
Daily Dose of Cybersecurity News - September 23, 2025
Ransomware Attack Disrupts Major European Airports
HighWhat happened
A ransomware attack targeted Collins Aerospace's MUSE system, disrupting check-in and boarding operations at several major European airports.
Who is affected
Airports including Heathrow (London), Brussels Airport, Brandenburg (Berlin), Cork, and Dublin experienced operational disruptions.
Why it matters
The attack led to significant flight delays and cancellations, affecting thousands of passengers and highlighting vulnerabilities in critical aviation infrastructure.
How it could have been prevented
Implementing robust cybersecurity measures, including regular system updates, network segmentation, and comprehensive incident response plans, could mitigate such attacks.
Relevant professional terms
- Ransomware
- Malicious software that encrypts data and demands payment for its release.
- MUSE (Multi-User System Environment)
- A system allowing multiple airlines to share check-in desks and boarding gates.
Recommended reading: Swissport Ransomware Attack Delays Flights, Disrupts Operations
Stellantis Data Breach via Third-Party Salesforce Platform
MediumWhat happened
Attackers gained unauthorized access to a third-party service provider's platform supporting Stellantis' North American customer service operations, resulting in the theft of customer contact information.
Who is affected
North American customers of Stellantis, the multinational automotive corporation.
Why it matters
Exposure of customer contact information increases the risk of phishing attacks and other social engineering tactics targeting affected individuals.
How it could have been prevented
Implementing stringent security measures for third-party service providers, including regular security audits and enforcing multi-factor authentication, could have mitigated the risk of unauthorized access.
Relevant professional terms
- Phishing
- A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
- Third-Party Service Provider
- An external organization that offers services or products to another company, often involving access to sensitive data or systems.
Recommended reading: BleepingComputer
EDR-Freeze Tool Exploits Windows WER to Suspend Security Software
HighWhat happened
A new proof-of-concept tool named EDR-Freeze has been developed, demonstrating that security solutions can be indefinitely suspended from user mode by exploiting Microsoft's Windows Error Reporting (WER) system.
Who is affected
Organizations utilizing endpoint detection and response (EDR) tools and antivirus software on Windows systems are potentially vulnerable to this technique.
Why it matters
This method allows attackers to disable security software without requiring kernel-level access or vulnerable drivers, making it more stealthy and harder to detect. It poses a significant risk to system integrity and data security.
How it could have been prevented
Implementing monitoring mechanisms to detect unusual behavior in the WER process and restricting its ability to interact with critical security processes can help mitigate this threat.
Relevant professional terms
- Windows Error Reporting (WER)
- A Windows feature that collects and sends error reports to Microsoft for analysis.
- MiniDumpWriteDump API
- A function in the DbgHelp library that creates a snapshot of a process's memory and state for debugging purposes.
Recommended reading: Zero Salarium
Malicious Password Managers Target Mac Users with AMOS Malware
HighWhat happened
Attackers are distributing fake password manager applications to macOS users via fraudulent GitHub repositories. These counterfeit apps install the Atomic (AMOS) info-stealing malware through deceptive installation commands.
Who is affected
macOS users seeking to download password managers and other popular software solutions are at risk of infection.
Why it matters
The AMOS malware can steal sensitive data from infected systems, including credentials and personal information. The addition of a backdoor component allows attackers to maintain persistent access, increasing the potential for prolonged exploitation.
How it could have been prevented
Users should download software exclusively from official vendor websites and avoid executing unfamiliar commands in the terminal. Verifying the authenticity of software sources can mitigate the risk of malware infection.
Relevant professional terms
- Malware-as-a-Service (MaaS)
- A business model where malware developers sell or lease their malicious software to others, often including support and updates.
- ClickFix Attack
- A social engineering technique that deceives users into executing malicious commands by presenting them as necessary fixes or updates.
Recommended reading: New MacStealer macOS malware steals passwords from iCloud Keychain
Shift in Phishing Tactics: Beyond Email-Based Attacks
HighWhat happened
Cyber attackers are increasingly utilizing non-email channels such as social media, instant messaging apps, and malicious search engine advertisements to distribute phishing links, moving beyond traditional email-based methods.
Who is affected
Organizations and individuals using decentralized internet applications and various communication platforms are at heightened risk due to this shift in phishing tactics.
Why it matters
The diversification of phishing delivery methods complicates detection and prevention efforts, as traditional email security measures may not effectively address threats originating from alternative channels.
How it could have been prevented
Implementing comprehensive security awareness training that encompasses all communication platforms and deploying advanced threat detection systems capable of monitoring multiple channels can mitigate the risk of such phishing attacks.
Relevant professional terms
- Adversary-in-the-Middle (AitM)
- A type of attack where the attacker intercepts and possibly alters communication between two parties who believe they are directly communicating with each other.
- Malvertising
- The use of online advertising to spread malware, often by injecting malicious code into legitimate advertisements.
Recommended reading: Why it's time for phishing prevention to move beyond email
Iran-Linked 'Nimbus Manticore' Targets European Critical Infrastructure with Advanced Malware
HighWhat happened
The Iranian cyber-espionage group known as "Nimbus Manticore" has expanded its operations beyond the Middle East, targeting critical infrastructure organizations in Western Europe using enhanced malware variants and sophisticated attack techniques.
Who is affected
Defense manufacturing, telecommunications, and aviation companies in Denmark, Portugal, and Sweden are the primary targets of these attacks.
Why it matters
The group's expansion into European critical infrastructure sectors signifies a heightened threat level, with potential implications for national security and economic stability in the affected regions.
How it could have been prevented
Implementing robust email filtering to detect and block spear-phishing attempts, conducting regular security awareness training for employees, and deploying advanced endpoint detection and response (EDR) solutions to identify and mitigate malware infections.
Relevant professional terms
- Backdoor
- A method by which authorized and unauthorized users can bypass normal security measures to gain high-level user access to a computer system, network, or software application.
- Command-and-Control (C2) Server
- A server used by attackers to maintain communications with compromised systems within a target network.
Recommended reading: Check Point Research: Nimbus Manticore Targets European Critical Infrastructure
Phony GitHub Repositories Distribute Atomic Infostealer to Mac Users
HighWhat happened
Threat actors are leveraging fake GitHub repositories and search engine optimization (SEO) poisoning to distribute the Atomic infostealer malware to Mac users. These repositories masquerade as legitimate software offerings, enticing users to execute malicious code.
Who is affected
Mac users seeking software from GitHub repositories, particularly those in the technology and financial sectors, are at risk of downloading and executing the Atomic infostealer.
Why it matters
The campaign exploits the trust users place in GitHub repositories and search engine results, potentially leading to widespread data theft and compromising sensitive information across various sectors.
How it could have been prevented
Users should verify the authenticity of software sources, download applications only from official or reputable platforms, and avoid executing unverified code. Employing up-to-date antivirus or endpoint detection and response (EDR) solutions can also mitigate such threats.
Relevant professional terms
- SEO Poisoning
- The manipulation of search engine algorithms to rank malicious websites higher in search results, increasing the likelihood of user visits.
- Infostealer
- A type of malware designed to gather and exfiltrate sensitive information from an infected system.
Recommended reading: LastPass Blog on Emerging Threat Campaign