Group of masked hackers around multiple screens displaying code with shields, warnings, and threat icons above

Daily Dose of Cybersecurity News - October 9, 2025

Discord Data Breach Exposes User Information

High

What happened

Hackers claim to have accessed Discord's customer support system, allegedly compromising data of 5.5 million users, including government IDs and partial payment information.

Who is affected

Approximately 70,000 users had their government ID photos exposed; the total number of affected users is disputed.

Why it matters

The breach raises concerns about the security of third-party services and the potential for identity theft and financial fraud among affected users.

How it could have been prevented

Implementing stricter access controls and regular security audits for third-party service providers.

Relevant professional terms

Third-Party Service Provider
An external organization that offers services to another company, often handling sensitive data.
Data Breach
An incident where unauthorized individuals gain access to confidential information.

Recommended reading: Infosecurity Magazine

FileFix Attack Employs Cache Smuggling to Evade Security Measures

High

What happened

A new variant of the FileFix social engineering attack utilizes cache smuggling to covertly download a malicious ZIP archive onto a victim’s system, effectively bypassing security software.

Who is affected

Organizations and individuals using Fortinet VPN services are targeted through phishing campaigns impersonating a "Fortinet VPN Compliance Checker."

Why it matters

This attack demonstrates an evolution in social engineering tactics, combining cache smuggling with FileFix techniques to evade detection, posing significant risks to network security.

How it could have been prevented

Implementing strict user education programs to recognize and avoid phishing attempts, and enhancing endpoint security solutions to detect and block unconventional attack vectors.

Relevant professional terms

Cache Smuggling
A technique where attackers manipulate web cache mechanisms to store and deliver malicious content to users.
FileFix Attack
A social engineering method that tricks users into executing malicious commands via the Windows File Explorer address bar.

Recommended reading: Expel Blog on Cache Smuggling

Qilin Ransomware Attack on Asahi Brewery

High

What happened

The Qilin ransomware group claimed responsibility for a cyberattack on Asahi, Japan's largest brewing company, exfiltrating over 9,300 files totaling 27GB of data, including internal financial documents, employee IDs, confidential contracts, and internal reports.

Who is affected

Asahi Group Holdings, a major Japanese brewing company with 30,000 employees and annual revenue of $20 billion, was directly impacted by this attack.

Why it matters

The breach led to the suspension of operations at six Asahi facilities, disrupting production and potentially causing significant financial losses. The exposure of sensitive internal documents also raises concerns about data privacy and corporate security.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system updates, employee training on phishing attacks, and comprehensive incident response plans, could have mitigated the risk and impact of such ransomware attacks.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system or data until a ransom is paid.
Data Exfiltration
Unauthorized transfer of data from a computer or network.

Recommended reading: Linux version of Qilin ransomware focuses on VMware ESXi

Crimson Collective Exploits AWS Environments for Data Theft

High

What happened

The 'Crimson Collective' threat group has been targeting AWS cloud environments to steal data and extort companies. They claimed responsibility for exfiltrating 570 GB of data from thousands of private GitLab repositories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/crimson-collective-hackers-target-aws-cloud-instances-for-data-theft/amp/?utm_source=openai))

Who is affected

Organizations utilizing AWS cloud services, particularly those with exposed credentials or misconfigured IAM policies, are at risk. Red Hat was specifically targeted in this campaign. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/crimson-collective-hackers-target-aws-cloud-instances-for-data-theft/amp/?utm_source=openai))

Why it matters

This attack underscores the critical importance of securing cloud environments. Unauthorized access can lead to significant data breaches, financial loss, and reputational damage. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/crimson-collective-hackers-target-aws-cloud-instances-for-data-theft/amp/?utm_source=openai))

How it could have been prevented

Regularly rotate and limit the lifespan of AWS access keys. Implement the principle of least privilege in IAM policies to restrict access rights. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/crimson-collective-hackers-target-aws-cloud-instances-for-data-theft/amp/?utm_source=openai))

Relevant professional terms

IAM (Identity and Access Management)
A framework of policies and technologies ensuring that the right individuals have appropriate access to technology resources.
Privilege Escalation
The act of exploiting a bug, design flaw, or configuration oversight to gain elevated access to resources that are normally protected.

Recommended reading: Red Hat confirms security incident after hackers breach GitLab instance

Critical Authentication Bypass in Service Finder WordPress Theme (CVE-2025-5947)

Critical

What happened

A critical vulnerability (CVE-2025-5947) in the Service Finder WordPress theme allows unauthenticated attackers to log in as any user, including administrators, by exploiting improper validation of the original_user_id cookie in the service_finder_switch_back() function.

Who is affected

Websites using Service Finder versions 6.0 and older are vulnerable to this authentication bypass exploit.

Why it matters

Exploitation of this vulnerability grants attackers full administrative control over affected WordPress sites, enabling them to modify content, create accounts, upload malicious files, and access sensitive data.

How it could have been prevented

Implementing proper validation of user input, particularly cookies, and adhering to secure coding practices could have prevented this vulnerability.

Relevant professional terms

Authentication Bypass
A security flaw that allows unauthorized users to gain access to a system without proper credentials.
Privilege Escalation
The process by which an attacker gains higher access rights than originally granted, often leading to full administrative control.

Recommended reading: Patchstack Advisory on CVE-2025-5947

London Police Arrest Two Teens for Nursery Data Breach and Child Doxing

High

What happened

Two 17-year-old individuals were arrested in Bishop's Stortford, Hertfordshire, on suspicion of blackmail and computer misuse following a ransomware attack on the Kido nursery chain. The attackers allegedly stole sensitive data and photos of over 1,000 children and leaked some of this information online to extort the nursery.

Who is affected

Families associated with Kido International's nurseries in Greater London, which serve over 15,000 families across multiple countries, were impacted by the data breach and subsequent doxing.

Why it matters

The exposure of children's personal data poses significant privacy and safety risks, including potential identity theft and endangerment. This incident underscores the critical need for robust cybersecurity measures in organizations handling sensitive information.

How it could have been prevented

Implementing comprehensive cybersecurity protocols, including regular system audits, employee training on phishing and social engineering attacks, and robust data encryption, could have mitigated the risk of such breaches.

Relevant professional terms

Doxing
The act of publicly revealing previously private personal information about an individual or organization, typically via the internet.
Ransomware
A type of malicious software designed to block access to a computer system or data, usually by encrypting it, until a ransom is paid.

Recommended reading: National Cyber Security Centre: Ransomware Guidance

Vampire Bot Malware Targets Job Seekers

High

What happened

A Vietnam-based threat group, BatShadow, is conducting phishing campaigns targeting job seekers and digital marketing professionals. The attackers distribute zip archives containing lure PDFs and hidden malicious files that, when opened, install a surveillance malware named Vampire Bot.

Who is affected

Individuals seeking employment and professionals in digital marketing sectors are the primary targets of this campaign.

Why it matters

Vampire Bot enables continuous desktop surveillance by capturing screenshots at configurable intervals and exfiltrating them over encrypted channels. This grants attackers substantial visibility and control over compromised systems, posing significant privacy and security risks.

How it could have been prevented

- Exercise caution when opening email attachments, especially from unknown or untrusted sources. - Implement robust endpoint protection solutions capable of detecting and blocking malicious payloads.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information or downloading malicious software.
Command and Control (C2) Server
A server used by attackers to send commands to compromised systems and receive stolen data.

Recommended reading: Aryaka's Analysis of Vampire Bot Malware