BotNet News

Your source for Online Security News

What’s Next:

Many of 2025’s most damaging attacks began with compromised vendors and shared platforms. Attacks on M&S, Ukrainian government users, retailers, and SaaS vendors like Snowflake underscore the importance of multi-factor authentication (MFA), identity monitoring, and keeping track of patch levels. In a new trend, threat groups increasingly use phishing and credential stuffing over complex malware. Campaigns targeting M&S, the UK Ministry of Defence, and 3CX Desktop App demonstrate that stolen credentials allow attackers to access systems without triggering alarms.

September 2025: A criminal group linked to ShinyHunters exploited OAuth 2.0 refresh tokens from Salesloft and Drift integrations to exfiltrate Salesforce data in a financially motivated hack that impacted over 300 companies worldwide. This highlights the growing reliance on third-party integrations for productivity and security applications.

October 2023: Pro-Hamas hackers attacked Israeli government sites and Hamas websites in retaliation for Israel’s bombing of Gaza. Attackers also disrupted government digital services in Albania, demonstrating the impact of political tensions on cybersecurity.

November 2024: Chinese cybercriminals breached government networks in Cambodia to steal national defense, elections, commerce, human rights, finance, and telecommunications data. The attacks exemplified the use of file-based ransomware, which is often used in conjunction with backdoors to gain persistence in systems.

In June, cartier joined the ranks of luxury brands to reveal a breach. The attack, which exposed limited customer information, was associated with activity attributed to Scattered Spider. Norway formally attributed an April attack on a hydropower plant in Bremanger to Russia, highlighting the threat of nation-state actors and their tactics to target critical infrastructure.