Oct 31, 2025 - This weekly report summarizes the latest cybersecurity incidents, emerging attack trends, critical CVEs and exploits, the most pressing risks for organizations, and actionable recommendations to enhance resilience.

Current cyber security incidents

Over the past week, the Cl0p ransomware gang has once again leveraged the MOVEit Transfer vulnerability (CVE-2023-46747), leading to data exfiltration at multiple government agencies and private organizations. Victims report significant disruptions to operational workflows and escalating ransom demands, underscoring the continued appeal of managed file transfer platforms to attackers. At the same time, security researchers disclosed an actively exploited zero-day in Google Chrome, tracked as CVE-2024-1283, which permits remote code execution via a crafted PDF file. Although Google has released an emergency patch, there is evidence that advanced persistent threat (APT) actors have already integrated this exploit into their arsenals.

Meanwhile, a large European telecom provider confirmed a breach resulting from compromised employee credentials in a social engineering campaign. Attackers gained access to internal dashboards, exfiltrating subscriber data and causing reputational damage. In a separate incident, an unnamed financial services firm experienced a third-party supply chain compromise when a software vendor’s build pipeline was seeded with malicious code, illustrating the persistent dangers of indirect attack vectors.

Current attack methods and trends

Ransomware operations continue to refine double extortion tactics by not only encrypting corporate networks but also threatening to leak sensitive data on public leak sites. Recent campaigns have targeted backup repositories and cloud-based storage to ensure victims cannot easily recover without paying. At the same time, phishing remains the primary initial access vector, but attackers are increasingly leveraging AI-driven tools to craft highly personalized lures, including deepfake voice messages that impersonate C-level executives.

Supply chain attacks are surging as threat groups realize the broad impact they can achieve by compromising a single vendor. Malicious updates or backdoored libraries in widely used DevOps tools have led to downstream compromises across hundreds of enterprises. In parallel, vulnerability chaining—combining web application flaws, misconfigured IAM policies, and edge device weaknesses—continues to enable sophisticated lateral movement inside corporate networks.

Important CVEs and exploits (selection)

CVE-2024-2140 (F5 BIG-IP iControl REST): An authentication bypass in F5’s iControl REST interface has been exploited in the wild to deploy web shells on perimeter devices. Organizations running on-premise BIG-IP instances should apply vendor patches immediately to prevent unauthorized administrative access.

CVE-2023-46747 (MOVEit Transfer): A SQL injection vulnerability in the MOVEit Transfer module continues to be weaponized by Cl0p affiliates. Despite patches released last year, many deployments remain unpatched, exposing massive personal and financial data at scale.

CVE-2024-0668 (Linux Kernel nftables): A use-after-free flaw in the nftables subsystem allows local privilege escalation. Several Linux distributions have issued updates, but exposed servers and containers that have not been updated remain vulnerable to root compromise.

CVE-2024-1283 (Google Chrome): This zero-day remote code execution vulnerability arises from a flaw in the PDFium component. Exploits have appeared in phishing emails carrying malicious PDFs, emphasizing the need for rapid browser updates.

Greatest risks for companies

Third-party and supply chain exposures rank among the most significant risks, as organizations often have limited visibility into vendor security postures. A single compromised software update or development pipeline can cascade into widespread network infiltration and data leakage. Equally concerning is the rapid transition to cloud and hybrid environments, where misconfigurations in IAM policies, storage buckets, or container orchestration platforms can provide attackers with privileged footholds.

The expansion of the remote workforce has also widened the attack surface. Home networks, personal devices, and less-secured collaboration tools are increasingly targeted for credential harvesting and initial access. Without consistent endpoint management and zero-trust segmentation, organizations face elevated risks of undetected intrusions and lateral spread.

Recommendations

To bolster resilience, organizations should prioritize patch management by adopting automated workflows that rapidly deploy critical security updates across the estate. Implementing a robust vulnerability management program—including continuous scanning, risk-based prioritization, and proof-of-concept exploit testing—can reduce the window of exposure. Enforcing least-privilege access controls, multi-factor authentication, and network micro-segmentation will limit attackers’ ability to move laterally even if they gain initial access.

Moreover, companies should enhance supply chain risk assessments by conducting regular security audits of third-party vendors, requiring attestation of secure SDLC practices, and monitoring for anomalous software updates. Finally, investing in AI-augmented detection tools and ensuring 24/7 security operations monitoring will help identify emerging threats and respond swiftly before incidents escalate.