San Mateo, CA, May 12, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
PowerSchool hack leads to downstream extortion
In December 2024, hackers breached education technology provider PowerSchool using compromised credentials tied to a maintenance account. The intrusion gave them unauthorized access to sensitive information, including names, contact details, birth dates, limited medical alerts, and Social Security numbers of students and staff. PowerSchool paid an undisclosed ransom and received assurances that the stolen data would be deleted. Despite this, threat actors have reportedly contacted multiple school district customers, attempting to extort them using data from the December breach. PowerSchool confirmed these downstream extortion attempts and verified that the data samples matched those in the original hack. The company emphasized that this is not a new incident, but a continuation of the earlier breach’s fallout. The situation illustrates the ongoing risks of cyberattacks, even after ransom payments, and reinforces the need for strong cybersecurity protocols and informed incident response strategies. Read more.
LOSTKEYS malware deployed through ClickFix in COLDRIVER campaign
In early 2025, the Russian-linked hacking group COLDRIVER — also known as Callisto, Star Blizzard, and UNC4057—launched a sophisticated cyber espionage campaign using a new malware strain called LOSTKEYS. The malware is distributed through a technique known as ClickFix, which tricks victims into executing malicious PowerShell commands disguised as CAPTCHA verifications. Once activated, these commands download and install LOSTKEYS, which then exfiltrate files from specified directories, collect system data, and monitor active processes. This campaign has primarily targeted current and former Western government and military advisors, journalists, think tanks, NGOs, and individuals connected to Ukraine. Traditionally focused on credential phishing, COLDRIVER’s use of LOSTKEYS marks a shift toward more direct and invasive tactics. Initially used by cybercriminals, the ClickFix technique has gained traction among state-sponsored actors for its ability to bypass standard security controls. Read more.
Six DDoS-for-hire platforms dismantled in Europol-led bust
Europol reports that four individuals have been arrested in Poland for administering and selling access to distributed denial-of-service (DDoS) platforms. Authorities say the suspects operated six “stressor” services—Cfxapi, Cfxsecurity, neostress, jetstress, quickdown, and zapcut—that enabled global customers to launch thousands of DDoS attacks against targets including government offices, businesses, and schools. The takedown involved Poland’s Central Cybercrime Bureau, the German Federal Criminal Police Office, the Prosecutor General’s Office in Frankfurt, the Dutch National Police, and several U.S. agencies, including the Department of Justice, the FBI, Homeland Security Investigations (HSI), and the Defense Criminal Investigative Service (DCIS). Read more.
LockBit ransomware gang breached and data leaked
LockBit, one of the most prolific ransomware groups, has been hacked. Its dark web affiliate panels were defaced with a message, “Don’t do crime. CRIME IS BAD. xoxo from Prague,” along with a link to download a file labeled “paneled_dump.zip.” According to BleepingComputer, the leaked database contains 20 tables, including 59,975 unique bitcoin addresses. Key tables include “builds,” which store affiliate-generated attack payloads; “builds_configurations,” listing the configurations used for each build; “chats,” which hold 4,442 negotiation messages between LockBit and victims; and “users,” which names 75 admins and affiliates. LockBit’s primary operator, LockBitSupp, has confirmed the breach is legitimate. The identity of the hacker remains unknown. Read more.
North Korean hackers pull off largest crypto heist to date
State-sponsored North Korean hackers have executed what experts call the largest cryptocurrency theft operation to date, stealing $625 million through a highly coordinated campaign. The attackers compromised a high-profile macOS developer’s environment and used Amazon Web Services (AWS) infrastructure as pivot points to infiltrate multiple crypto exchanges. The operation began with a spear-phishing campaign targeting a senior developer who had privileged access to the codebase of a popular cryptocurrency trading application. Using a new malware variant tailored to persist in macOS environments, the hackers extracted credentials and gained access to multiple AWS instances supporting the platform’s infrastructure. According to researchers at Elastic, the operation showcased unprecedented coordination and marked a significant evolution in the DPRK’s cyber capabilities. Read more.
NSO Group fined $168 million for Pegasus spyware attacks via WhatsApp
NSO Group has been ordered to pay $168 million in damages to WhatsApp for violating U.S. laws by “exploiting WhatsApp servers to deploy Pegasus spyware, targeting over 1,400 individuals globally.” Court documents show that NSO infected 456 victims in Mexico, 100 in India, 82 in Bahrain, 69 in Morocco, and 58 in Pakistan, targeting people across 51 countries. “The attacks leveraged a then zero-day vulnerability in WhatsApp’s voice calling feature (CVE-2019-3568, CVSS score: 9.8) to trigger the deployment of the spyware.” In a post on X, head of WhatsApp at Meta Will Cathcart said, “our case against spyware developer NSO made history when the court found that they broke both federal and state laws in the United States in December … And the jury’s verdict today to punish NSO is a critical deterrent to the spyware industry against their illegal acts aimed at American companies and our users worldwide.”Read more.
CISA warns of active exploitation in Langflow RCE vulnerability
The Cybersecurity & Infrastructure Security Agency (CISA) has “tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and mitigations as soon as possible.” Langflow is an open-source tool used to build LLM-powered workflows with LangChain components through a drag-and-drop interface. Popular among AI developers, researchers, and startups, the platform helps prototype AI applications and chatbots. Tracked as CVE-2025-3248, the flaw is a “critical unauthenticated RCE flaw that allows any attacker on the internet to take full control of vulnerable Langflow servers by exploiting an API endpoint flaw.” While CISA has not released technical details about the exploitation, it has given federal agencies until May 26 to apply patches or discontinue use of the platform. Read more.
GlobalX Airlines defaced in alleged Anonymous-linked hack
GlobalX Airlines suffered a website defacement following a distributed denial-of-service (DDoS) attack, reportedly carried out by hackers claiming affiliation with the Anonymous hacktivist collective. The hackers posted a message stating that the attack was retaliation for the U.S. government’s deportation program and the Trump administration’s refusal to comply with court rulings on its legality. GlobalX, whose fleet has been used to transport detainees under the deportation initiative, was also the victim of a data breach. The attackers published a March flight manifest containing passenger names and numbers, crew details, and other flight information. GlobalX has since restored control of its website. Read more.
New York Post’s X account hijacked in crypto scam scheme
Hackers compromised the New York Post’s X account and used direct messages to lure victims into a cryptocurrency scam. The messages read: “We’re lining up new guests for our podcast and would love to feature you in an upcoming episode. This is an exclusive editorial invite, with both in-person and virtual collaboration options available.” Unlike typical account takeovers pushing public crypto or gambling links, the attacker privately messaged targets, directed them to Telegram, and immediately blocked them to delay detection by the real New York Post team. Victims were invited to a Zoom call and prompted to enable audio over Wi-Fi or mobile data. Clicking the link handed control to the hacker, allowing them to drain crypto accounts. Read more.
Darcula PhaaS platform linked to theft of 884,000 credit cards
The Darcula Phishing-as-a-Service (PhaaS) operation has stolen 884,000 credit cards through malicious links, generating 13 million clicks worldwide. The discovery comes from a joint investigation by NRK, Bayerischer Rundfunk, Le Monde, and Norwegian cybersecurity firm Mnemonic, identifying Darcula’s primary creator and seller. Mnemonic traced the actor by reverse engineering the platform’s infrastructure and uncovering a phishing toolkit called Magic Cat. “The researchers also infiltrated the Telegram group associated with the Darcula operation, uncovering photos of SIM farms, modems, and evidence of lavish lifestyles financed by the scams. Through OSINT work and passive DNS analysis, they traced the operation’s digital footprints to a Chinese individual and a GitHub developer account, among other things.” The individual is reportedly a 24-year-old from Henan, China, with connections to a company believed to have developed Magic Cat. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.
