MSP cybersecurity news digest, July 29, 2025
ID: 0253426b-fe9b-579a-9390-a8428469bbe1
STIX ID: report--0253426b-fe9b-579a-9390-a8428469bbe1
Feed Name: TRU Security by Acronis
## Executive summary This intelligence roundup describes multiple active and high-impact incidents: CISA-added ToolShell SharePoint vulnerabilities (CVE-2025-49704 / CVE-2025-49706) being actively exploited by China-linked groups to deploy web shells and steal secrets; a joint advisory on Interlock ransomware and related law-enforcement takedowns of BlackSuit infrastructure; Koske Linux malware using benign-looking panda images (polyglot files) to deliver in-memory miners and rootkits via misconfigured JupyterLab instances; Patchwork spear-phishing campaigns targeting Turkish defense firms with malicious LNK files; and a $140M theft from Brazilian banks enabled by a bribed insider.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
