Cyber News: Week Ending September 12, 2025

Here’s a concise, non-technical summary of the week’s top cybersecurity stories, including what actions you can take to protect yourself or your organization [1][2][3].

1. Major Company Data Breaches Surge

Cloudflare, Zscaler, and other tech giants confirmed that hackers broke into accounts managed in cloud tools like Salesforce and Drift. Attackers manipulated app permissions and tried exporting sensitive data.[1]

BET-R Actions: Use strong, unique passwords for work and personal accounts. Turn on multi-factor authentication (MFA) wherever possible, especially for cloud services. Regularly review what apps have access to your accounts and remove anything unfamiliar or unused.[1]

2. Malicious Ads Spread Malware

Hackers ran fake ads for popular PDF editing software, tricking people into downloading malware that steals browser logins and credentials.[1]

BET-R Actions: Only download software from official websites or trusted app stores. Avoid clicking on ads that promise free or “premium” versions of tools. Double-check URLs and use an antivirus solution that scans downloads automatically.[1]

3. Amazon Halts Massive Phishing Attack

Amazon shut down parts of a campaign (called “Midnight Blizzard”) that targeted Microsoft 365 accounts using phishing links and dodgy apps to steal login tokens.[1]

BET-R Actions: Don’t click unexpected login or password reset links, especially those arriving by email or chat. If suspicious activity is detected, reset passwords and revoke access for unknown apps in account settings.[1]

4. Passwords for Millions Exposed

One of the largest breaches ever saw over 16 billion passwords leak online—including logins for Google, Facebook, Apple, and more—often from “info-stealer” malware on infected devices.[2]

BET-R Actions: Change passwords frequently, don’t reuse passwords, and turn on MFA. Review which devices are signed into accounts, and sign out of any you don’t recognize. If possible, use a reputable password manager to create and store strong passwords.[2]

5. SK Telecom Fined for Weak Security

SK Telecom was fined nearly $100 million after a breach exposed 23 million users’ data due to outdated software and slow security updates.[1]

BET-R Actions: Update your apps and operating systems as soon as updates are offered. Companies should promptly patch software vulnerabilities and use updated authentication methods to protect customer information.[1]

BET-R Tips to Counter Current Threats:

– Always enable multi-factor authentication for important accounts.[2]
– Update all software, including browsers, frequently.[3]
– Double-check before downloading software or clicking links, especially in emails or ads.[1]
– Use strong, unique passwords—never repeat them between accounts.[2]
– Be cautious of new apps asking for broad account or data permissions.[1]

These habits make it much harder for hackers to succeed, no matter what new threats emerge this week.[3][2][1]

Sources
[1] This Week In Cybersecurity: September 1–5, 2025 https://dailysecurityreview.com/cyber-security/this-week-in-cybersecurity-september-1-5-2025/
[2] List of Recent Data Breaches in 2025 – Bright Defense https://www.brightdefense.com/resources/recent-data-breaches/
[3] Cybersecurity News, Insights and Analysis | SecurityWeek https://www.securityweek.com

Discover more from BET-R Security Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading

search previous next tag category expand menu location phone mail time cart zoom edit close