MSP cybersecurity news digest, April 29, 2025
ID: 54f24468-8327-5712-a678-f2fa357ee736
STIX ID: report--54f24468-8327-5712-a678-f2fa357ee736
Feed Name: TRU Security by Acronis
This report summarizes multiple active cyber threats: CISA added exploited vulnerabilities including CVE-2025-24054 (NTLM hash leaks via .library-ms) being weaponized in phishing; North Korea-linked Kimsuky (Larva-24005) exploiting BlueKeep and Equation Editor to deploy MySpy and keyloggers; Interlock ransomware group using ClickFix social engineering to install stealers, RATs and deploy ransomware; China-linked UNC5174 deploying SNOWLIGHT and a new Linux/macOS RAT VShell; and a large Japanese fraud campaign involving 1,450+ unauthorized stock trades using stolen credentials (≈¥95 billion). The report details techniques, malware, affected sectors and attribution clues for ongoing investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
