HomeCybersecurity NewsNews roundup June 30, 2025
June 30, 2025

News roundup June 30, 2025

San Mateo, CA, June 30, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

Brother printers affected by unpatchable vulnerability

A critical, unpatchable vulnerability affects 695 models of Brother printers, scanners, and label makers, exposing millions of devices to potential attack, according to Rapid7. The flaw, CVE-2024-51978, allows attackers to generate default admin passwords using the device’s serial number, which can be obtained through other vulnerabilities or simple queries. Brother confirmed that the issue cannot be fully fixed via firmware and requires manufacturing changes. Seven additional flaws, including a remote code execution bug and a credential disclosure issue, impact Brother and other vendors like Fujifilm and Ricoh. Mitigation includes changing default passwords and applying available firmware updates immediately. The exploitation of these flaws has not yet been observed. Read more.

Iranian state hackers employ AI to phish Israeli tech experts

An Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC) has been targeting Israeli journalists, cybersecurity experts, and professors through spear-phishing campaigns, according to Check Point. The threat group, tracked as Educated Manticore, is associated with APT35 and its various aliases. “In some of those campaigns, Israeli technology and cybersecurity professionals were approached by attackers who posed as fictitious assistants to technology executives or researchers through emails and WhatsApp messages,” Check Point said in a report published Wednesday. “The threat actors directed victims who engaged with them to fake Gmail login pages or Google Meet invitations.” The phishing kit captures credentials, two-factor authentication codes, and keystrokes via advanced, React-based web applications. These attacks surged after the June 2025 outbreak of the Iran-Israel war, with threat actors leveraging AI tools for more convincing social engineering. Read more.

ClickFix attacks skyrocket in 2025

ClickFix social engineering attacks have spiked 517% in the past six months, making them the second most common threat vector after phishing, according to ESET’s latest report. ClickFix exploits user trust by displaying fake error messages, tricking victims into copying and running malicious scripts, effectively bypassing security tools. The technique, first reported by Proofpoint in 2024, now targets all major operating systems and is fueling a black market for ready-made attack kits. ClickFix attacks increasingly deliver ransomware, infostealers, cryptominers, and malware from nation-state actors. ESET also reported that SnakeStealer has become the most prevalent infostealer, overtaking Agent Tesla following law enforcement disruptions to Lumma Stealer and Danabot infrastructure. Read more.

Hacker known as IntelBroker charged by U.S. for data theft

The U.S. has charged British national Kai West, also known online as “IntelBroker,” for orchestrating a global cybercrime spree that resulted in an estimated $25 million in damages. The indictment, unsealed by the U.S. Attorney’s Office for the Southern District of New York, accuses the 25-year-old of stealing and selling sensitive data from government agencies, corporations, and critical infrastructure via BreachForums. IntelBroker has been linked to major breaches at Europol, AMD, HPE, and DC Health Link. West faces charges including conspiracy, wire fraud, and unauthorized computer access, which carry a potential penalty of up to 25 years in prison. U.S. authorities confirmed West’s identity through cryptocurrency transactions and email records. Read more.

CISA has issued an urgent warning about a critical path traversal flaw, CVE-2024-0769, which is actively exploited in D-Link DIR-859 routers. Added to the Known Exploited Vulnerabilities catalog on June 25, 2025, the flaw resides in the /hedwig.cgi component, allowing attackers to bypass file access restrictions via manipulated HTTP POST requests. Exploitation enables unauthorized access to configuration files, session tokens, and administrative controls, risking full device compromise. All hardware revisions of the DIR-859 are end-of-life with no security patches available. CISA mandates federal agencies replace affected devices by July 16, 2025. Organizations are urged to assess networks and replace vulnerable routers immediately. Read more.

Hackers turn ScreenConnect into malware using Authenticode stuffing

Threat actors are exploiting ConnectWise ScreenConnect installers to create signed remote access malware by tampering with hidden settings inside the installer’s Authenticode signature, a technique known as Authenticode stuffing. This allows attackers to insert malicious configuration data into the certificate table without breaking the digital signature. Cybersecurity firm G DATA uncovered malicious ScreenConnect binaries that showed identical hashes, except for an altered certificate table, which redirected victims to attacker-controlled servers. These attacks have been linked to phishing campaigns using PDFs or Canva pages that lead to infected installers disguised as legitimate files, such as “Request for Proposal.exe.” Once executed, the malware displays fake Windows Update screens while silently granting attackers remote access. ConnectWise revoked the compromised certificates after being alerted, but did not respond to G DATA’s report. Read more.

Google adds multi-layer defenses to prevent GenAI injection attacks

Google has detailed new safeguards aimed at enhancing the security of its generative AI systems, with a focus on emerging threats such as indirect prompt injections. Indirect prompt injections embed malicious instructions within external data sources such as emails or documents, tricking AI into exfiltrating data or executing harmful actions. Google has implemented a layered defense strategy, combining model hardening, machine learning tools to detect malicious prompts, and system-level protections. Gemini, Google’s flagship AI model, incorporates additional measures, including prompt classifiers, data “spotlighting” to neutralize hidden instructions, URL redaction, and user confirmation for risky actions. Despite these efforts, researchers warn that attackers are evolving their tactics to challenge defenses. Recent studies have shown that large language models (LLMs) can aid in generating exploits, polymorphic malware, and tailored social engineering attacks; however, they currently struggle to discover novel zero-day vulnerabilities. Read more.

Insurance provider customer data stolen in cyberattack

Aflac, one of the largest U.S. insurance providers, has confirmed a cyberattack that occurred earlier this month, compromising personal information belonging to customers, beneficiaries, employees, and agents. In a filing with the U.S. Securities and Exchange Commission, Aflac disclosed that hackers were detected in its network on June 12, and the breach has since been contained. The stolen data reportedly includes sensitive information such as Social Security numbers and health claims, though the full scope remains unknown. The attack appears to have been carried out by Scattered Spider, a financially motivated cybercrime group known for exploiting help desks and call centers through social engineering, which has been behind major breaches across various industries, including technology, casinos, and retail. The breach follows warnings from Google’s threat intelligence unit about an increase in attacks against U.S. insurers, with recent intrusions at Erie Insurance and Philadelphia Insurance Companies also linked to Scattered Spider. Read more.

Largest DDoS attack ever recorded blocked by Cloudflare

Cloudflare has revealed that it successfully blocked the largest distributed denial-of-service (DDoS) attack ever recorded, with one of its clients targeted by a flood of junk traffic peaking at 7.3 terabits per second (Tbps). The assault delivered 37.4 terabytes of data in under a minute, equivalent to roughly 9,350 high-definition movies or over 12 million photos transferred in just 45 seconds. The campaign also employed reflection attacks, where spoofed requests to third parties triggered amplified responses to the victim. Recent years have seen a dramatic rise in the scale of DDoS attacks, with Microsoft suffering a 3.47 Tbps incident in 2022, followed by a 5.6 Tbps attack on an East Asian ISP in 2024, and a 6.5 Tbps strike earlier in 2025. Despite protective measures, botnets comprising hundreds of thousands of compromised devices continue fueling these record-breaking attacks, often used to test defenses or extort businesses. Read more.

U.S. Homeland Security warns of escalating Iranian cyberattack risk

The U.S. Department of Homeland Security (DHS) issued a National Terrorism Advisory System bulletin on Sunday, warning of a heightened threat environment in the United States driven by the Iran-Israel conflict. The advisory highlights an increased risk of cyberattacks by Iran-backed hacking groups and pro-Iranian hacktivists, with low-level cyber incidents already targeting poorly secured U.S. networks. DHS officials also cautioned that violent extremists within the U.S. could be inspired to act if Iranian leaders call for retaliatory violence. Recent cyber campaigns linked to Iranian actors have targeted critical sectors, including healthcare, government, IT, and energy, often using tactics like brute-force attacks, password spraying, and MFA fatigue. Groups such as Br0k3r, believed to be state-sponsored, have been implicated in selling network access to ransomware affiliates. Though not mentioned directly in the DHS bulletin, this advisory follows U.S. strikes on Iranian nuclear facilities on Saturday and similar Israeli attacks earlier this month, prompting Iranian officials to threaten retaliation. Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles