2 min read

Monthly Security Bulletin – June 2025

Catch up on June’s most critical cybersecurity news — from malware outbreaks and major breaches to policy changes and tech updates:

  1. Microsoft and CrowdStrike partner to link hacking group names
  2. Microsoft ships emergency patch to fix Windows 11 startup failures
  3. SentinelOne: Last week’s 7-hour outage caused by software flaw
  4. Android malware Crocodilus adds fake contacts to spoof trusted callers
  5. Scattered Spider: Three things the news doesn’t tell you
  6. FBI warns of NFT airdrop scams targeting Hedera Hashgraph wallets
  7. Germany fines Vodafone $51 million for privacy, security breaches
  8. FBI: BADBOX 2.0 Android malware infects millions of consumer devices
  9. Critical Fortinet flaws now exploited in Qilin ransomware attacks
  10. Microsoft shares script to restore inetpub folder you shouldn’t delete
  11. SentinelOne shares new details on China-linked breach attempt
  12. How To Protect Your Family’s Smartphones While on Vacation
  13. Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
  14. Microsoft creates separate Windows 11 24H2 update for incompatible PCs
  15. Password-spraying attacks target 80,000 Microsoft Entra ID accounts
  16. What to Do If You Book a Hotel or Airbnb and It Turns Out to Be a Scam
  17. Discord flaw lets hackers reuse expired invites in malware campaign
  18. Kali Linux 2025.2 released with 13 new tools, car hacking updates
  19. Sitecore CMS exploit chain starts with hardcoded ‘b’ password
  20. ChainLink Phishing: How Trusted Domains Become Threat Vectors
  21. Can users reset their own passwords without sacrificing security?
  22. Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider
  23. Russian hackers bypass Gmail MFA using stolen app passwords
  24. Dissecting a Malicious Havoc Sample
  25. US Homeland Security warns of escalating Iranian cyberattack risks
  26. How Today’s Pentest Models Compare and Why Continuous Wins
  27. How Criminals Are Using AI to Clone Travel Agents and Steal Your Money
  28. Cisco warns of max severity RCE flaws in Identity Services Engine
  29. Cloudflare open-sources Orange Meets with End-to-End encryption
  30. Microsoft Defender for Office 365 now blocks email bombing attacks
  31. Cisco Identity Services Stored Cross-Site Scripting Vulnerability

Read the full report:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

​​ 

Your browser does not support PDFs. Download the PDF

Download