MSP cybersecurity news digest, August 4, 2025
ID: d806675e-7635-5923-83f5-64deadec5870
STIX ID: report--d806675e-7635-5923-83f5-64deadec5870
Feed Name: TRU Security by Acronis
This intelligence summary (July 2025) details active, high-risk activity: Scattered Spider operations and DragonForce ransomware targeting VMware ESXi and hypervisors, continued copycat campaigns (UNC6040), a widespread OAuth/phishing campaign using Tycoon/ODx and fake apps that compromised ~3,000 Microsoft 365 accounts, Salesforce-related breaches and extortion linked to ShinyHunters/UNC6040, plus operational incidents at Orange and St. Paul that disrupted services. The report emphasizes social-engineering, MFA bypass techniques (phishing, SIM swap, app consent abuse), use of legitimate RMM tools for access, and urges hardening, log reviews, and infrastructure changes ahead of vSphere 7 EOL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
