MSP cybersecurity news digest, August 13, 2025
ID: 38e4d0b8-4571-549a-b89f-88994a4b67c3
STIX ID: report--38e4d0b8-4571-549a-b89f-88994a4b67c3
Feed Name: TRU Security by Acronis
This report summarizes multiple concurrent high-risk incidents: CISA issued an emergency directive for a critical Exchange/SharePoint hybrid vulnerability (CVE-2025-53786) that could allow undetected privilege escalation into Exchange Online and urges immediate patching and credential resets; SharePoint flaws have been used in the ToolShell exploit chain. Acronis TRU analyzed Akira and Lynx ransomware targeting MSPs and SMBs using credential theft, VPN flaws, and double-extortion tactics; DaVita suffered a ransomware-related breach exposing ~915,952 customers' clinical and financial data. Salesforce credential-theft campaigns by ShinyHunters impacted major brands, Cisco experienced a CRM data theft via vishing, and Milford Entities lost ~$19M to a sophisticated phishing fraud—together illustrating active exploitation, significant data exposure, and high-impact financial and operational risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
