Monthly Security Bulletin – June 2025
Catch up on June’s most critical cybersecurity news — from malware outbreaks and major breaches to policy changes and tech updates:
- Microsoft and CrowdStrike partner to link hacking group names
- Microsoft ships emergency patch to fix Windows 11 startup failures
- SentinelOne: Last week’s 7-hour outage caused by software flaw
- Android malware Crocodilus adds fake contacts to spoof trusted callers
- Scattered Spider: Three things the news doesn’t tell you
- FBI warns of NFT airdrop scams targeting Hedera Hashgraph wallets
- Germany fines Vodafone $51 million for privacy, security breaches
- FBI: BADBOX 2.0 Android malware infects millions of consumer devices
- Critical Fortinet flaws now exploited in Qilin ransomware attacks
- Microsoft shares script to restore inetpub folder you shouldn’t delete
- SentinelOne shares new details on China-linked breach attempt
- How To Protect Your Family’s Smartphones While on Vacation
- Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
- Microsoft creates separate Windows 11 24H2 update for incompatible PCs
- Password-spraying attacks target 80,000 Microsoft Entra ID accounts
- What to Do If You Book a Hotel or Airbnb and It Turns Out to Be a Scam
- Discord flaw lets hackers reuse expired invites in malware campaign
- Kali Linux 2025.2 released with 13 new tools, car hacking updates
- Sitecore CMS exploit chain starts with hardcoded ‘b’ password
- ChainLink Phishing: How Trusted Domains Become Threat Vectors
- Can users reset their own passwords without sacrificing security?
- Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider
- Russian hackers bypass Gmail MFA using stolen app passwords
- Dissecting a Malicious Havoc Sample
- US Homeland Security warns of escalating Iranian cyberattack risks
- How Today’s Pentest Models Compare and Why Continuous Wins
- How Criminals Are Using AI to Clone Travel Agents and Steal Your Money
- Cisco warns of max severity RCE flaws in Identity Services Engine
- Cloudflare open-sources Orange Meets with End-to-End encryption
- Microsoft Defender for Office 365 now blocks email bombing attacks
- Cisco Identity Services Stored Cross-Site Scripting Vulnerability
Read the full report: