Business team around laptop displaying large shield with head icon surrounded by hexagonal security symbols

Daily Dose of Cybersecurity News - September 12, 2025

Stark Industries Solutions Evades EU Sanctions Through Rebranding

High

What happened

Stark Industries Solutions, a bulletproof hosting provider known for supporting Kremlin-linked cyberattacks, rebranded and transferred assets to evade European Union sanctions imposed in May 2025.

Who is affected

Organizations and individuals targeted by cyberattacks facilitated through Stark Industries' services, as well as entities involved in enforcing EU sanctions.

Why it matters

The rebranding and asset transfer highlight the challenges in enforcing sanctions against cybercriminal infrastructure, allowing continued support for malicious activities despite regulatory efforts.

How it could have been prevented

Implementing more robust monitoring and enforcement mechanisms to detect and disrupt rebranding and asset transfer strategies used to circumvent sanctions.

Relevant professional terms

Bulletproof Hosting
A hosting service that ignores abuse complaints and legal requests, often used to support illicit activities.
Rebranding
Changing the name and identity of a company to evade detection or sanctions.

Recommended reading: Stark Industries Solutions: An Iron Hammer in the Cloud

U.S. Senator Accuses Microsoft of Cybersecurity Negligence

High

What happened

U.S. Senator Ron Wyden has formally requested the Federal Trade Commission (FTC) to investigate Microsoft for alleged cybersecurity negligence, citing the company's failure to address known security vulnerabilities that led to ransomware attacks on critical infrastructure.

Who is affected

Microsoft and organizations utilizing its products, particularly those in critical infrastructure sectors like healthcare.

Why it matters

The alleged negligence has reportedly resulted in significant data breaches, including the 2024 Ascension Health ransomware attack that compromised the data of 5.6 million patients, highlighting potential risks to sensitive information and operational continuity.

How it could have been prevented

Implementing timely security patches, conducting regular security audits, and providing comprehensive user training on recognizing and avoiding phishing attempts.

Relevant professional terms

Kerberos
A network authentication protocol designed to provide strong authentication for client/server applications.
Kerberoasting
A post-compromise attack technique where attackers extract service account credentials from Active Directory for offline cracking.

Recommended reading: BleepingComputer

Apple Alerts Users to Mercenary Spyware Attacks

Critical

What happened

Apple has issued multiple threat notifications to users across 92 countries, warning them of targeted mercenary spyware attacks aimed at remotely compromising their devices.

Who is affected

Individuals such as journalists, activists, politicians, and diplomats are primarily targeted due to their roles or the sensitive information they may possess.

Why it matters

These sophisticated attacks exploit zero-day vulnerabilities and often require no user interaction, posing significant risks to personal privacy and national security.

How it could have been prevented

Regularly updating devices to the latest software versions and enabling security features like Lockdown Mode can mitigate the risk of such attacks.

Relevant professional terms

Zero-day vulnerability
A software flaw unknown to the vendor, exploited by attackers before a fix is available.
Lockdown Mode
A security feature introduced by Apple to protect high-risk users from sophisticated cyberattacks.

Recommended reading: Apple’s new Lockdown Mode defends against government spyware

Panama Ministry of Economy Targeted by INC Ransomware Group

High

What happened

The INC Ransomware group claims to have infiltrated Panama's Ministry of Economy and Finance (MEF), alleging the exfiltration of over 1.5 terabytes of sensitive data, including internal emails and financial documents. The group has released samples on the dark web and is threatening further leaks if the ministry does not engage with them.

Who is affected

The Panama Ministry of Economy and Finance, responsible for national fiscal policies and managing Panama Canal revenues, is the primary entity affected by this breach.

Why it matters

The potential exposure of sensitive financial data and internal communications poses significant risks to Panama's economic stability and could undermine public trust in governmental institutions.

How it could have been prevented

Implementing robust endpoint detection and response (EDR) solutions, conducting regular security audits, and ensuring timely software updates could have mitigated the risk of such breaches.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system or data until a ransom is paid.
Data Exfiltration
Unauthorized transfer of data from a computer or network.

Recommended reading: BreachSense

Akira Ransomware Exploits SonicWall SSLVPN Vulnerability CVE-2024-40766

Critical

What happened

The Akira ransomware group is actively exploiting CVE-2024-40766, a critical access control vulnerability in SonicWall SSLVPN devices, to gain unauthorized access to target networks.

Who is affected

Organizations using unpatched SonicWall SSLVPN devices are at risk of unauthorized access and potential ransomware attacks.

Why it matters

Exploitation of this vulnerability can lead to significant data breaches, operational disruptions, and financial losses due to ransomware deployment.

How it could have been prevented

Applying the security patch released by SonicWall in August 2024 and resetting all local user passwords for SSLVPN accounts would have mitigated the risk.

Relevant professional terms

Access Control Vulnerability
A security flaw that allows unauthorized users to access restricted resources or systems.
SSLVPN (Secure Sockets Layer Virtual Private Network)
A VPN that uses SSL protocol to secure data transmission over the internet.

Recommended reading: SonicWall Security Advisory on CVE-2024-40766

VMScape Attack Compromises Guest-Host Isolation on AMD and Intel CPUs

High

What happened

Researchers have identified a new speculative execution attack named VMScape, which enables a malicious virtual machine (VM) to extract cryptographic keys from an unmodified QEMU hypervisor process on modern AMD and Intel CPUs.

Who is affected

Organizations utilizing AMD processors from Zen 1 to Zen 5, and Intel's "Coffee Lake" CPUs running unmodified QEMU hypervisors are vulnerable.

Why it matters

This vulnerability undermines the isolation between VMs and the cloud hypervisor, potentially allowing attackers to access sensitive data across virtual environments, posing significant risks to cloud service providers and their clients.

How it could have been prevented

Implementing comprehensive speculative execution mitigations, regularly updating hypervisor software, and applying CPU microcode updates can help prevent such attacks.

Relevant professional terms

Speculative Execution
A CPU performance optimization technique where the processor predicts and executes instructions before they are confirmed to be needed.
Hypervisor
Software that creates and manages virtual machines by abstracting hardware resources.

Recommended reading: New Spectre v2 attack impacts Linux systems on Intel CPUs

'Gentlemen' Ransomware Exploits Vulnerable Driver to Disable Security Software

High

What happened

The 'Gentlemen' ransomware group has been observed utilizing a vulnerable driver, ThrottleStop.sys, to disable antivirus and endpoint detection and response (EDR) systems, facilitating the encryption of files without interference.

Who is affected

Organizations employing ThrottleStop.sys and similar drivers are at risk, as the 'Gentlemen' ransomware targets these vulnerabilities to compromise security defenses.

Why it matters

This tactic allows ransomware to bypass security measures effectively, leading to potential data breaches and operational disruptions.

How it could have been prevented

Implementing zero-trust controls and monitoring for unusual process combinations can help detect and prevent such attacks.

Relevant professional terms

Bring-Your-Own-Vulnerable-Driver (BYOVD) Attack
A technique where attackers use legitimate but vulnerable drivers to execute malicious code with elevated privileges.
Endpoint Detection and Response (EDR)
Security solutions focused on detecting, investigating, and responding to suspicious activities on endpoint devices.

Recommended reading: Know Thy Enemy: Fighting Half-Blind Against Ransomware Won't Work