San Mateo, CA, October 13, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
Microsoft finally ends the “update and shut down” nightmare
Microsoft has fixed a long-standing Windows 11 glitch where the “update and shut down” option caused PCs to reboot instead of powering off. The issue, active since 2021, frustrated users whose devices would restart overnight to complete updates, disrupting sleep and workflows. The bug stemmed from cumulative update errors that triggered automatic restarts. Microsoft’s September 29, 2025 Insider preview resolves the flaw by refining shutdown logic so systems fully power down when requested. Early tests in the company’s Insider program have confirmed success, with a stable release expected later this year. Thanks to the fix, average users should expect “update and shutdown” to actually do what it says. Read more.
U.S. investors take control of Pegasus spyware maker NSO Group
Notorious Israeli spyware maker NSO Group has confirmed that U.S. investors have acquired controlling ownership, marking a significant shift for the firm behind the Pegasus surveillance software used to target American government officials. Spokesperson Oded Hershowitz said the investors paid out “tens of millions of dollars,” and Israeli outlet Calcalist reported that Hollywood producer Robert Simonds leads the group. NSO Group has a documented history of selling its wares to governments looking to target and hack journalists, civil rights groups, and human rights defenders. The deal raises red flags among experts such as Citizen Lab’s John Scott-Railton, who said, “My real concern is that NSO has strenuously tried to enter the United States and sell their product to American police forces in U.S. cities. This dictator tech does not belong anywhere near Americans, or our constitutionally protect[ed] rights or freedoms.” Read more.
Google launches $30,000 bug bounty for AI vulnerabilities
Google has introduced a new AI Vulnerability Reward Program (VRP) offering up to $30,000 for verified bugs in its AI products, including Search, Gemini, and Workspace apps like Gmail and Drive. The program separates AI-related flaws from its previous Abuse VRP to simplify reporting and improve reward clarity. Google defines AI vulnerabilities as those involving large language models or generative AI interactions, covering issues like rogue actions, data exfiltration, phishing enablement, and model theft. Base rewards reach $20,000 for high-tier flaws, with multipliers raising payouts to $30,000. Prompt injections and jailbreaks are excluded. Participants who opt out of a cash reward may donate their funds to charity, with Google promising to double the amount. Read more.
Apple doubles bug bounties with record $5 million payouts
Apple is expanding its bug bounty program by doubling top payouts, adding research categories, and making rewards more transparent. Since 2020, Apple has awarded $35 million to 800 researchers through the program. The highest reward under the new expansion is now $2 million for zero-click remote compromise bugs, but that can actually exceed $5 million with additional bonuses applied. Apple called this “an unprecedented amount in the industry and the largest payout offered by any bounty program we’re aware of.” New or increased prizes include $1 million for one-click remote attacks, wireless proximity exploits, broad unauthorized iCloud access, and WebKit exploit chains, plus awards of up to $500,000 for device attacks and sandbox escapes. Apple will also distribute 1,000 secured iPhone 17 units to civil society groups likely to be targeted by spyware. Read more.
OpenAI blocks state-backed hackers using ChatGPT for cybercrime
OpenAI says it has disrupted three clusters of hackers misusing ChatGPT to aid in malware and phishing campaigns tied to Russian, North Korean, and Chinese threat groups. According to a report published Tuesday, Russian-speaking actors used ChatGPT to refine a RAT and credential stealer. At the same time, a North Korea-linked cluster leveraged it to support spear-phishing and C2 development. A third group tied to China used the tool for multilingual phishing content and targeting the semiconductor industry. OpenAI also blocked accounts linked to global scam and influence operations, including networks in Cambodia, Myanmar, Nigeria, and China. Rival Anthropic, meanwhile, released Petri, an open-source AI auditing tool that “deploys an automated agent to test a target AI system through diverse multi-turn conversations involving simulated users and tools.” Read more.
Teens arrested over London nursery ransomware targeting 8,000 children
Two teenagers have been arrested in Bishop’s Stortford after allegedly launching a ransomware attack and extortion attempt against the Kido nursery group in London, according to the Metropolitan Police. The attackers, who dubbed themselves “Radiant,” reportedly demanded £600,000 in Bitcoin after stealing data on 8,000 children, including names, addresses, photos, and parent contact details from the nursery’s Famly account. They allegedly pressured parents directly and posted images of children on the dark web before claiming to have deleted them in response to public outrage. Children’s data remains highly valuable to cybercriminals, thanks to kids having perfect credit scores and because the fraud goes undetected for an extended period of time. The incident is a further example of teens engaging in cybercrime. Read more.
North Korean hackers steal a staggering $2 billion in crypto in 2025
According to a report from blockchain analysis firm Elliptic, North Korean hackers have stolen more than $2 billion in cryptocurrency so far in 2025. For comparison, the United Nations Security Council estimated that from 2017 to 2023, the rogue nation’s hackers made off with $3 billion in crypto. Elliptic said the regime has conducted over 30 hacks in 2025, surpassing its 2022 peak of $1.35 billion, and bringing its total theft since 2017 to at least $6 billion. Unlike earlier attacks exploiting technical flaws, most 2025 heists relied on social engineering to trick victims, with hackers now also targeting wealthy individuals. The year’s record was primarily driven by the $1.4 billion theft from Bybit, attributed to North Korea by the FBI. Read more.
New FileFix malware attack hides inside fake Fortinet tool
A new FileFix social engineering variant is exploiting cache smuggling to bypass security tools and deliver malware disguised as a “Fortinet VPN Compliance Checker.” First spotted by researcher P4nd3m1cb0y and detailed further by cybersecurity firm Expel’s Marcus Hutchins, the attack tricks victims into pasting what looks like a network path into Windows File Explorer. The path is displayed as “\\Public\Support\VPN\ForticlientCompliance.exe” but contains a PowerShell command that extracts a ZIP archive, allowing the malware to run without traditional downloads or flagged web requests. “Neither the webpage nor the PowerShell script explicitly download any files. By simply letting the browser cache the fake ‘image,’ the malware is able to get an entire zip file onto the local system without the PowerShell command needing to make any web requests. As a result, any tools scanning downloaded files or looking for PowerShell scripts performing web requests wouldn’t detect this behavior,” said Hutchins. Read more.
Discord breach exposes user IDs and support messages
Hackers breached a third-party customer service provider used by Discord, stealing sensitive data such as partial payment information, names, emails, contact details, messages sent to support, and photos of government-issued IDs. The September 20 attack impacted a limited number of users who interacted with Discord’s customer support or Trust and Safety teams. In a statement, Discord said that it responded by “revoking the customer support provider’s access to our ticketing system, launching an internal investigation, engaging a leading computer forensics firm to support our investigation and remediation efforts, and engaging law enforcement.” The attackers, believed to be financially motivated, demanded a ransom to prevent data leaks. Threat group Scattered Lapsus$ Hunters initially claimed responsibility, but then suggested that another group they associate with was behind the breach. Read more.
LinkedIn sues over “industrial-scale” fake account operation
LinkedIn has filed a federal lawsuit against software firm ProAPIs and its CEO, Rahmat Alam, accusing them of creating millions of phony user accounts to scrape member data and sell it to third parties. The company allegedly charges clients up to $15,000 a month for information that includes LinkedIn user details, posts, reactions, and comments. Some of this material is only accessible from behind the social network’s password wall. LinkedIn says the platform detects ProAPI’s activity regularly, but because it creates “hundreds if not thousands” of fake accounts every day, it’s not possible to stop it completely. With AI-driven data scraping proliferating, the case highlights growing concerns over industrial-scale misuse of social media content. ProAPIs has not commented on the lawsuit. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
