We are just two weeks away from Black Hat 2025 and DefCon in Las Vegas. Most of the security news is focused on breaches that are happening rather than new product launches. The biggest breach news last week was the announcement over the weekend of a serious RCE flaw in SharePoint. It has caused the company to scramble and issue two emergency updates to patch CVE-2025-53770 and CVE-2025-53771.
In other news, Sectigo has bolstered its APAC management team as it seeks to expand its business in the region. It is looking forward to the introduction of 47-day SSL/TLS certificates.
1Password has announced its MCP Server for Trelica. It is available in the AWS Marketplace under AI Tools and Agents. The company has priced it at $10,000 on a 12-month contract with no discount for extending that to 24 or 36 months. However, it does provide access governance for every SaaS App on the Trelica platform, which means customers don’t need to buy additional licences.
BlueVoyant
BlueVoyant has been highlighted on the 2025 MES Midmarket 100 list for the fourth year in a row. It selects vendors based on their go-to-market strategy, how they innovate to better serve the midmarket, and the strength of their midmarket product portfolios.
Craig Hurley, head of channels at BlueVoyant, said, “Getting listed on the MES Midmarket 100 multiple times recognizes the value that BlueVoyant brings to the midmarket and partners. BlueVoyant’s Cyber Defense Platform, enables partners to offer cutting-edge technology, such as third-party cyber risk management, to shared clients to improve their cybersecurity.”
eSentire
eSentire Threat Response Unit (TRU) has published a blog looking at GhostCrypt, which was used to deliver and execute the PureRAT malware. The blog shows the initial attack vector and how the attack unfolded. It provides details on what IT security teams should look for in terms of files placed on infected machines. It also includes an analysis of GhostCrypt and PureRAT.
Europol
Europol coordinated an operation with Eurojust that targeted the pro-Russian cybercrime network NoName057(16). Involved in the operation were law enforcement from Czechia, France, Finland, Germany, Italy, Lithuania, Poland, Spain, Sweden, Switzerland, the Netherlands and the United States. Other agencies and countries also provided support for the investigation.
The action disrupted the attack infrastructure, which consisted of over one hundred computer systems worldwide. It also took a significant part of the group’s central server infrastructure offline. Seven arrest warrants were issued, and two individuals were arrested. Over 1,000 supporters of the network were notified of their potential legal liability for their involvement.
National Cyber Security Centre
The NCSC has named APT 28 and Russia’s GRU, specifically the 85th Main Special Service Centre, Military Unit 26165, as using the Authentic Antics malware. It has also sanctioned three GRU units, 26165, 29155, and 74455, as well as 18 GRU officers and agents, for cyber and information interference operations.
Authentic Antics is malware that targets Microsoft cloud accounts, establishing persistent endpoint access. It regularly asks users to log in and then captures their credentials and any OAuth tokens, allowing it access to Microsoft services.
noyb
noyb has filed GDPR complaints against TikTok, WeChat and AliExpress. All three have failed to implement automation tools to provide users with the data that they hold on them. In addition, when they do respond, they provide incomplete data and continue to withhold data when repeatedly asked for it.
noyb has filed the complaints with the data protection authorities (DPAs) in Belgium, Greece and the Netherlands. It wants a decision from the DPAs that the three companies have violated Article 12 and 15 GDPR. It also wants to see administrative fines to prevent similar violations in the future.
US Department of Justice
Cameron John Wagenius, a former soldier in the US Army, has pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. He was accused of hacking into telecommunications companies’ databases, accessing sensitive data, extortion and ransomware.
Wagenius used a tool called SSH Brute and others while working as part of a gang that stole credentials that gave them access to systems. He will be sentenced in October, where he will get a mandatory 2-year sentence for aggravated identity theft. The other charges carry terms of 5 years and 20 years. Sentences are expected to run concurrently.

















