI systems, leading to unintended actions.
Agentic AI Browser
An AI-powered browser capable of autonomously performing tasks such as browsing, shopping, and managing online activities on behalf of the user.

Recommended reading: Perplexity’s Comet AI browser tricked into buying fake items online

Clop Ransomware Exploits Oracle E-Business Suite Vulnerabilities (CVE-2025-30745, CVE-2025-30746, CVE-2025-50107)

High

What happened

The Clop ransomware gang initiated an extortion campaign targeting organizations using Oracle E-Business Suite (EBS). They exploited vulnerabilities patched in Oracle's July 2025 Critical Patch Update to gain unauthorized access and exfiltrate sensitive data.

Who is affected

Organizations utilizing Oracle E-Business Suite that have not applied the July 2025 security patches are at risk of data breaches and extortion attempts by the Clop ransomware group.

Why it matters

Exploitation of these vulnerabilities can lead to significant data breaches, financial loss, and reputational damage. The Clop group's actions underscore the critical importance of timely application of security patches to prevent such attacks.

How it could have been prevented

Regularly applying Oracle's Critical Patch Updates promptly after release can mitigate the risk of exploitation. Additionally, monitoring systems for unusual activity and implementing robust access controls are essential preventive measures.

Relevant professional terms

Critical Patch Update (CPU)
A collection of patches for multiple security vulnerabilities, released on a regular schedule by Oracle.
Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to execute arbitrary code on a target system over a network.

Recommended reading: Oracle July 2025 Critical Patch Update

Jaguar Land Rover Cyberattack Leads to Data Breach and Operational Disruption

Critical

What happened

Jaguar Land Rover (JLR) experienced a significant cyberattack that led to the theft of sensitive data and forced the company to shut down its global IT systems, halting manufacturing and retail operations.

Who is affected

JLR's global operations, including manufacturing plants and retail services, were severely impacted, affecting employees, suppliers, and customers worldwide.

Why it matters

The attack underscores the vulnerability of large corporations to cyber threats, highlighting the potential for substantial financial losses and operational disruptions in the automotive industry.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system audits, employee training on phishing attacks, and establishing comprehensive incident response plans, could have mitigated the risk and impact of such an attack.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system until a sum of money is paid.
Incident Response Plan
A structured approach outlining the procedures to follow in the event of a cybersecurity incident.

Recommended reading: Dark Reading