
Weekly Cybersecurity Recap - 24 March 2025
This Week in Cybersecurity: Phishing, Ransomware, and a $32B Acquisition
Major Threat Campaigns, Vulnerabilities and Industry Updates
From groundbreaking AI-powered threats to urgent zero-day fixes, last week’s cybersecurity landscape underscored the speed at which attackers innovate and the vigilance defenders must maintain. Here’s a recap of the most significant developments
Hackers steal data from Salesforce instances in widespread campaign
Researchers at Google Threat Intelligence Group revealed that hackers stole user credentials from Salesforce customers by abusing a third-party tool. The campaign, which unfolded earlier this month, enabled attackers to harvest credentials that could be leveraged for follow-up attacks. This highlights once again how third-party services can expand the threat surface for enterprises.
Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack
The Nx build platform - downloaded more than 4 million times weekly - became the first known case of a supply chain attack where adversaries weaponized AI assistants to facilitate data theft. Thousands of developer credentials were compromised, demonstrating how widely used open-source platforms can quickly become high-value targets for attackers.
Someone Created the First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model
ESET researchers disclosed PromptLock, the first ransomware strain powered by AI. Written in Golang, PromptLock uses the gpt-oss:20b model locally via the Ollama API to generate malicious Lua scripts on the fly. By integrating AI in real time, the ransomware takes customization and automation to a new level, signaling a worrying shift in cybercriminal tactics.
WhatsApp Patches Zero-Click Exploit Targeting iOS and macOS Devices
WhatsApp patched a serious vulnerability in its iOS and macOS apps, which may have been exploited in targeted zero-day campaigns. Tracked as CVE-2025-55177, the flaw stemmed from insufficient authorization of linked device synchronization messages. Researchers noted its potential connection to a recently disclosed Apple zero-day, emphasizing the growing risks posed by zero-click exploits.
Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution
Security researchers disclosed three vulnerabilities in the Sitecore Experience Platform that could be chained to achieve information disclosure and remote code execution. The flaws, if exploited together, open a path for attackers to compromise critical web infrastructure, raising concerns for enterprises that rely on Sitecore for digital content management.
How AI is reshaping cybersecurity operations
Artificial intelligence is transforming enterprise security operations, forcing CISOs to adapt their teams and defenses. Generative AI tools are already embedded into workflows, with a Boston Consulting Group survey showing that half of organizations are using them to redesign processes. Looking ahead, 77% of security leaders believe AI agents will be critical to enterprise functions within the next five years.
Cybersecurity signals: Connecting controls and incident outcomes
A new study by Marsh McLennan’s Cyber Risk Intelligence Center analyzed thousands of organizations’ cyber self-assessments against real-world claims data. The research revealed which controls most effectively reduce breach risks, providing CISOs with evidence-based insights on where to focus security budgets for maximum impact.
UAE Cybersecurity Council warns 60 per cent of financial attacks start with stolen credentials
The UAE Cybersecurity Council revealed that stolen credentials are the entry point for 60% of financial cyberattacks. Officials emphasized that adopting safe digital practices could cut risks by as much as 40%, underscoring the importance of basic security hygiene in protecting high-value assets.
UAE Cybersecurity Council stresses importance of device updates
The Council also urged UAE users to keep essential devices updated, including laptops, smartphones, routers, and smart home systems. Outdated software leaves systems vulnerable to malware, data theft, and breaches, particularly when used on unsecured networks. Enabling automatic updates was highlighted as a key step in closing security gaps.
Cisco outlines 5 steps to boost cybersecurity in UAE healthcare sector
Cisco published guidance for UAE healthcare providers, identifying five priority steps to strengthen defenses. With patient records increasingly targeted, and many hospitals still relying on outdated systems, the company stressed the urgency of building resilience against cyberattacks that could jeopardize both data security and patient care.
CrowdStrike Buys Onum for $290M to Boost SIEM Data Ingestion
CrowdStrike announced its plan to acquire Madrid-based Onum for $290M. Onum, a telemetry pipeline management startup founded by Devo’s former CTO, will enhance CrowdStrike’s ability to ingest and process third-party data. The move reflects CrowdStrike’s strategy to expand its platform capabilities and improve SIEM efficiency in handling complex enterprise data flows.
This Week in Cybersecurity: Phishing, Ransomware, and a $32B Acquisition
AI Weaknesses, Airport Ransomware, Cloud Gaps & Phishing PhaaS
Fake Apps, Data Leaks, Ransomware Tactics & WordPress Plugin Exploits
Multi-stage malware, GPS spoofing, ClickFix campaigns, and Shadow AI adoption—this week’s cybersecurity recap has it all
QR code scams, GenAI hallucinations, mobile spyware, and double extortion — it’s another action-packed week in cybersecurity.
TikTok fined €530M, hackers breach CNI, and top 2025 cyber threats – your weekly cyber update
FreeDrain Crypto Phishing, Qilin Ransomware Surge & Google’s AI Moves
Botnets, Bounties, and the AI Balancing Act
Fake Installers, Ransomware Fallout & Malicious Extensions: Last Week’s Cyber Recap
Malware campaigns, breaches, and the $111B cloud security boom
From a massive AT&T data leak to new macOS malware and a takedown of a notorious carding site - here's what happened last week.
Discord Malware, Salesforce Risks, SME Pressures and more
Cybercriminal Innovation, Record-Breaking DDoS, and Retail Breaches - What You Missed Last Week
Emerging Quantum Threats, UAE Cyber Trends, and Critical Exploits – Last Week’s Cybersecurity Recap
Weekly Cybersecurity Recap: AI-Enhanced Phishing, Android Fraud, and Emerging Risks
Weekly Cybersecurity Recap: Human Weakness, AI Risks, and Critical Vulnerabilities
Weekly Cybersecurity Recap: AI-Powered Scams, Vault Flaws, Airline Breaches & GPT-5 Jailbreaks
Weekly Cybersecurity Recap: Wi-Fi Breaches, AI Risks, and Major Exploits
AI-powered Threats, Global Partnerships, Zero-Day Exploits & Record DDoS Attack
npm Breach, Zero-Days, AI Jailbreaks and More
Ready to get started? Fill out the form below and we'll get back to you in no time!
risk decrease
To: Paratus
Thank you for reaching out to us. Your request has been received, and we will get back to you within the next 24 hours. Alternatively, you can also reach us at [email protected]
To: Paratus
To: Paratus