Weekly Cybersecurity Recap - 27 October 2025

Major Threats, Exploits, Malware and Industry Updates

01 / Blog Article

Weekly Cybersecurity Recap - 27 October 2025
    Weekly Recap

    Introduction

    From large-scale phishing operations to new supply chain compromises and costly data breaches, this week’s cybersecurity landscape underscores one truth - the threat environment is expanding faster than ever. Let’s break down the top developments shaping global cybersecurity this week.

    Threats and Exploits

    Critical Windows Server WSUS Vulnerability Exploited in the Wild

    Microsoft rushed to patch a critical flaw in its Windows Server Update Service (WSUS), but attackers had already begun exploiting it within hours of disclosure. The bug, tracked as CVE-2025-59287, enables remote code execution without authentication, making it a high-priority fix for enterprises. Since WSUS is central to distributing updates in corporate networks, exploitation of this flaw poses serious risks for large-scale compromise.

    Self-Spreading 'GlassWorm' Infects VS Code Extensions in Widespread Supply Chain Attack

    Security researchers have discovered a self-propagating worm - GlassWorm - infecting Visual Studio Code extensions on both the Microsoft Marketplace and Open VSX Registry. The campaign, the second such DevOps-focused supply chain attack this year, highlights growing adversary interest in developer ecosystems following September’s Shai-Hulud npm incident.

    Jaguar Land Rover Hack Could Cost UK $2.5 Billion

    The fallout from the Jaguar Land Rover cyberattack continues to escalate, with new estimates suggesting the UK economy could lose up to £1.9 billion ($2.5 billion). According to the Cyber Monitoring Center, this makes it the costliest cyber incident in UK history - and the financial impact could rise further if factory control systems were affected.

    Phishing and Social Engineering

    Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation

    A coordinated smishing campaign tied to the so-called Smishing Triad has been linked to over 194,000 malicious domains globally. Researchers from Palo Alto Networks Unit 42 say the group is leveraging automated domain generation and SMS phishing infrastructure to target users across multiple regions and industries.

    3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation

    The YouTube Ghost Network — a malicious cluster of YouTube accounts distributing malware via fake tutorials and software cracks — has published more than 3,000 infected videos since 2021. The campaign’s volume has tripled in 2025, prompting Google to remove thousands of affected videos as part of a sweeping cleanup effort.

    $1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal

    A much-hyped $1 million WhatsApp exploit scheduled for demonstration at Pwn2Own was quietly withdrawn after researchers realized it wasn’t viable for remote code execution. Meta later confirmed that only two low-risk bugs were disclosed, underscoring the challenges of developing reliable exploits for hardened mobile applications.

    Strategy and Leadership

    Africa: Shifting From Cyber ‘Security’ To Cyber ‘Resilience’

    At the Cyber Security Summit 2025 in Johannesburg, experts called for a new approach — moving from pure cybersecurity to cyber resilience. With Africa’s rapidly growing digital economy, the conversation is shifting from prevention to recovery and continuity. According to Cybersecurity Ventures, cybercrime costs are projected to reach $10.5 trillion in 2025, up from $3 trillion a decade ago, cementing its position as the most significant economic threat of our time.

    The Cybersecurity Perception Gap: Why Executives and Practitioners See Risk Differently

    A new Bitdefender report exposes a concerning disconnect between how executives and technical teams perceive cyber risk. Leaders often underestimate vulnerabilities that practitioners face daily, leading to resource misalignment and slower incident responses. This perception gap may seem subtle now, but experts warn it could evolve into major organizational blind spots - especially as boards push for greater automation and AI-driven security decisions.

    Why Organizations Are Abandoning Static Secrets for Managed Identities

    As cloud adoption accelerates, companies are retiring static credentials like API keys and tokens in favor of managed identities. This shift not only improves productivity but also reduces operational overhead tied to secret rotation and exposure. Researchers note that legacy systems remain the primary weak link, describing the use of static secrets as an "operational nightmare" that’s increasingly unsustainable in modern DevOps environments.

    Regional Developments

    Mideast, African Hackers Target Gov'ts, Banks, Small Retailers

    In the Middle East and North Africa, cyberattacks have expanded beyond government and critical infrastructure to include small retailers — a sector now frequently targeted for data theft and ransomware. Analysts attribute this trend to a mix of political motivations, financial gain, and opportunistic exploitation of under-protected networks amid rapid digital transformation in the region.

    02/ Related Posts

    view all
    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 24 March 2025

    This Week in Cybersecurity: Phishing, Ransomware, and a $32B Acquisition

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 7 April 2025

    AI Weaknesses, Airport Ransomware, Cloud Gaps & Phishing PhaaS

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 14 April 2025

    Fake Apps, Data Leaks, Ransomware Tactics & WordPress Plugin Exploits

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 21 April 2025

    Multi-stage malware, GPS spoofing, ClickFix campaigns, and Shadow AI adoption—this week’s cybersecurity recap has it all

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 28 April 2025

    QR code scams, GenAI hallucinations, mobile spyware, and double extortion — it’s another action-packed week in cybersecurity.

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 5 May 2025

    TikTok fined €530M, hackers breach CNI, and top 2025 cyber threats – your weekly cyber update

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 12 May 2025

    FreeDrain Crypto Phishing, Qilin Ransomware Surge & Google’s AI Moves

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 19 May 2025

    Botnets, Bounties, and the AI Balancing Act

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 26 May 2025

    Fake Installers, Ransomware Fallout & Malicious Extensions: Last Week’s Cyber Recap

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 2 June 2025

    Malware campaigns, breaches, and the $111B cloud security boom

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 9 June 2025

    From a massive AT&T data leak to new macOS malware and a takedown of a notorious carding site - here's what happened last week.

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 16 June 2025

    Discord Malware, Salesforce Risks, SME Pressures and more

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 23 June 2025

    Cybercriminal Innovation, Record-Breaking DDoS, and Retail Breaches - What You Missed Last Week

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 30 June 2025

    Emerging Quantum Threats, UAE Cyber Trends, and Critical Exploits – Last Week’s Cybersecurity Recap

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 7 July 2025

    Weekly Cybersecurity Recap: AI-Enhanced Phishing, Android Fraud, and Emerging Risks

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 14 July 2025

    Weekly Cybersecurity Recap: Human Weakness, AI Risks, and Critical Vulnerabilities

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 11 August 2025

    Weekly Cybersecurity Recap: AI-Powered Scams, Vault Flaws, Airline Breaches & GPT-5 Jailbreaks

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 25 August 2025

    Weekly Cybersecurity Recap: Wi-Fi Breaches, AI Risks, and Major Exploits

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 1 September 2025

    AI Ransomware, WhatsApp Zero-Click Exploit, and Salesforce Credential Theft

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 8 September 2025

    AI-powered Threats, Global Partnerships, Zero-Day Exploits & Record DDoS Attack

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 15 September 2025

    npm Breach, Zero-Days, AI Jailbreaks and More

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 22 September 2025

    AI-powered threats, airport cyberattacks, phishing surges & critical vulnerabilities

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 6 October 2025

    Oracle Extortion, Red Hat Breach, and AI Browser Exploits

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 13 October 2025

    New Malware Strains, Supply Chain Risks, and Massive Breaches

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 20 October 2025

    Smart Contract Malware, Corporate Breaches, and Ransomware Disruptions

    Protect your business with Paratus

    Ready to get started? Fill out the form below and we'll get back to you in no time!

    To: Paratus

    risk decrease

    96% Risks from dealing with clients and traders decrease by 96%