HomeCybersecurity NewsNews roundup July 21, 2025
July 21, 2025

News roundup July 21, 2025

San Mateo, CA, July 21, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

Meta patched flaw exposing private AI prompts

Meta patched a critical security flaw that allowed users of its AI chatbot to access private prompts and responses submitted by others, raising serious concerns about data privacy in generative AI platforms. The bug stemmed from Meta’s failure to verify user authorization when editing prompts. The system assigned easily guessable ID numbers to each interaction, allowing potential scraping of private content. Meta fixed the issue, discovered by the founder of security testing firm AppSecure, Sandeep Hodkasia, by late January 2025 and “found no evidence of abuse and rewarded the researcher.” According to TechCrunch, Hodkasiai “identified the bug after examining how Meta AI allows its logged-in users to edit their AI prompts to regenerate text and images. He discovered that when a user edits their prompt, Meta’s back-end servers assign the prompt and its AI-generated response a unique number. By analyzing the network traffic in his browser while editing an AI prompt, Hodkasia found he could change that unique number and Meta’s servers would return a prompt and AI-generated response of someone else entirely.” Read more.

Iranian hackers target Western cybersecurity experts

Iranian state-sponsored group APT35, AKA Charming Kitten, has launched a sophisticated AI-enhanced phishing campaign targeting cybersecurity researchers and academics in Western countries. The operation marks a strategic shift in Iran’s cyber tactics following the June 2025 U.S. strikes on its nuclear facilities. Instead of traditional surveillance, APT35 now uses AI to craft convincing, personalized emails that mimic trusted industry figures and build long-term relationships with victims. The group’s emails reference relevant research and trends, exploiting trust and curiosity to bait professionals. CyberProof analysts say this evolution poses a significant threat to the global cybersecurity community by targeting its knowledge base directly. Read more.

Hackers use AI cloaking to hide phishing and scams

Cybercriminals are increasingly using AI-enhanced cloaking services to evade detection, according to new research by SlashNext. Platforms like Hoax Tech and JS Click Cloaker offer “cloaking-as-a-service,” deploying machine learning, real-time profiling, and behavioral targeting to show scam content to real human users while masking it from automated scanners. Experts warn that this represents a major leap in the sophistication of threat actors. “Using AI to detect the difference between a tool that is checking to see if a link in an email is malicious, and a real user who has clicked a link that made it through their email filter because no malicious activity was detected, is certainly next level,” said Apollo CISO Andy Bennett. Security leaders recommend implementing zero-trust frameworks, utilizing behavioral analysis tools, and employing adaptive defenses to counter the rising threat. Read more.

Thai police raid cyber scam sites linked to Kok An

Thai police raided seven properties allegedly tied to Cambodian tycoon and senator Kok An as part of a growing crackdown on Southeast Asia’s cyber scam industry. The raids, which included locations in Bangkok and the Sa Kaeo province, targeted Kok’s daughters Juree and Phu Chelin, accused of running a scam compound in Poipet, Cambodia. Arrest warrants were issued for them and Kok’s son, with Thai authorities seeking an Interpol Red Notice for Kok himself. The actions deepen a border-driven diplomatic rift between Thailand and Cambodia, already marked by Prime Minister Paetongtarn Shinawatra’s suspension and Cambodia’s Hun Sen accusing Thailand of hypocrisy. Amnesty International recently released a report covering the scamming problem in Cambodia, in which it identified more than 50 compounds operating in the country and interviewed survivors who were trafficked into the facilities and forced to engage in fraud. Read more.

China extracts phone data with new surveillance tool

Chinese authorities are utilizing a new surveillance malware tool, Massistant, to extract sensitive data from seized Android phones, including encrypted messages, images, location histories, and other information, according to a report by cybersecurity firm Lookout. Its use appears widespread, raising serious privacy concerns for both Chinese citizens and travelers. “It’s a big concern. I think anybody who’s traveling in the region needs to be aware that the device that they bring into the country could very well be confiscated, and anything that’s on it could be collected,” warned Lookout researcher Kristina Balaam. Though Lookout could not confirm whether an iOS version exists, the developer’s website shows iPhones connected to its forensic system. Chinese law, since at least 2024, permits state police to inspect digital devices without a warrant. Massistant is a successor to Meiya Pico’s earlier tool, MSSocket, and the firm holds a 40% share in China’s forensic tech market. Read more.

Cloudflare stops record-breaking 7.3Tbps DDoS attack

Cloudflare has revealed that it blocked the largest DDoS attack ever recorded, peaking at 7.3 Terabits per second. The 45-second burst surpassed the previous 6.5Tbps record from Q1 and exemplifies a new trend in which attackers use ultra-short, high-intensity surges to bypass defenses and inflict rapid damage. The company reported a sharp rise in these hyper-volumetric attacks, logging 6,500 between April and June, or about 71 daily. DDoS strikes exceeding 100 million packets per second increased by 592%, while those topping 1 billion pps and 1 Tbps doubled. Hyper-volumetric DDoS attacks are defined as those involving traffic exceeding 1 billion packets per second (pps), 1 terabit per second (Tbps), or HTTP floods over 1 million requests per second. Ransom DDoS incidents jumped 68% quarter-over-quarter, with more customers receiving threats or facing extortion-driven attacks. Read more.

Ex-Air Force officer leaked secrets on dating app

Retired U.S. Air Force Lt. Colonel David Slater has pleaded guilty to leaking SECRET-level military intelligence about Russia’s war in Ukraine through a dating app to someone posing as a Ukrainian woman. While working as a civilian at U.S. Strategic Command, Slater repeatedly violated national security protocols by sharing classified data, including NATO plans and details of weapons supplies, between February and April 2022. Federal prosecutors charged Slater under the Espionage Act with one count of conspiracy and two counts of unauthorized disclosure of national defense information. Despite holding a TOP SECRET//SCI clearance and receiving extensive security training, Slater responded to requests such as “what is shown on the screens in the special room?” and “the supply of weapons is completely classified, which is great!” Prosecutors stressed that the co-conspirator manipulated him into revealing intelligence that, if disclosed, could severely harm U.S. national security. The case highlights the growing threat of foreign actors using online platforms for espionage through social engineering. Read more.

GMX hacker returns $42M, gets $5M bounty

The hacker behind a $42 million exploit of decentralized exchange GMX has returned the stolen cryptocurrency in exchange for a $5 million bounty, following negotiations with the platform. In a note, the company said to the hacker that “it’s likely already clear to you that the decision between accepting this bounty and keeping the exploited funds is the difference between being able to spend the funds freely versus taking additional risks to access them.” GMX offered not to pursue legal action if the funds were returned and assured users they’d be made whole through bug bounty reserves. The hacker responded via blockchain message saying “ok, funds will be returned later,” eventually transferring $40.5 million in assets, 10,000 ETH and $10.5 million in FRAX, back to GMX. GMX’s post-mortem revealed that the vulnerability the hacker used has already been patched via recent updates. Read more.

Chinese hackers breach top D.C. law firm

Suspected Chinese government-affiliated hackers breached Microsoft 365 accounts belonging to attorneys and advisers at prominent Washington, D.C. law firm Wiley Rein, the firm disclosed to clients. Known for its influence in U.S. trade and foreign investment matters, Wiley Rein suggested the intrusion was part of a broader intelligence-gathering effort amid escalating U.S.-China tensions. The breach follows the Trump administration’s imposition of new tariffs on Chinese exports, a flashpoint that has intensified bilateral espionage. Mandiant is handling incident remediation, while law enforcement, including the FBI, has been notified. China’s U.S. embassy denied involvement, denouncing accusations lacking evidence. Brett Leatherman, the assistant director of the FBI’s Cyber Division, warns that “Beijing’s cyber doctrine is more than access… It’s about building long-term leverage.” Wiley Rein is still assessing what data was breached. Read more.

Fake IDE plugin used to steal $500K in crypto

A fake extension for the Cursor AI IDE, disguised as a Solidity syntax highlighter, infected systems with infostealers and remote access tools, leading to a $500,000 cryptocurrency theft from a Russian developer. The malicious extension, named “Solidity Language,” was available on the Open VSX registry and secretly executed a PowerShell script to install ScreenConnect and download further malware. The malware deployed included Quasar RAT and PureLogs stealer, which stole credentials, browser data, and crypto wallets. Though removed on July 2 after reaching 54,000 downloads, a duplicate version called “solidity” was quickly reposted and inflated to nearly two million installs to appear legitimate. Similar malware-laced extensions were found on the Visual Studio Code Marketplace under names like “solaibot” and “among-eth.” Kaspersky warns that open-source repositories are increasingly exploited to spread malware, urging developers to verify extensions and source code before installation. Read more.

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles