Threat Intelligence Executive Report – Volume 2025, Number 4
This issue of the Counter Threat Unit’s high-level bimonthly report discusses noteworthy updates in the threat landscape during May and June
Jonathan Greig reports: Officials at a large energy industry and federal government contractor were locked out of company financial systems for six weeks due to a recent ransomware attack. ENGlobal Corporation revealed the extended disruptions in an update to the U.S. Securities and Exchange Commission on Monday evening. “The cybersecurity incident limited the Company’s ability to access…
NL Times reports: The Royal Netherlands Marechaussee detained a 24-year-old Amsterdam-based cargo worker at Schiphol on Tuesday, May 19, on suspicion of unauthorized access to computer systems and the leaking of confidential company information, Luchtvaart Nieuws has reported. According to the ongoing investigation, the suspect allegedly used his access to a cargo handling company’s systems at the……
This breach may not turn out to be the biggest insider breach of 2025, but it may well turn out to be one of the most impactful. Jason Leopold reports: A software company that handles sensitive data for nearly every US federal agency was the victim of a cyber breach earlier this year due to…
Jay Peters reports: 5CA is a customer service support company that works with Discord. Recently, the chat platform said the vendor had been breached as part of a “security incident” where 70,000 government ID photos may have leaked. Now, 5CA says in a post on its website that it was “not hacked.” According to Discord, “this incident impacted a……
Cybersecurity researchers have lifted the lid on two threat actors that orchestrate investment scams through spoofed celebrity endorsements and conceal their activity through traffic distribution systems (TDSes). The activity clusters have been codenamed Reckless Rabbit and Ruthless Rabbit by DNS threat intelligence firm Infoblox. The attacks have been observed to lure victims with bogus
Some human errors are more dangerous than others. PA News reports: A data breach which may have put up to 100,000 people at risk of death or serious harm from the Taliban can now be reported more than three years after it took place. Here the PA news agency looks at the timeline of events…