San Mateo, CA, October 27, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
Fake YouTube network spreads global malware
A large-scale malware campaign known as the “YouTube Ghost Network” has been exploiting hacked YouTube accounts to spread stealer malware through fake tutorials and pirated software videos. Active since 2021, the network has uploaded over 3,000 malicious videos, with activity tripling in 2025, according to Check Point. The operation relies on hijacked accounts that are given designated roles for uploading, posting, and interacting to make them appear legitimate. Google has removed most of the content, but researchers warn that Ghost Networks’ modular, role-based design allows attackers to recover quickly and persist. “The ongoing evolution of malware distribution methods demonstrates the remarkable adaptability and resourcefulness of threat actors in bypassing conventional security defenses,” Check Point said. “Adversaries are increasingly shifting toward more sophisticated, platform-based strategies” that “leverage the trust inherent in legitimate accounts and the engagement mechanisms of popular platforms.” Read more.
Leaders call for ban on superintelligent AI
More than 700 public figures, technologists, and policymakers have signed an open letter calling for a global ban on developing “superintelligent” artificial intelligence until it can be proven safe and publicly supported. The letter, published by the Future of Life Institute, warns that unchecked AI competition among major tech firms could surpass human control, posing economic, social, and existential risks. Signatories include AI pioneers Yoshua Bengio and Geoffrey Hinton, Apple co-founder Steve Wozniak, and political figures from both U.S. parties. The group argues that the race toward human-level intelligence threatens civil liberties, national security, and human dignity. Despite similar past warnings, they say the urgency has now grown, as public skepticism toward superintelligence outpaces industry regulation. Read more.
Amazon blames DNS failure for AWS outage
Amazon Web Services suffered a widespread outage on Monday that disrupted major websites, banks, apps, and government services worldwide. Amazon has since confirmed that the issue stemmed from a DNS resolution failure affecting DynamoDB API endpoints in its North Virginia region. The company said the problem was mitigated fully by 2:24 a.m. PDT, with all services restored by 6:01 p.m. ET. The disruption affected Amazon.com, Ring, and customer support systems, as well as third-party platforms such as Coinbase, Venmo, Zoom, and Signal. AWS, which powers about 30% of the global cloud market, advised users to monitor its Health Dashboard for updates. Read more.
Court bans NSO Group from WhatsApp spying
A U.S. federal judge has permanently barred NSO Group from targeting WhatsApp users with its spyware, handing Meta a decisive victory in a six-year legal battle. Judge Phyllis Hamilton ruled that NSO’s actions undermined WhatsApp’s core promise of privacy and encryption, granting the injunction to prevent further targeting. However, she also slashed punitive damages from $167.3 million to $4 million, citing limited precedent for excessive awards in electronic surveillance cases. WhatsApp head Will Cathcart called the ruling a major precedent for protecting user privacy, while NSO hailed the reduced damages as progress and noted the injunction doesn’t apply to its customers. Citizen Lab’s John Scott-Railton said the decision is a “[h]uge competitive disadvantage for the notorious company” and “seriously dims value of NSO’s spyware product.” Read more.
Chinese hackers exploit SharePoint flaw worldwide
Chinese state-linked hackers are exploiting a critical Microsoft SharePoint flaw, CVE-2025-53770, in an espionage campaign spanning multiple continents. The ToolShell vulnerability allows unauthenticated remote code execution, letting attackers deploy webshells and maintain persistence even after patching. Despite Microsoft’s July 2025 fixes, Symantec researchers say groups including Budworm, Sheathminer, and Storm-2603 began exploiting the bug immediately, breaching government, telecom, and financial networks in the Middle East, Africa, South America, the U.S., and Europe. Attackers used backdoors such as Zingdoor, ShadowPad, and KrustyLoader, alongside credential theft and living-off-the-land tools, to expand their access. More than 400 compromises have been detected, underscoring ToolShell’s global impact and the urgency of patching on-premises SharePoint servers. Read more.
Lapsus$ Hunters shift to extortion-as-a-service
Palo Alto Networks’ Unit 42 has observed new signs of evolution among the Scattered Lapsus$ Hunters, a threat group linked to the Scattered Spider, ShinyHunters, and LAPSUS$ ransomware gangs. Monitoring the group’s Telegram activity since early October, analysts found references to an “extortion-as-a-service” model, an adaptation that omits file encryption to evade law enforcement scrutiny. Posts also mentioned testing a possible new ransomware variant dubbed SHINYSP1D3R, though its authenticity remains unclear. The group’s data-leak site appeared defaced, preventing researchers from confirming whether the stolen data was still being published. Despite earlier claims that they would cease operations, the hackers recently leaked data from six companies before abruptly announcing that “nothing else will be leaked.” Read more.
Meta adds new anti-scam tools to its apps
Meta has unveiled new anti-scam tools for WhatsApp and Messenger to help users spot and avoid fraudulent activity. Messenger is testing advanced scam-detection features that warn users about suspicious chats and let them submit recent messages for AI analysis. If a potential scam is found, the platform provides educational information and options to block or report the sender. WhatsApp now warns users not to share their screens with anyone but trusted contacts, aiming to prevent scammers from capturing sensitive data during video calls. Meta said the measures build on previous features, such as safety cards for unknown group invites and alerts for messages from unfamiliar numbers. The company also reported disabling nearly eight million scam-linked accounts and removing over 21,000 impersonation pages this year. Read more.
China accuses NSA of major cyberattack
China’s Ministry of State Security has accused the U.S. National Security Agency of orchestrating cyberattacks against the country’s National Time Service Center (NTSC) between 2022 and 2024, claiming the NSA used 42 types of “special cyberattack weapons” and stolen passwords to infiltrate its network and timing systems. The NTSC, which manages China’s national time synchronization for industries including defense and finance, warned that the alleged breach could disrupt power grids and satellite navigation. China called the incident “a classic form of state-level cyber aggression, internationally referred to as an advanced persistent threat” and accused Washington of hypocrisy in condemning Chinese hackers. The NSA declined to confirm or deny the claims, saying its mission remains focused on countering foreign threats to U.S. interests. Read more.
Europol dismantles SIMCARTEL cybercrime ring
European authorities have dismantled a major cybercrime-as-a-service network known as SIMCARTEL, arresting seven suspects in coordinated raids across multiple countries. The operation, led by law enforcement from Austria, Estonia, Latvia, and Finland, with support from Europol and Eurojust, targeted a SIM-box service that enabled cybercriminals to create fake online accounts using phone numbers from over 80 countries. Authorities seized five servers, 1,200 SIM-box devices operating 40,000 SIM cards, and froze over $835,000 in assets. Europol said the service facilitated the creation of 49 million fake accounts linked to more than 3,200 victims and resulting in millions in losses. Crimes associated with SIMCARTEL include “phishing, extortion, migrant smuggling, the distribution of child sexual abuse material and a variety of fraud schemes, such as investment fraud and fraud on online second-hand marketplaces.” Two associated websites were also taken down during the crackdown. Read more.
AWS outage knocks major sites offline
A widespread AWS outage has disrupted millions of websites, including Amazon.com, Prime Video, Canva, and Perplexity AI, with effects rippling across the U.S. and Europe. Amazon confirmed elevated error rates and latency in its US-EAST-1 region, which also impacted access to AWS Support Center. Fortnite, Canva, and Perplexity all reported partial or complete downtime, with login systems and editing tools temporarily offline. Downdetector showed outages across at least 15 major services, including Roblox, Hulu, and Robinhood. AWS said it’s actively investigating and working to mitigate the issue, and early reports suggest partial recovery began about 45 minutes after the disruption started. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
