logo

MSP cybersecurity news digest, June 30, 2025

ID: e7b2ab4e-c25f-5b12-9a1c-ba85f7434aa1

STIX ID: report--e7b2ab4e-c25f-5b12-9a1c-ba85f7434aa1

Feed Name: TRU Security by Acronis

Threat Score
78/100

Date Published: 2025-06-30

Date Updated: 2026-07-24

...
...

This report summarizes multiple active threats: attackers exploited authenticode stuffing to create signed ConnectWise ScreenConnect-based remote access malware distributed via phishing and cloud-hosted payloads; insurance firms Aflac and Erie Insurance were breached with potential exposure of sensitive data; the Dire Wolf ransomware group has conducted double-extortion attacks against 16 organizations in 11 countries using Golang encryptors and strong cryptography; the OneClik campaign abuses ClickOnce to deploy a Golang backdoor (RunnerBeacon) against energy/oil/gas firms using cloud infrastructure for C2; and new social-engineering variants (FileFix and Trezor-related phishing) increase the risk of credential and seed theft. Organizations are advised to patch, harden endpoints, monitor for suspicious signed binaries and cloud C2 activity, and reinforce phishing defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.