MSP cybersecurity news digest, June 30, 2025
ID: ea8a4a20-dbf5-509e-9d3b-ffeb1ca5301e
STIX ID: report--ea8a4a20-dbf5-509e-9d3b-ffeb1ca5301e
Feed Name: TRU Security by Acronis
This report summarizes several active cyber threats: attackers are using an "authenticode stuffing" technique to trojanize ConnectWise ScreenConnect installers and sign remote-access malware distributed via phishing; major insurers (Aflac, Erie, Philadelphia Insurance) experienced data breaches with investigations ongoing; the Dire Wolf ransomware group has executed double-extortion attacks across 11 countries with Golang encryptors and strong cryptography; the OneClik campaign abuses ClickOnce to deploy a Go-based backdoor to energy and oil & gas targets; and social‑engineering variants like FileFix and Trezor phishing are being used to execute commands or steal crypto seed phrases. Organizations across sectors should prioritize patching, endpoint protection, monitoring for anomalous signed binaries and cloud-hosted C2, and user-awareness against sophisticated phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
