HomeCybersecurity NewsNews roundup August 11, 2025
August 11, 2025

News roundup August 11, 2025

San Mateo, CA, August 11, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

GreedyBear campaign drains $1M through Firefox wallet extensions

Koi Security has discovered a large-scale malware campaign called “GreedyBear” that has infiltrated Mozilla’s Firefox add-on store with 150 malicious extensions. Posing as legitimate crypto wallets like MetaMask and TronLink, the campaign has already stolen an estimated $1 million from victims. “The weaponized extensions capture wallet credentials directly from user input fields within the extension’s own popup interface, and exfiltrate them to a remote server controlled by the group,” said Koi Security’s Tuval Admoni. A network of pirated software sites and fake wallet services linked to the same IP address also support broader malware distribution, including ransomware. Koi Security researchers report that GreedyBear operators are moving into the Chrome Web Store as well. Read more.

Exchange Server flaw opens cloud door in hybrid setups

Microsoft has issued a warning about CVE-2025-53786, a high-severity flaw in on-premises Exchange Server versions with a CVSS score of 8.0. According to Microsoft, “in an Exchange hybrid deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization’s connected cloud environment without leaving easily detectable and auditable traces.” CISA echoed the company’s concerns, warning of potential identity compromises if the flaw is left unpatched. Microsoft advises installing the April 2025 Hot Fix or newer and reviewing hybrid configuration settings. The alert coincides with new CISA findings on ToolShell malware exploiting recent SharePoint flaws to steal machine keys and exfiltrate data. Read more.

Cloudflare accuses Perplexity AI of stealth data scraping

Cloudflare has accused AI startup Perplexity of using deceptive tactics to bypass website restrictions and scrape data. “There are clear preferences that crawlers should be transparent, serve a clear purpose, perform a specific activity, and, most importantly, follow website directives and preferences,” Cloudflare engineers wrote. “Based on Perplexity’s observed behavior, which is incompatible with those preferences, we have de-listed them as a verified bot and added heuristics to our managed rules that block this stealth crawling.” The move follows customer complaints that Perplexity was accessing web content despite being banned via their robots.txt files, activity Cloudflare said it confirmed through targeted tests. Perplexity, which has faced previous accusations of unethical scraping, denied the claims while calling Cloudflare’s post a “sales pitch” and “embarrassing.” In contrast, Cloudflare praised OpenAI for complying with crawler transparency standards. Read more.

Critical Apex One console bugs exploited in active attacks

Trend Micro has issued an urgent warning to customers about active exploitation of two critical vulnerabilities, CVE-2025-54948 and CVE-2025-54987, affecting on-premises Apex One Management Consoles version 14039 and below. Both flaws allow unauthenticated remote code execution and have been rated 9.4 in severity. A temporary mitigation tool is available, though it disables remote agent installation from the console, and a full patch is expected by mid-August. At least one exploitation attempt has been observed in the wild. Trend Micro urged customers to implement additional safeguards, including restricting remote access, reviewing perimeter security, and hardening externally exposed IPs. It also reminded customers that a backend certificate update in September will require certain version baselines to avoid update issues. Read more.

WhatsApp adds scam alerts for unknown group invites

WhatsApp has launched a new safety overview feature to help users identify potential scams when added to group chats by unknown contacts. The update shows key group details, such as creation date, member count, and suspicious activity indicators, before users even view the chat, allowing them to exit silently. Group notifications are muted until the user confirms they want to stay. WhatsApp is also enhancing one-on-one scam defenses by alerting users when contacted by unknown numbers, encouraging skepticism toward fast-money promises. In the first half of 2025, WhatsApp disabled over 6.8 million scam-linked accounts and revealed it had worked with OpenAI to dismantle a criminal scam hub in Cambodia. That operation used ChatGPT to bait victims with TikTok tasks, fake crypto investments, and pyramid schemes. Read more.

Treasury flags crypto ATMs as scam and laundering hubs

The U.S. Treasury’s FinCEN division has issued a warning to financial institutions about the rising use of cryptocurrency ATMs in scams and money laundering. With U.S. Bitcoin ATMs jumping from 4,250 in 2020 to over 30,000 today, FinCEN reports a surge in non-compliant operators who fail to follow anti-money laundering regulations under the Bank Secrecy Act. “CVC kiosks operated by non-compliant operators are especially vulnerable to abuse by scammers and other criminals,” the agency said. Many of these machines, often found in gas stations and stores, are exploited in tech support scams targeting seniors. The FBI logged nearly 11,000 complaints and over $246 million in losses last year. FinCEN is urging vigilance for large ATM cash withdrawals and those making multiple payments just below reporting thresholds. Legislation introduced by Sen. Dick Durbin would require kiosk operators to register with the Treasury, disclose locations, and issue traceable receipts. Read more.

Russian hackers intercept embassy traffic via ISP-level attacks

A Russian-state hacker group known as Secret Blizzard is targeting foreign embassies in Moscow using advanced adversary-in-the-middle (AiTM) attacks at the ISP level, Microsoft warned. These operations exploit state-controlled internet providers to intercept traffic and deliver custom malware dubbed ApolloShadow. Once installed, ApolloShadow adds a rogue TLS root certificate, allowing attackers to impersonate trusted sites and maintain long-term access. “While we previously assessed with low confidence that the actor conducts cyberespionage activities within Russian borders against foreign and domestic entities, this is the first time we can confirm that they can do so at the Internet Service Provider (ISP) level,” members of the Microsoft Threat Intelligence team said. “This means that diplomatic personnel using local ISP or telecommunications services in Russia are highly likely targets of Secret Blizzard’s AiTM position within those services.” Read more.

North Korean IT worker scams surge to 320+ cases in a year

North Korean operatives posing as remote IT workers drove nearly one CrowdStrike investigation per day over the past year. “We saw a 220% year-over-year increase in the last 12 months,” said Adam Meyers, senior vice president of counter adversary operations. “We see them every day now.” In total, the firm handled over 320 incidents involving North Koreans infiltrating companies globally to earn salaries funneled to Pyongyang. CrowdStrike’s report highlights how generative AI tools helped these operatives create fake resumes, pass interviews, and maintain multiple jobs while remaining undetected. The firm also tracked a 27% rise in hands-on-keyboard intrusions, most of which were malware-free. Read more.

AI boom reshapes internet traffic and phishing risks

Web traffic to AI-related tools and websites jumped 50% in under a year, rising from 7 billion visits in February 2024 to over 10.5 billion by January 2025, according to Menlo Security. 80% of generative AI users still access generative AI through browsers, making them key threat surfaces. A recent Menlo study found 5.6 million GenAI visits in one month, 6,500 unique GenAI domains, and a 130% year-over-year rise in AI-driven phishing attacks. “There has been a lot more information and awareness about the risks and threats with regard to AI provided over the last year,” said Satyam Sinha, CEO and co-founder at Acuvity. “In our discussions with customers, it is evident that they are overwhelmed about how to prioritize and tackle the issues.” Experts warn that shadow AI use, such as employees using ChatGPT with a personal account but inputting sensitive data, compounds risk. Read more.

DOJ launches $200M fund for Backpage trafficking victims

The U.S. Department of Justice has launched a $200 million compensation program for victims of human trafficking facilitated by Backpage.com, marking the largest such effort in U.S. history. The funds, forfeited after criminal convictions of Backpage’s operators, stem from the site’s 14-year role as a hub for illegal sex ads, including child trafficking. Victims can file claims through backpageremission.com by February 2, 2026. IRS and FBI investigations helped trace illicit profits, following the 2017 FOSTA law. Though the domain now redirects to an unrelated site, the DOJ warns victims to avoid scams and only use official resources. Read more.

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles