
Weekly Cybersecurity Recap - 24 March 2025
This Week in Cybersecurity: Phishing, Ransomware, and a $32B Acquisition
Major Cyber Attacks, Malware and Industry Updates
This past week brought a wave of critical developments across the cybersecurity landscape, from large-scale breaches and social engineering campaigns to new frameworks designed to secure AI. Organizations faced threats ranging from ransomware and backdoors to clickjacking in password managers, while researchers shed light on systemic flaws across major platforms. Here’s a breakdown of the most important updates.
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
A patched flaw in Microsoft Windows has been exploited to deliver the PipeMagic backdoor in ransomware attacks. CVE-2025-29824, a privilege escalation vulnerability in the Windows Common Log File System, was used by threat actors to deploy PipeMagic, first seen in industrial-focused RansomExx campaigns. Researchers note that PipeMagic enables full remote access and command execution, making the flaw especially dangerous despite Microsoft’s April 2025 patch.
Apple Patches Zero-Day Flaw Used in 'Sophisticated' Attack
Apple addressed CVE-2025-43300 in its ImageIO framework, an out-of-bounds write vulnerability actively exploited in targeted attacks. Apple described the exploitation as “extremely sophisticated,” warning that malicious image files could lead to memory corruption. This is the latest in a series of zero-day flaws patched by Apple this year, underscoring the ongoing pressure on defenders to monitor evolving attack vectors.
Password Managers Vulnerable to Data Theft via Clickjacking
A security researcher revealed that nearly a dozen major password managers were vulnerable to clickjacking attacks, enabling the theft of highly sensitive credentials. The findings, presented at DEF CON, affected browser extensions of widely used services such as 1Password, LastPass, Bitwarden, and NordPass. These flaws highlight the persistent risks in tools that are supposed to safeguard identity and authentication data.
Intel Employee Data Exposed by Vulnerabilities
A researcher discovered flaws in Intel systems that exposed employee information, including through an authentication bypass on an internal India-based portal. Although Intel patched the vulnerabilities in late 2024, the disclosure highlights the lingering risks in employee-facing infrastructure that can be leveraged by attackers.
Cybercriminals Deploy CORNFLAKE.V3 Backdoor via ClickFix Tactic and Fake CAPTCHA Pages
Threat group UNC5518 has been observed using deceptive CAPTCHA lures to trick victims into granting system access, which is then used to deploy the CORNFLAKE.V3 backdoor. Researchers from Mandiant noted that the access gained is often sold to other groups as part of a growing access-as-a-service ecosystem.
Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger
QuirkyLoader, a newly discovered malware loader, is being used in spam campaigns to distribute a wide range of malicious payloads. Since November 2024, campaigns have delivered well-known threats such as Agent Tesla, Remcos RAT, and Snake Keylogger, making QuirkyLoader an increasingly versatile tool for cybercriminals.
Hackers target Workday in social engineering attack
Hackers impersonating IT and HR staff breached a third-party vendor’s customer support system linked to Workday. This gave them access to customer names, emails, and phone numbers, which could be used for further social engineering. While Workday confirmed no compromise of its core systems, the incident highlights the continuing risks posed by third-party vendors.
AI and Security
New NIST Concept Paper Outlines AI-Specific Cybersecurity Framework
The U.S. National Institute of Standards and Technology (NIST) has released a concept paper proposing AI-specific overlays to its SP 800-53 framework. These controls are designed to address unique risks associated with AI, such as data poisoning, adversarial prompts, and misuse of generative models. This initiative marks an important step in formalizing standards around AI security.
Agentic AI promises a cybersecurity revolution - with asterisks
Experts predict that agentic AI could significantly reshape cybersecurity by automating defenses and reducing repetitive workloads. However, they caution that AI agents are still in early stages and raise difficult questions about trust, accountability, and governance. CISOs are urged to proceed carefully before adopting this emerging technology.
UAE: Warning issued as over 12,000 WIFI breaches recorded in 2025
The UAE’s Cyber Security Council reported more than 12,000 Wi-Fi breaches so far in 2025, accounting for 35% of all cyberattacks in the country. Hackers are exploiting open and free Wi-Fi networks to steal banking data, passwords, and personal information. The Council is urging citizens to avoid unsecured connections and prioritize safe browsing practices.
This Week in Cybersecurity: Phishing, Ransomware, and a $32B Acquisition
AI Weaknesses, Airport Ransomware, Cloud Gaps & Phishing PhaaS
Fake Apps, Data Leaks, Ransomware Tactics & WordPress Plugin Exploits
Multi-stage malware, GPS spoofing, ClickFix campaigns, and Shadow AI adoption—this week’s cybersecurity recap has it all
QR code scams, GenAI hallucinations, mobile spyware, and double extortion — it’s another action-packed week in cybersecurity.
TikTok fined €530M, hackers breach CNI, and top 2025 cyber threats – your weekly cyber update
FreeDrain Crypto Phishing, Qilin Ransomware Surge & Google’s AI Moves
Botnets, Bounties, and the AI Balancing Act
Fake Installers, Ransomware Fallout & Malicious Extensions: Last Week’s Cyber Recap
Malware campaigns, breaches, and the $111B cloud security boom
From a massive AT&T data leak to new macOS malware and a takedown of a notorious carding site - here's what happened last week.
Discord Malware, Salesforce Risks, SME Pressures and more
Cybercriminal Innovation, Record-Breaking DDoS, and Retail Breaches - What You Missed Last Week
Emerging Quantum Threats, UAE Cyber Trends, and Critical Exploits – Last Week’s Cybersecurity Recap
Weekly Cybersecurity Recap: AI-Enhanced Phishing, Android Fraud, and Emerging Risks
Weekly Cybersecurity Recap: Human Weakness, AI Risks, and Critical Vulnerabilities
Weekly Cybersecurity Recap: AI-Powered Scams, Vault Flaws, Airline Breaches & GPT-5 Jailbreaks
Ready to get started? Fill out the form below and we'll get back to you in no time!
risk decrease
To: Paratus
Thank you for reaching out to us. Your request has been received, and we will get back to you within the next 24 hours. Alternatively, you can also reach us at [email protected]
To: Paratus
To: Paratus