Friday Wrap Up: 22 August 2024
Cars weren’t the only things being unlocked — patient records, HR data, and even McDonald’s portals were on the menu.
Meanwhile, governments went after ransomware wallets, AI browsers went shopping on their own, and TikTok replaced moderators with algorithms.
🔍 From zero-days to fake Europol rewards, this week proves one thing: cyber never sleeps (but maybe TikTok’s moderators finally will).
🚨 Major Cyberattacks & Data Breaches This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.
👔 Workday discloses data breach linked to Salesforce attacks (Published on 8/18/2025, BleepingComputer). Read More
🍔 Hacker finds flaws in McDonald’s staff & partner hubs, exposing APIs and sensitive documents (Published on 8/20/2025, Dark Reading). Read More
🌿 Nearly 1M medical marijuana patient records exposed, including SSNs and health files (Published on 8/21/2025, Hackread). Read More
🛡️ Malware & Vulnerabilities Fresh malware families and critical zero-days kept defenders busy, with both Apple and Microsoft under the spotlight.
🧩 Microsoft dissects PipeMagic backdoor disguised as ChatGPT app (Published on 8/19/2025, SecurityWeek). Read More
🍏 Apple patches zero-day CVE-2025-43300 across all platforms — update now (Published on 8/21/2025, Malwarebytes). Read More
🐧 APT36 hackers abuse Linux .desktop files for malware delivery in India (Published on 8/22/2025, BleepingComputer). Read More
🛰️ Chinese Silk Typhoon hackers exploited Commvault zero-day in new campaign (Published on 8/22/2025, SecurityWeek). Read More
📡 DDoS, Outages & Infrastructure Attacks on availability and critical services made headlines, alongside a major Microsoft service disruption.
🎶 DOJ charges 22-year-old for RapperBot botnet tied to 370K DDoS attacks (Published on 8/19/2025, The Hacker News). Read More
🌐 Microsoft investigates outage impacting Copilot and Office.com users in North America (Published on 8/20/2025, BleepingComputer). Read More
🔍 Espionage & Data Extraction Nation-state operations escalated this week, targeting infrastructure, cloud, and telecom networks with precision.
🕵️ FBI warns FSB-linked hackers exploiting 7-year-old Cisco flaws for espionage (Published on 8/20/2025, The Hacker News). Read More
☁️ Chinese Murky/Genesis/Glacial Panda escalate cloud & telecom espionage (Published on 8/22/2025, The Hacker News). Read More
💻 Ransomware & Law Enforcement Actions Governments pushed back on ransomware operators, even as fake campaigns tried to muddy the waters.
💰 US seizes $2.8M from Zeppelin ransomware operator after indictment (Published on 8/18/2025, SecurityWeek). Read More
🎭 Europol confirms fake $50K Qilin ransomware reward was a troll hoax (Published on 8/21/2025, BleepingComputer). Read More
🔧 Vulnerability Research & Industry Analysis Researchers uncovered critical flaws in next-gen networks and infrastructure setups.
📶 New 5G attack “Sni5Gect” bypasses need for fake base stations (Published on 8/18/2025, SecurityWeek). Read More
🌍 Citizen Lab report reveals hidden VPN networks with shared ownership & flaws (Published on 8/19/2025, Hackread). Read More
🖥️ Hackers abuse VPS services for stealthy infrastructure setup (Published on 8/21/2025, Dark Reading). Read More
⚖️ AI, Policy & Regulation Encryption debates and AI security risks took center stage as governments and researchers clashed over control.
🔐 U.K. drops Apple encryption backdoor order after U.S. pushback (Published on 8/19/2025, The Hacker News). Read More
🤖 Perplexity’s Comet AI browser tricked into buying fake items online (Published on 8/20/2025, BleepingComputer). Read More
🎥 TikTok shifts to AI-driven moderation, triggering mass layoffs & backlash (Published on 8/22/2025, Gizmodo). Read More
Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!