Team around laptop displaying lock with hexagonal shields showing cyber threats, exploits, and security vulnerabilities

Daily Dose of Cybersecurity News - September 23, 2025

Ransomware Attack Disrupts Major European Airports

High

What happened

A ransomware attack targeted Collins Aerospace's MUSE system, disrupting check-in and boarding operations at several major European airports.

Who is affected

Airports including Heathrow (London), Brussels Airport, Brandenburg (Berlin), Cork, and Dublin experienced operational disruptions.

Why it matters

The attack led to significant flight delays and cancellations, affecting thousands of passengers and highlighting vulnerabilities in critical aviation infrastructure.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system updates, network segmentation, and comprehensive incident response plans, could mitigate such attacks.

Relevant professional terms

Ransomware
Malicious software that encrypts data and demands payment for its release.
MUSE (Multi-User System Environment)
A system allowing multiple airlines to share check-in desks and boarding gates.

Recommended reading: Swissport Ransomware Attack Delays Flights, Disrupts Operations

Stellantis Data Breach via Third-Party Salesforce Platform

Medium

What happened

Attackers gained unauthorized access to a third-party service provider's platform supporting Stellantis' North American customer service operations, resulting in the theft of customer contact information.

Who is affected

North American customers of Stellantis, the multinational automotive corporation.

Why it matters

Exposure of customer contact information increases the risk of phishing attacks and other social engineering tactics targeting affected individuals.

How it could have been prevented

Implementing stringent security measures for third-party service providers, including regular security audits and enforcing multi-factor authentication, could have mitigated the risk of unauthorized access.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Third-Party Service Provider
An external organization that offers services or products to another company, often involving access to sensitive data or systems.

Recommended reading: BleepingComputer

EDR-Freeze Tool Exploits Windows WER to Suspend Security Software

High

What happened

A new proof-of-concept tool named EDR-Freeze has been developed, demonstrating that security solutions can be indefinitely suspended from user mode by exploiting Microsoft's Windows Error Reporting (WER) system.

Who is affected

Organizations utilizing endpoint detection and response (EDR) tools and antivirus software on Windows systems are potentially vulnerable to this technique.

Why it matters

This method allows attackers to disable security software without requiring kernel-level access or vulnerable drivers, making it more stealthy and harder to detect. It poses a significant risk to system integrity and data security.

How it could have been prevented

Implementing monitoring mechanisms to detect unusual behavior in the WER process and restricting its ability to interact with critical security processes can help mitigate this threat.

Relevant professional terms

Windows Error Reporting (WER)
A Windows feature that collects and sends error reports to Microsoft for analysis.
MiniDumpWriteDump API
A function in the DbgHelp library that creates a snapshot of a process's memory and state for debugging purposes.

Recommended reading: Zero Salarium

Malicious Password Managers Target Mac Users with AMOS Malware

High

What happened

Attackers are distributing fake password manager applications to macOS users via fraudulent GitHub repositories. These counterfeit apps install the Atomic (AMOS) info-stealing malware through deceptive installation commands.

Who is affected

macOS users seeking to download password managers and other popular software solutions are at risk of infection.

Why it matters

The AMOS malware can steal sensitive data from infected systems, including credentials and personal information. The addition of a backdoor component allows attackers to maintain persistent access, increasing the potential for prolonged exploitation.

How it could have been prevented

Users should download software exclusively from official vendor websites and avoid executing unfamiliar commands in the terminal. Verifying the authenticity of software sources can mitigate the risk of malware infection.

Relevant professional terms

Malware-as-a-Service (MaaS)
A business model where malware developers sell or lease their malicious software to others, often including support and updates.
ClickFix Attack
A social engineering technique that deceives users into executing malicious commands by presenting them as necessary fixes or updates.

Recommended reading: New MacStealer macOS malware steals passwords from iCloud Keychain

Shift in Phishing Tactics: Beyond Email-Based Attacks

High

What happened

Cyber attackers are increasingly utilizing non-email channels such as social media, instant messaging apps, and malicious search engine advertisements to distribute phishing links, moving beyond traditional email-based methods.

Who is affected

Organizations and individuals using decentralized internet applications and various communication platforms are at heightened risk due to this shift in phishing tactics.

Why it matters

The diversification of phishing delivery methods complicates detection and prevention efforts, as traditional email security measures may not effectively address threats originating from alternative channels.

How it could have been prevented

Implementing comprehensive security awareness training that encompasses all communication platforms and deploying advanced threat detection systems capable of monitoring multiple channels can mitigate the risk of such phishing attacks.

Relevant professional terms

Adversary-in-the-Middle (AitM)
A type of attack where the attacker intercepts and possibly alters communication between two parties who believe they are directly communicating with each other.
Malvertising
The use of online advertising to spread malware, often by injecting malicious code into legitimate advertisements.

Recommended reading: Why it's time for phishing prevention to move beyond email

Iran-Linked 'Nimbus Manticore' Targets European Critical Infrastructure with Advanced Malware

High

What happened

The Iranian cyber-espionage group known as "Nimbus Manticore" has expanded its operations beyond the Middle East, targeting critical infrastructure organizations in Western Europe using enhanced malware variants and sophisticated attack techniques.

Who is affected

Defense manufacturing, telecommunications, and aviation companies in Denmark, Portugal, and Sweden are the primary targets of these attacks.

Why it matters

The group's expansion into European critical infrastructure sectors signifies a heightened threat level, with potential implications for national security and economic stability in the affected regions.

How it could have been prevented

Implementing robust email filtering to detect and block spear-phishing attempts, conducting regular security awareness training for employees, and deploying advanced endpoint detection and response (EDR) solutions to identify and mitigate malware infections.

Relevant professional terms

Backdoor
A method by which authorized and unauthorized users can bypass normal security measures to gain high-level user access to a computer system, network, or software application.
Command-and-Control (C2) Server
A server used by attackers to maintain communications with compromised systems within a target network.

Recommended reading: Check Point Research: Nimbus Manticore Targets European Critical Infrastructure

Phony GitHub Repositories Distribute Atomic Infostealer to Mac Users

High

What happened

Threat actors are leveraging fake GitHub repositories and search engine optimization (SEO) poisoning to distribute the Atomic infostealer malware to Mac users. These repositories masquerade as legitimate software offerings, enticing users to execute malicious code.

Who is affected

Mac users seeking software from GitHub repositories, particularly those in the technology and financial sectors, are at risk of downloading and executing the Atomic infostealer.

Why it matters

The campaign exploits the trust users place in GitHub repositories and search engine results, potentially leading to widespread data theft and compromising sensitive information across various sectors.

How it could have been prevented

Users should verify the authenticity of software sources, download applications only from official or reputable platforms, and avoid executing unverified code. Employing up-to-date antivirus or endpoint detection and response (EDR) solutions can also mitigate such threats.

Relevant professional terms

SEO Poisoning
The manipulation of search engine algorithms to rank malicious websites higher in search results, increasing the likelihood of user visits.
Infostealer
A type of malware designed to gather and exfiltrate sensitive information from an infected system.

Recommended reading: LastPass Blog on Emerging Threat Campaign