logo

MSP cybersecurity news digest, October 13, 2025

ID: 31f4a65c-09d9-5131-b4eb-6629e3c5a155

STIX ID: report--31f4a65c-09d9-5131-b4eb-6629e3c5a155

Feed Name: TRU Security by Acronis

Threat Score
84/100

Date Published: 2025-10-13

Date Updated: 2026-07-24

...
...

A security roundup reports multiple active and high-impact incidents: Medusa ransomware is exploiting a maximum-severity RCE in Fortra’s GoAnywhere MFT to perform deserialization and command-injection attacks for data theft and ransomware deployment; attackers used a compromised Zendesk instance to exfiltrate Discord user ticket data (including ~70,000 ID photos); Vampire Bot is distributing an infostealer via fake job ads and typosquatted sites; Asahi Group experienced production downtime after a ransomware attack attributed to Qilin; and Storm-2603 abused the legitimate Velociraptor DFIR tool to establish covert C2 and stage ransomware, with recommended mitigations including isolation, credential rotation, strict network controls, and application of vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.