Executive Summary
Small businesses continue to dominate the ranks of breach victims at 84.25%. When we consider that small businesses represent about half of employment globally and about 44% of US GDP they fall victim to more than their fair share of cyber-attacks. This is a symptom of the fact that many SMBs lag larger enterprises in their security posture and capabilities. Lacking the financial resources of large enterprises, a cyber breach is also more likely to put an SMB out of business. Smaller businesses must focus on addressing cyber risk – their survival depends on it.
Report Links
Download Threat Brief For August 1-15 2025
Top Ransomware
Ransomware | Percentage | Previous | Change |
---|---|---|---|
Qilin | 0.200787 | 0.131 | remains at #1 |
Akira | 0.141732 | 0.0992 | Up from 3 |
PLAY | 0.0748031 | ||
Sinobi | 0.0669291 | ||
BlackNevas | 0.0472441 |
Amongst ransomware actors, Qilin has solidified its position in first place, growing from 13% to just over 20% of attacks. Akira has also strengthened its position, moving to number 2 with just over 14% of attacks (up from just under 10%). The remaining positions in the top 5 ransomware actors are taken by new players: PLAY, Sinobi and BlackNevas. BlackNevas, a crypto-ransomware actor also known as Trial_Recovery, while first seen in September 2024, is notable for its recent reappearance after a hiatus of several months.
Victim Sector
Sector | Percentage | Previous |
---|---|---|
manufacturing | 0.165354 | 0.1508 |
financial-services | 0.161417 | 0.1389 |
construction | 0.133858 | 0.1627 |
retail | 0.110236 | 0.1548 |
technology | 0.0826772 | 0.1071 |
Victim Location
Location | Percentage | Previous |
---|---|---|
USA | 0.574803 | 0.5 |
UK | 0.0629921 | 0.0437 |
Germany | 0.0511811 | 0.0357 |
Italy | 0.0433071 | 0.0397 |
Canada | 0.0314961 | 0.0357 |
Trending Adversaries
- Curly COMrades
- Linen Typhoon
- ShinyHunters
- Storm-2603
- Violet Typhoon
Amongst trending adversaries, it is worth noting Curly COMrades, which is an APT group with apparent links to the Russian Federation. The name “Curly COMrades” is derived from their use of curl.exe
for Command and Control (C2) communications and data exfiltration. Their main targets appear to be in Eastern Europe, particularly organizations in EU-aspirant nations Moldova and Georgia. Once they infiltrate a network they set up multiple reverse proxy tunnels to relays under their control. These tunnels are ultimately used to exfiltrate data, apparently for espionage purposes. Indicators of Compromise and TTPs are listed in Bitdefender’s report and can be used to create detection rules. While targets are currently primarily in Georgia and Moldova, Russian groups are notorious for targeting any country that supports Ukraine.
Trending & Actively Exploited Vulnerabilities
CVE | Vendor | Product |
---|---|---|
CVE-2020-25078 | D-Link | DCS-2530L and DCS-2670L Devices |
CVE-2020-25079 | D-Link | DCS-2530L and DCS-2670L Devices |
CVE-2022-40799 | D-Link | DNR-322L |
CVE-2025-25256 | Fortinet | FortiSIEM |
CVE-2025-53786 | Microsoft | Exchange |
CVE-2025-54948 | Trend Micro | Apex One |
Vulnerabilities that warrant attention include 3 affecting D-Link equipment and dating back to 2020 and 2022 (CVE-2020-25078, CVE-2020-25079, CVE-2022-40799). Of particular concern is a recently announced high-severity vulnerability in on-premises Microsoft Exchange Server 2019 deployments (CVE-2025-53786). Microsoft strongly recommends that affected organizations promptly apply hotfixes which were provided in April 2025. Organizations with vulnerable systems exposed to the Internet should consider isolating them until they are patched.
Trending Malware
- 4L4MD4R
- EDRKillShifter
- MucorAgent
- Plague
- SparkKitty
- XZ backdoor
Top News
- Critical Zero-Day Bugs Crack Open CyberArk, HashiCorp Password Vaults
- Hacker extradited to US for stealing $3.3 million in crypto
- Microsoft pays record $17 million in bounties
- New 'Shade BIOS' Technique Beats Every Kind of AV
- New Ghost Calls tactic abuses Zoom and Microsoft Teams
- ShinyHunters Tactics Now Mirror Scattered Spider
- SonicWall urges admins to disable SSLVPN amid critical bug
- Over $300 million in cybercrime crypto seized by DOJ
Contributors
Written by Jeremy Nichols, former Director Of The Global Threat Intelligence Center
Executive Summaries & Adversary Bio’s by Geoff Rehmet, Cybersecurity Expert
Produced & Distributed By Phish Tank Cybersecurity Marketing Division
Categories
- B2B Marketing & Lead Generation (17)
- Digital Marketing Trends & Thought Leadership (15)
- Content Marketing & Copywriting (13)
- SEO Strategies & Best Practices (8)
- Marketing Analytics & Data Insights (6)
- Marketing Technology & Tools (6)
- Social Media Marketing & Management (4)
- PPC & Online Advertising (4)
- Cybersecurity Reports (4)
- E-commerce Marketing & Growth (2)
- Conversion Rate Optimization (1)
- Email Marketing & Automation (1)