MSP cybersecurity news digest, November 3, 2025
ID: 66bb3164-98d5-5daf-b3f6-61f93ea6cd8f
STIX ID: report--66bb3164-98d5-5daf-b3f6-61f93ea6cd8f
Feed Name: TRU Security by Acronis
This report describes several concurrent and active threats: PhantomRaven’s supply‑chain campaign that uploaded over 100 poisoned npm packages delivering cross‑platform infostealers and infecting tens of thousands of developer environments; a Merkle (Dentsu subsidiary) data breach exposing client and employee PII; Qilin ransomware abusing Windows Subsystem for Linux to run ELF encryptors on Windows hosts to evade Windows EDR; Atroposia malware that scans for host vulnerabilities to prioritize exploitation; and SideWinder APT using ClickOnce installers in spear‑phishing to deploy .NET stealers against South Asian diplomatic and government targets. Together these incidents illustrate large‑scale supply‑chain abuse, novel cross‑platform evasion techniques, targeted exploitation of unpatched systems, and consequential data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
