← Back to list

Tuesday Morning Threat Report: Oct 21, 2025

Researchers find that satellite communications are less secure than coffee shop Wi-Fi and MANGO fashion suffers a data breach

Mark Maguire · 2025-10-21 00:50 · 0 claps · 3.8 min read
#cl0p #cybersecurit #hacking #patch-tuesday
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🔭 · Astronomy & Space 🍳 · Food & Cooking 👗 · Fashion

Tuesday Morning Threat Report: Oct 21, 2025

Where the news is always bad, but the analysis is always good.

Image by Markus Spiske on Pixabay

Image by Markus Spiske on Pixabay

Good morning everybody! Happy Tuesday!

Researchers find that satellite communications are less secure than coffee shop Wi-Fi and MANGO fashion suffers a data breach. Let’s dive in!

Top Stories:

This week’s biggest headlines. Analysis section below.

**Satellite Communications Less Secure than Coffee Shop Wi-Fi?**: Researchers from the University of Maryland and the University of California found that large amounts of sensitive satellite communications, including civilian text messages and military data, are transmitted without encryption.

**China Accuses U.S. of Hacking National Time Center**: China’s National Time Service Center is responsible for maintaining Beijing Standard Time, which is relied upon by financial markets and national defense organizations. China has accused the U.S. National Security Agency of hacking the center and stealing data from employees.

**F5 Says Nation-State Behind Hack that Stole BIG-IP Source Code**: F5, a publicly traded cybersecurity firm, disclosed that it was breached by nation-state hackers who maintained persistent access and stole the source code for its BIG-IP network security product.

**Android Phones Vulnerable to “Pixanapping” Attacks**: Researchers have published a paper warning about “Pixanapping” vulnerabilities, which allow attackers to steal two-factor authentication codes from Android devices using authenticator apps.

**EU’s Biometric Border System Off to a Bumpy Start**: The EU rolled out its new biometric Entry/Exit System (EES) at Prague’s international airport, but equipment malfunctions resulted in 90+ minute lines and border agents needing to manually process travelers.

**OpenAI’s Guardrails Framework Easily Bypassed with Prompt Injection**: Guardrails is an open-source framework released by OpenAI to help developers secure AI agents. Researchers at HiddenLayer showed that Guardrails can be easily bypassed, tricking a model into producing harmful responses.

**Microsoft Fixes 172 Vulnerabilities in October’s Patch Tuesday**: Patch Tuesday is Microsoft’s monthly security update, released on the second Tuesday of each month. In the October update, Microsoft fixed 172 vulnerabilities, including six zero-days and eight rated as critical.

**Oracle Issues Another Emergency Patch as Cl0p Victims Increase**: Oracle released a second emergency security patch to address vulnerabilities in its E-Business Suite (EBS) product. The Cl0p ransomware group has exploited EBS vulnerabilities to hack an estimated 100+ organizations.

My Takeaways

Analysis based on this week’s news and my experience in the industry. More headlines below in the Lower Echelon.

Guess Who’s Back: 2,700 organizations breached. The personal data of 93.3 million victims stolen. Healthcare, finance, and government all suffering from the same vulnerability at the hands of the same hacking group: Cl0p. The breaches happened during 2023 through a vulnerability in “MOVEit,” a popular automation software. Cl0p ended up extorting $75 million from victims and although U.S. and European police departments launched investigations, not even a single member of Cl0p has been arrested for the hacks.

Following their success breaching organizations through MOVEit, Cl0p kept a low profile. Throughout 2024 and most of 2025, they rarely made headlines, until a few weeks ago.

Oracle E-Business Suite (EBS) is a collection of software applications used by 9,000+ customers that help with HR, project management, supply chain management, and other essential functions. A few weeks ago, rumors began to spread that Cl0p was back, and that they had found a vulnerability in EBS and used it to hack dozens of organizations. In this case, reality looks like it will be worse than the rumors. Google’s Threat Intelligence Group estimates that over 100 organizations have been breached by Cl0p. Harvard confirmed they are one of Cl0p’s victims, and that they had 1 terabyte of data stolen. Cl0p’s reemergence highlights that it remains one of the top hacking groups, capable of discovering critical vulnerabilities and scalably hacking scores of victims at once.

The Lower Echelon:

Interesting cybersecurity news that didn’t quite make the cut to be a top story.

**MANGO Fashion Brand Suffers Data Breach**: MANGO, the Spanish fashion brand with over 2,800 stores worldwide, experienced a data breach that exposed customers’ personal information, including names, email addresses, and phone numbers.

**Europol Busts SIM Card Operation Connected to 3,200 Scams**: Europol’s Operation SIMCARTEL led to the seizure of equipment containing 40,000 SIM cards used in 3,200 scams that stole a total of $5 million from victims.

**GXC Team Creator Arrested by Spanish Police**: Spanish police raided and disrupted GXC Team, an online criminal network that sold hacking tools, arresting a 25-year-old Brazilian believed to be its mastermind.

**New Botnet Launching RDP Attacks**: Cybersecurity researchers at GreyNoise have detected a new botnet of over 100,000 infected devices being used to launch attacks via the Remote Desktop Protocol (RDP).

**Capita Fined $18M for Data Breach That Affected Millions**: Capita, a London-based outsourcing and professional services firm, was fined $18.8 million for a 2023 data breach that affected 6.6 million people.

**Microsoft Edge’s Internet Explorer Mode Causes Vulnerability**: Hackers exploited a zero-day vulnerability in Microsoft Edge’s Internet Explorer (IE) mode, allowing malicious websites to force victims’ browsers to reload in IE mode and execute arbitrary code.

**Chinese Hacking Group Used ArcGIS Backdoor for Over a Year**: ArcGIS, a geographic information system (GIS) software product, was compromised for over a year by the Chinese hacking group Flax Typhoon. The backdoor allowed the group to monitor ArcGIS users.

**Cisco Releases Project CodeGuard to Secure AI-Written Code**: Cisco unveiled a new framework called Project CodeGuard, a multi-step process designed to ensure AI-generated code is “secure by default.”

On the right side of this page, you can follow and subscribe to receive this newsletter to your inbox weekly (no Medium account needed, just sign in with Google)!

Thanks for reading! See everyone next week!


메타데이터
post_id
e3dd522a152a
slug
tuesday-morning-threat-report-oct-21-2025-e3dd522a152a
url
https://medium.com/@cyber_securiti/tuesday-morning-threat-report-oct-21-2025-e3dd522a152a
canonical_url
https://medium.com/@cyber_securiti/tuesday-morning-threat-report-oct-21-2025-e3dd522a152a
author_url
https://medium.com/@cyber_securiti
status
ok
fetched_at
2026-07-16 08:29:43