JUNE 2025 Cybersecurity Newsletter

iwebbs-cybersecurity-newsletter-June-2025

Cybersecurity in June 2025 is anything but quiet—organizations worldwide are facing new waves of sophisticated malware, zero-day exploits, and high-impact data breaches. From international law enforcement takedowns to fresh vulnerabilities threatening critical systems, every headline underscores the urgency of staying proactive. This newsletter distills the most important updates you need to know—helping you understand the risks, learn from recent incidents, and strengthen your defenses against evolving cyber threats.

Welcome to our June 2025 Cybersecurity Newsletter! This edition brings you the latest updates on global cyber incidents, emerging threats, and critical vulnerabilities impacting organizations and individuals alike. From high-profile arrests to massive data breaches and new malware campaigns, we cover the key developments shaping the cybersecurity landscape this month.

News Highlights:

1. U.S. DoJ and Global Partners Dismantle Cybercrime Crypting Services, Seize Key Domains

On May 27, 2025, the U.S. Department of Justice, in collaboration with Dutch and Finnish authorities, seized four domains—AvCheck[.]net, Cryptor[.]biz, and Crypt[.]guru—that provided crypting and counter-antivirus (CAV) services to cybercriminals. These platforms helped threat actors evade security tools by obfuscating malware. Supported by France, Germany, Denmark, Portugal, and Ukraine, the international operation marks a significant step in disrupting cybercrime infrastructure.

2. Malicious Go Modules Target Linux Systems with Disk-Wiping Malware in Sophisticated Supply Chain Attack

Researchers have uncovered three malicious Go modules—prototransform, go-mcp, and tlsproxy—designed to deliver a disk-wiping payload that renders Linux systems unbootable. The modules use obfuscated code to fetch a shell script from a remote server, which then overwrites /dev/sda with zeroes. This attack highlights growing threats in open-source ecosystems, alongside recent discoveries of npm packages that steal crypto wallet data and sensitive user information.

3. Golden Chickens Unleash TerraStealerV2 and TerraLogger in Phishing Campaigns Targeting Credentials and Crypto Wallets

The Golden Chickens threat group (aka TA4557) has introduced two new malware strains—TerraStealerV2 and TerraLogger—designed to exfiltrate browser credentials, crypto wallet data, and log keystrokes. Distributed via phishing emails disguised as resumes, the malware leverages Windows shortcut files to execute JavaScript-based payloads. This marks an evolution in the group’s malware-as-a-service (MaaS) tactics, continuing their focus on credential theft and financial gain.

4. AirPlay Flaws Enable Zero-Click RCE and Wormable Attacks on Apple Devices

Researchers from Oligo Security have uncovered a set of critical vulnerabilities—collectively dubbed AirBorne—affecting Apple and third-party devices using the AirPlay SDK. The flaws, including CVE-2025-24252 and CVE-2025-24132, can be chained to enable zero-click, wormable remote code execution (RCE) over public Wi-Fi, allowing attackers to spread malware across local networks. These bugs open the door to backdoors, ransomware, AitM attacks, and information disclosure, posing serious security threats.

5. Samsung Patches Critical MagicINFO 9 Path Traversal Flaw Exploited for Mirai Botnet

Samsung has issued urgent updates to fix CVE-2025-4632, a critical path traversal vulnerability in MagicINFO 9 Server actively exploited in the wild to deploy the Mirai botnet. This flaw bypasses the previous patch for CVE-2024-7399 and allows attackers to write arbitrary files with system privileges. Disclosed shortly after a proof-of-concept release, the vulnerability affected even the latest MagicINFO versions before patching, prompting swift action from Samsung and security researchers.

6. Fileless Remcos RAT Spread via Malicious LNK Files and MSHTA in PowerShell Attacks

Threat actors are delivering the fileless Remcos RAT using malicious LNK files hidden in ZIP archives and leveraging mshta.exe for proxy execution, according to Qualys. The attack uses tax-themed lures to trick users into opening a shortcut that triggers obfuscated HTA files, which download and execute PowerShell scripts to load Remcos entirely in memory. This sophisticated malware grants full remote control over infected systems, enabling espionage and data theft through keylogging, screenshot capture, and system monitoring.

Breaches Highlights:

1. Ascension Data Breach Exposes Personal and Health Information of Over 430,000 Patients

Ascension, a leading U.S. healthcare provider, disclosed a data breach impacting more than 430,000 patients, resulting from a vulnerability in third-party software used by a former business partner. The breach, which occurred in December 2024 and was confirmed in early 2025, exposed sensitive personal and medical information, including Social Security numbers, medical records, and contact details. Notifications have been sent to affected individuals across multiple states, highlighting the scope and severity of the incident.

2. Australian Human Rights Commission Data Breach Exposes Sensitive Documents Indexed by Search Engines

The Australian Human Rights Commission (AHRC) suffered a data breach that leaked 670 private documents online, which were subsequently indexed by major search engines. The exposed files contained sensitive personal information, including names, health details, and photographs, spanning complaints and submissions from 2021 to 2025. The breach affected various AHRC projects and complaint webforms, with unauthorized access occurring between April and May 2025.

3. Coinbase Data Breach Exposes Personal Information of Up to 1 million Customers

Coinbase revealed a data breach involving rogue support agents and external contractors who stole personal information from roughly 1% of its customers—around one million individuals—without accessing private keys or wallets. Stolen data includes names, contact details, masked Social Security numbers, government ID images, account balances, and limited corporate documents. After receiving a $20 million ransom demand, Coinbase refused to pay and instead offered a $20 million reward for information leading to the attackers. The company has terminated the insiders involved and continues its investigation.

4. SK Telecom Malware Breach Exposed Data of 27 million Subscribers Over Three Years

SK Telecom disclosed a malware breach dating back to 2022 that compromised USIM data of 27 million subscribers, including IMSI numbers, authentication keys, and stored SMS/contact data. Detected in April 2025, the incident raised risks of SIM-swapping attacks, prompting the company to issue SIM replacements and enhance security. A government investigation revealed the malware accessed 25 types of sensitive data, and SK Telecom temporarily halted new subscriptions to manage the fallout.

5. SAP NetWeaver Flaw Exploited by China-Linked APTs to Compromise 581 Critical Systems

At least 581 critical systems worldwide were compromised by China-linked threat groups exploiting a zero-day vulnerability (CVE-2025-31324) in SAP NetWeaver, allowing unauthenticated file uploads and remote code execution. Targets included infrastructure sectors in the UK, US, and Saudi Arabia. Dutch firm EclecticIQ linked the attacks to UNC5221, UNC5174, and CL-STA-0048, who deployed web shells and malware like PlugX and SNOWLIGHT. SAP patched the flaw in May 2025, but experts warn of ongoing threats, including a newly identified related bug, CVE-2025-42999.

6. LexisNexis Data Breach Exposes Personal Information of Over 364,000 Individuals

LexisNexis Risk Solutions disclosed that over 364,000 individuals had their personal data exposed in a December 2024 breach, after attackers accessed files from a compromised GitHub account. While the company’s internal systems were not affected, exposed information included names, contact details, Social Security numbers, driver’s license numbers, and birth dates. No financial data was compromised, and forensic investigations were launched immediately upon discovery in April 2025.

Malware Highlights:

1. PureRAT Malware Attacks Quadruple in 2025, Targeting Russian Firms with Phishing Campaigns

Kaspersky reports a fourfold increase in PureRAT malware attacks against Russian organizations in early 2025 compared to last year. The campaign, ongoing since March 2023, uses phishing emails with RAR attachments disguised as Word or PDF files. Once executed, the malware installs itself in the victim’s %AppData% folder as “task.exe” and creates a startup script to maintain persistence.

2. Horabot Malware Campaign Hits Six Latin American Countries via Invoice-Themed Phishing

A new phishing campaign distributing Horabot malware is targeting Windows users across Mexico, Guatemala, Colombia, Peru, Chile, and Argentina. Using fake invoice emails, the malware steals email credentials, harvests contacts, and installs banking trojans. Notably, the attack leverages Outlook COM automation to send phishing emails from compromised accounts, spreading the infection laterally within networks, primarily affecting Spanish-speaking victims.

3. EDDIESTEALER Malware Bypasses Chrome Encryption to Steal Browser and Crypto Data

A new Rust-based malware called EDDIESTEALER is spreading via deceptive CAPTCHA pages that trick users into running malicious PowerShell scripts through a ClickFix social engineering tactic. The malware, delivered after executing obfuscated scripts from compromised websites, steals sensitive data including browser credentials, cryptocurrency wallets, and system information. It communicates with a command-and-control server to receive tasks and exfiltrate valuable data from infected machines.

4. PumaBot Botnet Uses Targeted SSH Brute-Force to Compromise Linux IoT Devices

PumaBot, a new Go-based Linux botnet, targets embedded IoT devices by brute-forcing SSH credentials using IP lists from a command-and-control server instead of broad internet scanning. The malware focuses on surveillance and traffic cameras, identified by the “Pumatronix” string, and verifies compromised devices by gathering system information before deploying malicious payloads. Darktrace’s analysis details the attack methods, indicators, and detection strategies for this evolving threat.

5. Germany Identifies TrickBot and Conti Ransomware Leader Vitaly Kovalev

Germany’s Federal Criminal Police Office (BKA) has revealed that Vitaly Nikolaevich Kovalev, a 36-year-old Russian, is the alleged leader behind the TrickBot and Conti ransomware gangs. Kovalev, founder of the “Wizard Spider” group, is wanted internationally for orchestrating cybercrime campaigns involving malware like TrickBot, Bazarloader, and Ryuk. This follows a global law enforcement crackdown known as Operation Endgame, with Kovalev previously sanctioned by the U.S. in 2023 under multiple aliases.

6. Go-Based RedisRaider Malware Exploits Redis Servers to Deploy XMRig Miner on Linux

Datadog Security Labs uncovered RedisRaider, a Go-based malware that scans for exposed Redis servers on Linux hosts and abuses Redis configuration commands to inject cron jobs. This allows it to deploy a custom XMRig cryptominer and propagate across vulnerable Redis instances. The attack involves altering Redis’s working directory to drop a scheduled task that runs a Base64-encoded script, downloading the malicious payload. RedisRaider also operates a web-based Monero miner, combining server-side cryptojacking with broader infection capabilities.

New Vulnerabilities:

1. CVE-2025-47577: Critical Unpatched RCE Vulnerability in TI WooCommerce Wishlist Plugin Puts 100K+ WordPress Sites at Risk

CVE-2025-47577 is a critical CVSS 10.0 vulnerability in the TI WooCommerce Wishlist plugin (≤ v2.9.2) affecting over 100,000 WordPress sites. It allows unauthenticated arbitrary file uploads due to improper use of WordPress’s wp_handle_upload() function, bypassing MIME type validation. Exploitation can lead to remote code execution, but requires the WC Fields Factory plugin to be active. With no patch currently available, users are strongly advised to deactivate and remove the plugin immediately.

2. CVE-2025-32432: Critical Remote Code Execution Vulnerability in Craft CMS Exploited to Deploy Cryptominers

CVE-2025-32432 is a critical flaw in Craft CMS exploited by threat actors to gain unauthorized access and deploy web shells for persistent control. Observed in active attacks since February 2025, the attackers used the access to execute a malicious script (“4l4md4r.sh”) that removes competing cryptominers and installs a custom ELF binary. The flaw was patched in Craft CMS versions 3.9.15, 4.14.15, and 5.6.17.

3. CVE-2025-30397: Remote Code Execution via Scripting Engine Bug Forces Edge into Legacy IE Mode

CVE-2025-30397 is a memory corruption vulnerability in the Windows Scripting Engine that allows remote code execution if a user clicks a maliciously crafted link. The flaw, exploited in the wild, forces Microsoft Edge into Internet Explorer mode, reviving outdated behaviors. Microsoft has not disclosed attack scale, but users are strongly urged to apply patches immediately.

4. CVE-2025-32706: Privilege Escalation Vulnerability in Windows Common Log File System Driver

CVE-2025-32706 is an elevation of privilege vulnerability in the Windows Common Log File System Driver that allows attackers to escalate privileges to SYSTEM. Previously targeted by threat actors, this flaw is often combined with code execution bugs to gain full control of a system. Historically used in ransomware campaigns, it remains a critical risk.

5. CVE-2025-32709: Privilege Escalation Vulnerability in Windows WinSock Driver

CVE-2025-32709 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock, actively exploited in the wild. Previously targeted earlier this year, repeated attacks raise concerns about patch effectiveness. The flaw enables attackers to escalate privileges to SYSTEM, making it a valuable tool in post-exploitation chains. Organizations should prioritize testing and deploying this fix swiftly.

6. CVE-2025-30400: Elevation of Privilege Vulnerability in Microsoft DWM Core Library

CVE-2025-30400 is an elevation of privilege vulnerability in the Microsoft DWM Core Library that allows attackers to gain SYSTEM-level access. Although patched previously in January, this marks the first known exploitation in the wild. Commonly used in phishing and ransomware campaigns, such EoP flaws remain critical in attack chains.

Tools of the Month

  1. VIPER: It’s a powerful and flexible red team platform. It integrates the core tools and functionalities required for adversary simulation and red team operations, assisting you in efficiently completing cybersecurity assessment tasks.
  2. Suna: It’s an open-source AI assistant designed to simplify real-world tasks through natural conversation, offering capabilities in research, data analysis, and daily problem-solving with an intuitive, results-driven interface.

Protect Your Business from Cyber Attacks!

In today’s world, cyber threats are constantly evolving, and staying one step ahead is crucial for your business. At iwebbs.com, we understand the stakes. Our team of certified security experts is here to help you pinpoint weak spots, implement rock-solid protection, and keep your business safe from even the most sophisticated attacks.

Don’t wait until it’s too late. Take control of your cybersecurity today. Reach out to us for a personalized consultation and find out how we can help you protect your organization from cyber risks. Let’s work together to secure your future!

Secure your business with iwebbs!

Related posts:
Categories:

Share this content: