Multiple hackers surrounding central laptop displaying code with shields, locks, malware, and cloud threats visible

Daily Dose of Cybersecurity News - September 30, 2025

Cyberattack Disrupts Asahi Group's Operations

High

What happened

Asahi Group Holdings, Ltd., Japan's largest brewer, experienced a cyberattack that led to a system failure, disrupting ordering, shipping, and customer service operations.

Who is affected

The cyberattack impacted Asahi's Japan-based operations, affecting employees, customers, and partners relying on its services.

Why it matters

Asahi holds approximately one-third of Japan's domestic beer market and reported nearly $20 billion in revenue in 2024. Operational disruptions can have significant economic implications and may indicate vulnerabilities in critical infrastructure.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system audits, employee training on phishing and social engineering, and maintaining up-to-date security protocols, could mitigate such risks.

Relevant professional terms

System Failure
A malfunction or breakdown in a computer system that prevents it from operating correctly.
Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.

Recommended reading: BleepingComputer

Ransomware Gang Attempts to Recruit BBC Reporter for Insider Attack

High

What happened

A cybercriminal, identifying as "Syndicate" from the Medusa ransomware group, contacted BBC cybersecurity correspondent Joe Tidy via Signal in July, offering a substantial financial incentive to facilitate unauthorized access to the BBC's internal systems for a ransomware attack.

Who is affected

The British Broadcasting Corporation (BBC) was the intended target, with journalist Joe Tidy being approached to act as an insider.

Why it matters

This incident highlights the evolving tactics of ransomware groups, including the recruitment of insiders to bypass external security measures, posing significant risks to organizational integrity and data security.

How it could have been prevented

Implementing comprehensive insider threat detection programs and conducting regular security awareness training can help mitigate the risk of such recruitment attempts.

Relevant professional terms

Insider Threat
A security risk originating from within the organization, often involving employees or partners who have access to sensitive information.
Ransomware
Malicious software designed to block access to a computer system or data until a sum of money is paid.

Recommended reading: BBC News: Ransomware gang sought BBC reporter's help in hacking media giant

UK Government Provides £1.5 Billion Loan Guarantee to JLR Post-Cyberattack

High

What happened

Jaguar Land Rover (JLR) suffered a severe cyberattack that disrupted its production operations. In response, the UK Government has provided a £1.5 billion loan guarantee to assist JLR in restoring its supply chain.

Who is affected

Jaguar Land Rover, its suppliers, employees, and the broader UK automotive sector.

Why it matters

The cyberattack on JLR not only impacts a leading British automotive manufacturer but also poses risks to the UK's automotive industry and associated jobs. The government's intervention aims to stabilize the supply chain and protect employment.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system audits, employee training on phishing attacks, and establishing comprehensive incident response plans.

Relevant professional terms

Loan Guarantee
A commitment by a guarantor (in this case, the UK Government) to assume the debt obligation of a borrower if they default.
Supply Chain
The network between a company and its suppliers to produce and distribute a specific product.

Recommended reading: UK Government Announcement

Harrods Data Breach Exposes 430,000 Customer Records

High

What happened

Hackers compromised a third-party supplier associated with Harrods, leading to the theft of 430,000 e-commerce customer records containing sensitive information.

Who is affected

Harrods' e-commerce customers whose data was stored by the compromised third-party supplier.

Why it matters

The breach exposes a significant number of customers to potential phishing attacks and identity theft, highlighting vulnerabilities in third-party vendor security.

How it could have been prevented

Implementing stringent security assessments and continuous monitoring of third-party vendors; ensuring data minimization practices to limit the amount of sensitive information stored by external partners.

Relevant professional terms

Third-Party Risk Management (TPRM)
The process of identifying, assessing, and controlling risks associated with outsourcing to third-party vendors or service providers.
Data Exfiltration
The unauthorized transfer of data from a computer or network, often conducted by cybercriminals to steal sensitive information.

Recommended reading: periculo.co.uk

IoT Security Challenges Amid Rising Threats

High

What happened

The proliferation of Internet of Things (IoT) devices has outpaced the implementation of adequate security measures, leaving systems vulnerable to attacks such as distributed denial-of-service (DDoS) and data breaches. Efforts to establish government-backed security standards for these devices are progressing slowly.

Who is affected

Organizations and individuals utilizing IoT devices, including smart office equipment, medical devices, and agricultural machinery, are at increased risk due to these security gaps.

Why it matters

The widespread adoption of IoT devices without robust security measures exposes critical infrastructure and personal data to potential cyberattacks, emphasizing the need for standardized security protocols.

How it could have been prevented

Implementing standardized security frameworks for IoT devices and ensuring regular software updates and patches could mitigate these vulnerabilities.

Relevant professional terms

Distributed Denial-of-Service (DDoS)
A cyberattack where multiple systems overwhelm a target, such as a server, website, or network, with a flood of internet traffic, causing disruption of services.
Internet of Things (IoT)
A network of physical devices embedded with sensors, software, and other technologies to connect and exchange data with other devices and systems over the internet.

Recommended reading: Most Security Pros Expect to Suffer Cyberattacks via Unsecured IoT

Malicious MCP Server 'postmark-mcp' Exfiltrates Sensitive Data via BCC

High

What happened

A malicious Model Context Protocol (MCP) server named 'postmark-mcp' was discovered on the npm repository, designed to exfiltrate sensitive data by blind carbon copying (BCC) emails to a threat actor.

Who is affected

Approximately 1,500 organizations that downloaded the 'postmark-mcp' package, with an estimated 300 actively using it, are potentially sending sensitive information to cybercriminals.

Why it matters

The compromised MCP server allows unauthorized access to confidential data, including passwords, API keys, and financial details, posing significant security and privacy risks to affected organizations.

How it could have been prevented

Organizations should verify the authenticity of packages by sourcing them from official repositories and implement approval processes for integrating third-party tools.

Relevant professional terms

Model Context Protocol (MCP)
A protocol that enables AI applications to connect with external data and tools, facilitating integration with services like email platforms.
Blind Carbon Copy (BCC)
An email feature that sends copies of a message to recipients without revealing their addresses to other recipients.

Recommended reading: Koi Security Blog on Malicious MCP Server

Akira Ransomware Exploits SonicWall VPN Vulnerability (CVE-2024-40766)

Critical

What happened

The Akira ransomware group exploited a critical vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices, enabling unauthorized access and deployment of ransomware across multiple sectors.

Who is affected

Organizations using vulnerable SonicWall SSL VPN devices, including NSA and TZ series running specific versions of SonicOS, are impacted.

Why it matters

The exploitation of this vulnerability allows attackers to bypass multi-factor authentication, leading to rapid ransomware deployment and significant operational disruptions.

How it could have been prevented

Regularly updating firmware to the latest versions and implementing robust monitoring of VPN access logs could have mitigated the risk.

Relevant professional terms

SSL VPN
A type of virtual private network that uses the Secure Sockets Layer protocol to provide secure remote access to an organization's network.
Multi-Factor Authentication (MFA)
A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity.

Recommended reading: arcticwolf.com