Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Global Cyber Landscape Shrouded in Malware: Security Threats Lurk Around Every Corner



A global cyber landscape shrouded in malware is a harsh reality that organizations and individuals must confront head-on. In this edition of the Security Affairs Malware Newsletter Round 63, we delve into some of the most pressing issues affecting the cybersecurity world. From major cyberattacks to vulnerabilities in software applications, the threats are relentless and the stakes have never been higher.

  • A recent cyberattack on Collins Aerospace disrupted operations at major European airports, highlighting the potential for malware to have far-reaching consequences.
  • Fortra addressed a maximum severity flaw in GoAnywhere MFT software, which was discovered by researchers from the security firm.
  • UK police arrested two teenage members of Scattered Spider, a group linked to the 2024 attack on Transport for London.
  • ShadowLeak uncovered a zero-click attack on ChatGPT that leverages advanced techniques to infect systems without user interaction.
  • SonicWall warned customers to reset their credentials after MySonicWall backups were exposed due to a security vulnerability.
  • A zero-day exploit, CVE-2025-10585, affected the Chrome browser and was patched by Google in 2025.
  • Jaguar Land Rover extended its production halt due to a cyberattack that compromised sensitive data.
  • China-linked APT41 targeted government, think tanks, and academics tied to US-China trade and policy.
  • Microsoft and Cloudflare teamed up to dismantle RaccoonO365 phishing service.
  • The DoJ resentenced former BreachForums admin to three years in prison for his role in a data breach.
  • A backport fix for CVE-2025-43300 was released by Apple.
  • A new supply chain attack hit the npm registry, compromising 40+ packages.
  • Cybercrime group accessed Google Law Enforcement Request System (LERS) without authorization.
  • China-linked Mustang Panda deployed advanced SnakeDisk USB worm.
  • Insider breach at FinWise Bank exposed data of 689,000 AFF customers.
  • Hackers stole millions of Gucci, Balenciaga, and Alexander McQueen customer records.
  • Fairmont Federal Credit Union 2023 data breach impacted 187K people.
  • UK ICO finds students behind majority of school data breaches.


  • The cybersecurity landscape has never been more complex, with threats emanating from every direction. In this edition of the Security Affairs Malware Newsletter Round 63, we delve into some of the most pressing issues affecting individuals and organizations worldwide.

    A recent cyberattack on Collins Aerospace disrupted operations at major European airports, highlighting the potential for malware to have far-reaching consequences. The attack, which is believed to have been carried out by a group of hackers, exposed vulnerabilities in the company's systems that could have had devastating effects on air travel. As we move forward in this era of digital transformation, it has become increasingly clear that cybersecurity must be prioritized to prevent such incidents.

    Meanwhile, Fortra addressed a maximum severity flaw in GoAnywhere MFT software, which was discovered by researchers from the security firm. The vulnerability, known as CVE-2025-10585, is believed to have been actively exploited by attackers. This incident serves as a reminder of the importance of regular updates and patches for software applications.

    In another development, UK police arrested two teenage members of Scattered Spider, a group linked to the 2024 attack on Transport for London. The arrests bring some much-needed closure to the case, but it also underscores the ongoing threat posed by hacktivist groups like Scattered Spider.

    Furthermore, ShadowLeak, a security firm, uncovered a zero-click attack on ChatGPT that leverages advanced techniques to infect systems without user interaction. This finding highlights the evolving nature of cyber threats and the need for organizations to stay vigilant in the face of emerging malware.

    SonicWall warned customers to reset their credentials after MySonicWall backups were exposed due to a security vulnerability. This incident underscores the importance of robust security measures, particularly when it comes to data backup systems.

    The Chrome browser has also been affected by a zero-day exploit, CVE-2025-10585, which was patched by Google in 2025. This highlights the ongoing struggle between attackers and defenders as they engage in a cat-and-mouse game.

    Jaguar Land Rover extended its production halt due to a cyberattack that compromised sensitive data. The incident serves as a reminder of the potential risks associated with cybersecurity breaches and the importance of investing in robust security measures.

    China-linked APT41 targeted government, think tanks, and academics tied to US-China trade and policy, highlighting the ongoing tensions between nations and the potential for malicious activity.

    Microsoft and Cloudflare teamed up to dismantle RaccoonO365 phishing service, which had been using advanced techniques to trick users into divulging sensitive information. This incident underscores the importance of vigilance when it comes to online security.

    DoJ resentenced former BreachForums admin to three years in prison for his role in a data breach that exposed sensitive information. The sentence serves as a reminder of the consequences of engaging in malicious activity.

    In another development, Apple backports fix for actively exploited CVE-2025-43300. This highlights the ongoing struggle between attackers and defenders as they engage in a cat-and-mouse game.

    New supply chain attack hits npm registry, compromising 40+ packages. The incident serves as a reminder of the potential risks associated with vulnerabilities in software dependencies.

    Cybercrime group accessed Google Law Enforcement Request System (LERS) without authorization, highlighting the ongoing threat posed by malicious actors.

    China-linked Mustang Panda deployed advanced SnakeDisk USB worm, which is believed to have been used in a recent attack. The incident serves as a reminder of the potential risks associated with USB-based malware.

    Insider breach at FinWise Bank exposed data of 689,000 AFF customers. The incident highlights the ongoing threat posed by insider threats and the importance of robust security measures.

    Hackers stole millions of Gucci, Balenciaga, and Alexander McQueen customer records, highlighting the potential risks associated with data breaches and the importance of investing in robust security measures.

    Fairmont Federal Credit Union 2023 data breach impacted 187K people, serving as a reminder of the ongoing threat posed by cybersecurity breaches and the importance of investing in robust security measures.

    UK ICO finds students behind majority of school data breaches. The incident highlights the potential risks associated with insider threats and the importance of robust security measures.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Global-Cyber-Landscape-Shrouded-in-Malware-Security-Threats-Lurk-Around-Every-Corner-ehn.shtml

  • Published: Sun Sep 21 12:04:05 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us