HomeCybersecurity NewsNews roundup August 25, 2025
August 25, 2025

News roundup August 25, 2025

San Mateo, CA, August 25, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

Scattered Spider hacker faces major prison term

A 20-year-old member of the Scattered Spider hacking group has been sentenced to ten years in U.S. federal prison for wire fraud and aggravated identity theft tied to cryptocurrency theft and major hacks. Noah Michael Urban, who used aliases including “Sosa” and “King Bob,” was arrested in Florida in 2024 and admitted to stealing over $800,000 from victims through SIM swapping attacks. Along with 120 months in prison, Urban must serve three years of supervised release and pay $13 million in restitution. Prosecutors linked him and other members to broader social engineering campaigns targeting corporate networks, while experts warn Scattered Spider’s merger with ShinyHunters and LAPSUS$ could make the group even more dangerous. “We regularly see groups team up when there is an increase in external pressures, like law enforcement crackdowns. To survive, these groups need to consolidate,” said Adam Darrah, vice president of intelligence at ZeroFox. “And the result is often a more versatile and potentially dangerous combined operation.” Read more.

Apple issues urgent zero-day patch for iOS and macOS

Apple has released emergency security updates to fix a newly discovered zero-day vulnerability tracked as CVE-2025-43300, which was exploited in what the company called an “extremely sophisticated attack.” The flaw, found in the Image I/O framework, stems from an out-of-bounds write weakness that can be triggered by processing malicious image files, potentially leading to memory corruption, crashes, or remote code execution. The issue affects a wide range of devices, including iPhone XS and later, multiple generations of iPad models, and Macs running macOS Sequoia, Sonoma, and Ventura. Apple addressed the bug with improved bounds checking in iOS 18.6.2, iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, and macOS Ventura 13.7.8. While exploitation appears to have been limited to targeted attacks, users are strongly advised to update immediately. This marks Apple’s sixth zero-day fix of 2025, adding to six others patched in 2024. Read more.

Creator of Rapper Bot charged in massive DDoS case

Federal prosecutors have charged 22-year-old Ethan J. Foltz of Eugene, Oregon, with creating and operating Rapper Bot, a massive distributed denial-of-service (DDoS) botnet. According to a complaint filed in U.S. District Court in Alaska, Rapper Bot infected Wi-Fi routers, DVRs and other devices worldwide, then was rented to clients who used it for attacks across more than 80 countries. Investigators linked it to over 370,000 attacks and at least 18,000 confirmed victims, though millions may have been affected since its launch in 2021. Built as a variant of the Mirai malware, Rapper Bot harnessed 65,000 to 95,000 devices and generated attack traffic exceeding six terabits per second at its peak, placing it among the most powerful botnets ever seen. Victims included Elon Musk’s social media platform X, which was taken offline in March. Foltz admitted to managing the botnet with a partner known as “SlayKings” and using the alias “Special Agent William Stevens Johnson III” on Telegram. Read more.

Researchers uncover stealthier QR code phishing tricks

Security researchers at Barracuda Networks have uncovered two new QR code phishing (quishing) techniques designed to evade traditional email defenses. In a report published August 20, “Threat Spotlight: Split and nested QR codes fuel new generation of ‘Quishing’ attacks,” analysts explained how phishing-as-a-service kits are evolving to bypass detection. The first method, used by Gabagool operators, involves splitting a QR code into two separate images within an email. Security scanners see only harmless visuals, but to the recipient the code appears intact and redirects to a phishing page that steals Microsoft credentials. The second method embeds a malicious QR code inside or around a legitimate one. For example, the outer code may redirect to a phishing site while the inner code points to Google, creating ambiguity for scanners and misleading users. Read more.

Hackers claim sale of millions of PayPal credentials

Hackers on a well-known forum are claiming to be selling a massive dataset containing 15.8 million PayPal account credentials, including emails, plaintext passwords, and associated URLs, allegedly stolen in May 2025. If real, the leak could fuel credential stuffing and other attacks across multiple platforms, since URLs may link exposed data to different services. Researchers note the structure of the dataset suggests it was harvested using info-stealing malware rather than a direct PayPal breach. The low asking price and limited samples raise doubts about the dataset’s overall quality, but users are still urged to change passwords, enable MFA, and use password managers for protection. Read more.

New HTTP/2 flaw could trigger record-breaking DDoS attacks

A new distributed denial-of-service (DDoS) vulnerability in HTTP/2, dubbed “MadeYouReset,” has been uncovered by Tel Aviv University researchers, raising concerns of record-breaking cyberattacks similar to 2023’s “Rapid Reset.” Like its predecessor, MadeYouReset manipulates stream cancellations in HTTP/2, but instead of relying on client-side resets, it abuses invalid control messages that force servers to cancel streams while backend processes continue. The flaw, tracked as CVE-2025-8671, affects major implementations including Netty and F5 BIG-IP. While some vendors had already hardened systems after Rapid Reset, many required new patches. Researchers note that fully mitigating the issue is complex, as fixes may introduce trade-offs in performance and security. Read more.

U.K. drops demand for Apple iCloud backdoor access

The U.K. has reportedly abandoned its push to force Apple to weaken encryption by creating a backdoor into iCloud, a move that would have exposed U.S. citizens’ private data. U.S. Director of National Intelligence Tulsi Gabbard said the reversal followed months of coordination to protect Americans’ civil liberties and that “as a result, the UK has agreed to drop its mandate for Apple to provide a ‘backdoor’ that would have enabled access to the protected encrypted data of American citizens and encroached on our civil liberties.” The order, issued in January 2025 under the Investigatory Powers Act, sought blanket access to encrypted cloud backups via a technical capability notice. Apple disabled Advanced Data Protection in the U.K. earlier this year in response but has maintained its stance of never building backdoors. Critics warned the mandate would endanger security worldwide. Interestingly, Google and Meta confirmed that they received no such requests from the U.K. Read more.

Attackers patch flaws after exploiting them to block rivals

A new attack technique has emerged in which a threat actor exploited flaws and then patched them afterward to block competitors and reduce detection from vulnerability scanners. Red Canary researchers uncovered the method in a campaign abusing Apache ActiveMQ’s CVE-2023-46604, a critical remote code execution flaw disclosed in October 2023. In one case, attackers replaced vulnerable JAR files with patched versions, locking out rival actors while maintaining persistence through other means. They also deployed a new downloader, DripDropper, which communicates with a Dropbox account to execute malicious tasks and enable long-term access. Despite available patches, CVE-2023-46604 remains heavily exploited to deliver malware, ransomware, and cryptominers. “The patching of the vulnerability to prevent competition underscores how prevalent exploitation can be,” said Red Canary. Read more.

Cybersecurity information-sharing law nears expiration

The Cybersecurity Information Sharing Act (CISA) of 2015 is set to expire at the end of September, sparking concerns that cyber threat intelligence sharing could sharply decline as a result. The law, which provides liability protections for companies sharing threat data with peers and the federal government, underpins much of today’s information exchange between sectors. Experts warn that its lapse would shift decisions from CISOs to corporate legal teams, where liability risks could halt most sharing activity. “We can expect, roughly, potentially, if this expires, maybe an 80 to 90% reduction in cyber threat information flows, like raw flows,” Emily Park, a Democratic staffer on the Senate Homeland Security and Governmental Affairs Committee, said. “But that doesn’t say anything about the break in trust that will occur as well, because at its core, CISA 2015, as an authority, is about trust, and being able to trust the businesses and organizations around you, and being able to trust the federal government that it will use the information you share with it.” Read more.

Workday hit in sophisticated social engineering breach

Enterprise software provider Workday has confirmed a security incident stemming from a compromised third-party CRM platform that exposed employee contact details. According to Workday, the sophisticated breach was part of a large social engineering campaign in which attackers impersonated HR and IT staff through calls and texts to obtain login credentials. Workday stressed that “there is no indication of access to customer tenants or the data within them,” a key assurance given its extensive Fortune 500 customer base. Experts warn that even limited data, such as email addresses and phone numbers, can fuel follow-on phishing attempts. The case highlights the growing risk of third-party integrations and the need for regular audits, tighter vendor oversight, and continuous employee security training. Read more.

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles