Biggest Cyberattacks, Ransomware Attacks and Data Breaches in May 2025


 May 2025 was a brutal month for cybersecurity! The massive Marks & Spencer cyber attack stayed in the news daily. Get all new details on the M&S cybersecurity saga in our Updated Marks and Spencer Cyber Attack Timeline.

Sadly, that wasn’t all. The UK retail sector suffered from DragonForce’s relentless rampage. Harrods, Co-Op UK, even European Christian Dior faced aggressive attacks. Peter Green Chilled, serving major retailers including Tesco, Sainsbury’s, Aldi, M&S, Waitrose, Asda, Ocado, Co-op, and Morrisons, was also hit.

The Coinbase ransomware attack was pure drama. Attackers brazenly bribed insiders for internal system access and user data—an audacious move. The CEO took to X, rejecting ransom and offering a $20 million reward to unmask perpetrators.

Read about these and more headline-grabbing cyber events in our exclusive May 2025 roundup: ransomware attacks, data breaches, and digital mayhem.

  • Ransomware Attacks in May 2025
  • Data Breaches in May 2025
  • Cyber Attacks in May 2025
  • New Malware & Ransomware Discovered
  • Vulnerabilities Discovered & Patches Released
  • Advisories, Reports, Analysis etc. in May 2025

These alarming headlines underscore a critical truth: simply reacting to cyber incidents is no longer enough. The sheer volume and sophistication of attacks in May 2025 highlight the urgent need for robust, proactive defense strategies. Your business cannot afford to wait until it’s targeted; investing in strong cybersecurity precautions now is the only way to safeguard your data, operations, and reputation against this relentless digital mayhem.


Ransomware Attacks in May 2025

DateVictimSummaryThreat ActorBusiness ImpactSource Link
May 01, 2025SynnovisPatients left in the dark months after cyber criminals leak testing lab dataQilin RansomwareMore than 11 months after a ransomware group published information from a U.K. pathology services company, the affected patients still have not been informed about what data of theirs was exposed in the incident, with material about sexually transmitted infections and cancer cases being included in the leaks. Synnovis ransomware attack update
May 01, 2025Cobb County, GeorgiaQilin announces attack on Cobb County, GeorgiaQilin RansomwareOn May 1, Qilin added Cobb County, Georgia to its dark web leak site. The ransomware gang claims to have acquired 150 GB of data and more than 400,000 files. They provided 16 image files as proof of their claims. Qilin threatened to release the data on May 3 if no payment is received. Cobb County announced that it had declined to pay any ransom.Cobb County, Georgia ransomware attack
May 06, 2025Peru’s government portal gob.pe.Peru denies it was hit by ransomware attack following Rhysida claimsRhysida RansomwarePeru’s government is denying claims that its federal digital platform was taken over by a ransomware gang that has previously attacked governments around the world as the group demanded a 5 bitcoin ransom — worth about $472,000 —  and shared documents allegedly stolen from Peru’s government portal gob.pe.Source: The Record
May 07, 2025Toronto school district/PowerSchoolToronto school district says data not deleted after ransom was paid to hackerLockBit (Allegedly)The Toronto District School Board (TDSB) told parents and staff that it was sent an extortion letter even after a hacker was paid off by the ed tech giant PowerSchool to prevent the leak of sensitive data. PowerSchool  provides student information systems (SIS) to K-12 schools including those in the Toronto school district. 
Source: The Record
May 20, 2025Kettering HealthKettering Health hit by system-wide outage after ransomware attackInterlockKettering Health, a healthcare network that operates 14 medical centers in Ohio, was forced to cancel inpatient and outpatient procedures following a cyberattack that caused a system-wide technology outage.Kettering Health ransomware attack
May 20, 2025The logistics company Peter Green ChilledRansomware attack hits supplier of refrigerated groceries to British supermarketsApparently Scattered SpiderThe logistics company Peter Green Chilled announced being hit by a ransomware attack that is disrupting supplies of refrigerated goods to some of the country’s largest supermarkets, according to reports.Source: The Record
May 22, 2025Coca-ColaCoca-Cola ignores ransom demand, hackers dump employee dataEverest ransomwareAfter an alleged ransomware attack, hackers have publicly released Coca-Cola’s internal data. Coca-Cola’s name showed up on a dark web leak site run by the Everest ransomware gang on May 22nd. The hackers claimed they’d swiped personal data from 959 employees, most tied to Coca-Cola’s Middle East distributor.Coca-Cola ransomware attack
May 26, 2025MATLABMATLAB dev confirms ransomware attack behind service outageUnknownMathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage.Source: Bleeping Computer
May 27, 2025Sheboygan, WisconsinNearly 70,000 impacted by ransomware attack on Sheboygan, WisconsinChort ransomwareThe Wisconsin city of Sheboygan warned around 67,000 people that a ransomware attack in October gave hackers access to their personal information.Source: The Record
May 29, 2025ConnectWiseConnectWise breached in cyberattack linked to nation-state hackersUnknownIT management software firm ConnectWise said a suspected state-sponsored cyber attack breached its environment and impacted a limited number of ScreenConnect customers.Source: Bleeping Computer


Data Breaches in May 2025

DateVictimSummaryThreat ActorBusiness ImpactSource Link
May 01, 2025AscensionHealthcare group Ascension discloses second cyber attack on patients’ dataUnknownAscension Health informed some of its patients, potentially for the second time in the space of a year, that their medical data was compromised during a major cyber attack. The company said one of its former business partners, with which the company shared some patient medical data (about 430,000), was ransacked by criminals that exploited a vulnerability in some third-party software. Ascension data breach
May 01, 2025Barnstable County Sheriff’s OfficeBarnstable County Sheriff’s Office Employee On Leave, Suspected In Data BreachInsider Threat (Suspected)An employee with the Barnstable County Sheriff’s Office (BCSO) has been placed on leave for allegedly leaking personal information via a breach of data on over 100 former and one current employee. The sheriff’s office said that the leaked information included names, home addresses, and Social Security numbers.Barnstable County Sheriff’s Office data breach
May 01, 2025Oracle Health Outage45 CHS hospitals were affected by the Oracle Health outageHuman ErrorReportedly all resolved now, on April 25, Becker’s Hospital Review reported that 45 hospitals affiliated with Franklin, Tenn.-based Community Health Systems were experiencing IT outages after data storage linked to their Oracle Health EHRs was accidentally deleted. The hospitals have reverted to paper for patient records, with the issue expected to be resolved by the evening of April 28. Oracle Health engineers mistakenly deleted the storage while conducting maintenance work at one of their data centers.Source: DataBreaches.net
May 02, 2025Co-op UKCo-op cyber attack affects customer data, firm admits, after hackers contact the BBCDragonForceHackers said they had infiltrated IT networks and stolen huge amounts of customer and employee data as a Co-op spokesperson said the hackers “accessed data relating to a significant number of our current and past members”. The cyber criminals claim to have the private information of 20 million people who signed up to Co-op’s membership scheme, but the firm would not confirm that number.Source: The BBC
May 02, 2025Emera PowerNova Scotia Power Says Hackers Stole Customer InformationUnknownEmera reported earlier this week that on April 25 they detected unauthorised access to parts of their Canadian network and servers used for business applications. The impacted servers were shut down and isolated in response to the hack, which resulted in the disruption of customer phone lines and online services. However, the power company said there was no disruption to physical operations.Emera Power data breach
May 02, 2025HarrodsHarrods the next UK retailer targeted in a cyber attackDragonForce (Allegedly)In a statement, Harrods said threat actors recently attempted to hack into their systems, causing the company to restrict access to sites.Source: Bleeping Computer
May 02, 2025Star Health InsuranceHacker hired Telangana man to courier threats to Star Health Insurance MDXenzenThe case of breach of data of 3.1 crore customers of the Chennai-headquartered Star Health Insurance has taken a fresh turn with its MD Anand Roy, his wife Akhila Shetty Roy and CFO Nilesh Kambli allegedly getting threat messages delivered via courier from Hyderabad. A probe by the TN cyber crime wing has found that the hacker known by his online identity ‘Xenzen’, who had released the data in public domain in September 2024, had hired a Hyderabad-based youth to send threats to the company’s officials in February 2025.Star Health Insurance data breach update
May 02, 2025Dating app Raw Dating app Raw exposed users’ location data and personal informationUnknownA security lapse at dating app Raw publicly exposed the personal data and private location data of its users as the exposed data included users’ display names, dates of birth, dating and sexual preferences associated with the Raw app, as well as users’ locations. Some of the location data included coordinates that were specific enough to locate Raw app users with street-level accuracy.Raw dating app data breach
May 02, 2025Saskatoon children’s hospitalSaskatoon children’s hospital nurse unlawfully snooped on records of 314 patients: privacy reportInsider ThreatWithout legal authority, a nurse who worked at Saskatoon’s Jim Pattison Children’s Hospital snooped on the private medical records of 314 patients, according to a recent report. The report stated that a registered nurse (RN) who was employed in the maternity department accessed the records for reasons “unrelated to patient care.”Source: Yahoo.com
May 06, 2025UK Legal Aid AgencyUK Legal Aid Agency investigates cybersecurity incidentUnknownThe Legal Aid Agency (LAA), an executive agency of the UK’s Ministry of Justice that oversees billions in legal funding, warned law firms of a security incident and said the attackers might have accessed financial information.UK Legal Aid Agency data breach
May 06, 2025MasimoMedical device maker Masimo warns of cyber attack, manufacturing delaysUnknownMedical device company Masimo Corporation warned that a cyber attack is impacting production operations and causing delays in fulfilling customers’ orders.Source: Bleeping Computer
May 06, 2025iHeartRadioMultiple iHeartRadio stations breached in DecemberUnknownSeveral radio stations owned by iHeartMedia were breached in December, exposing Social Security numbers, financial information and other personal details.Source: The Record
May 07, 2025Insight PartnersVC giant Insight Partners confirms investor data stolen in breachUnknownVenture capital firm Insight Partners has confirmed that sensitive data for employees and limited partners was stolen in a January 2025 cyberattack.Source: Bleeping Computer
May 08, 2025PearsonEducation giant Pearson hit by cyber attack exposing customer dataUnknownEducation giant Pearson suffered a cyber attack, allowing threat actors to steal corporate data and customer information. Pearson confirmed they suffered a cyber attack and that data was stolen, but stated it was mostly “legacy data.”Source: Bleeping Computer
May 13, 2025Marks & SpencerMarks & Spencer confirms customer data stolen in cyber attackDragonForce/Scattered SpiderBritish retailer Marks and Spencer (M&S) announced that it was writing to customers to confirm their personal data had been compromised in a recent and massive cyber attack.Marks & Spencer data breach
May 14, 2025Nova Scotia PowerNova Scotia Power says customer banking details may have been stolen by hackersUnknownNova Scotia’s largest electric utility, Emera said that hackers stole sensitive information from customers in a recent cyber attack. The company discovered on April 25 that an intruder had gained access to parts of its network, prompting the companies to isolate the affected servers.Source: The Record
May 14, 2025CoinbaseCoinbase offers $20 million bounty after extortion attempt with stolen dataUnknown hackersCoinbase said in a regulatory filing with the Securities and Exchange Commission (SEC) that an “unknown threat actor” emailed a demand on May 11 for $20 million, threatening to publish stolen data about Coinbase customers and other company information. “We said no,” Coinbase said Thursday in a blog post explaining the incident. “Criminals targeted our customer support agents overseas. They used cash offers to convince a small group of insiders to copy data in our customer support tools for less than 1% of Coinbase monthly transacting users,” the blog post said. “Their aim was to gather a customer list they could contact while pretending to be Coinbase—tricking people into handing over their crypto.”Coinbase data breach
May 14, 2025Australian Human Rights CommissionAustralian Human Rights Commission leaks docs to search enginesUnknownThe Australian Human Rights Commission (AHRC) disclosed a data breach incident where private documents leaked online and were indexed by major search engines. Many of the hundreds of documents exposed online contained private, sensitive information, like names, contact information, health details, schooling, religion, employment info, and photographs.Australian Human Rights Commission data breach
May 26, 2025AdidasAdidas warns of data breach after customer service provider hackUnknownGerman sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and stole some customers’ data.Source: Bleeping Computer
May 28, 2025LexisNexisData broker LexisNexis discloses data breach affecting 364,000 peopleUnknownData broker giant LexisNexis Risk Solutions, a Georgia-based American data analytics company, has revealed that attackers stole the personal information of over 364,000 individuals in a December breach.Source: Bleeping Computer

Cyber Attacks in May 2025

DateVictimSummaryThreat ActorBusiness ImpactSource Link 
May 01, 2025CommvaultCommvault Shares IoCs After Zero-Day Attack Hits Azure EnvironmentUnknownCommvault has shared indicators of compromise (IoCs) associated with the exploitation of a vulnerability-CVE-2025-3928 (CVSS score of 8.7) recently added to CISA’s Known Exploited Vulnerabilities (KEV) catalogue. 
Commvault is investigating recent Azure environment activity by a nation-state threat actor affecting a small number of shared customers with Microsoft. Notified authorities and impacted customers are receiving assistance. Commvault has implemented stronger monitoring and key rotation measures post-attack.
Source: Security Week
May 01, 2025Bartlesville SchoolCyber attack shuts down Bartlesville School network, state testing postponedUnknownA network security incident crippled Bartlesville Public Schools’ internet systems, forcing the district to cancel state testing and prompted an investigation into the scope of the breach.Bartlesville School cyber attack
May 02, 2025MagentoMagento supply chain attack compromises hundreds of e-storesUnknownA supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational. Sansec researchers who discovered the attack report that some extensions were backdoored as far back as 2019, but the malicious code was only activated in April 2025. Source: Bleeping Computer
May 05, 2025Georgia school district, New Mexico, and New Mexico universityHackers launch ‘serious’ attacks against Georgia school district, New Mexico universityUnknownMultiple school districts and a university in New Mexico are currently suffering from cyber attacks causing operational issues for thousands of students as Georgia’s Coweta County School System said it experienced a cyber attack that will impact its 23,000 students across 29 K-12 schools. Western New Mexico University has struggled for weeks with the cyber attack that took down its website and forced officials to provide alternative services to students and administrators.Source: The Record

May 07, 2025South African AirwaysSouth African Airways says cyber attack disrupted operational systemsUnknownSouth Africa’s state-owned airline said a cyber attack temporarily disrupted its website and several internal operational systems as South African Airways (SAA) said the attack also affected its mobile application but noted the IT team was able to contain the incident and “minimise disruption to core flight operations.”Source: The Record
May 07, 2025PowerSchoolDespite ransom payment, PowerSchool hacker now extorting individual school districtsUnknownPowerSchool that was hacked in December said that the same threat actor is now attempting to use the stolen data to extort the individual school districts that it works with as Four school boards were contacted with the extortion requests, according to a source familiar with the investigation.Source: The Record
May 08, 2025Japan’s Financial Services Agency (FSA)Hackers hijack Japanese financial accounts to conduct nearly $2 billion in tradesUnknownJapan’s Financial Services Agency (FSA) reported an explosion of unauthorised stock market trades in April — with almost $2 billion in funds moved by hackers. The FSA provided updated figures for last month after initially warning that there had been a “sharp increase in the number of cases of unauthorised access and unauthorised trading” through online trading services in the first three months of 2025.Source: The Record
May 10, 2025iClickeriClicker site hack targeted students with malware via fake CAPTCHAUnknownThe website of iClicker, a popular student engagement platform, was compromised in a ClickFix attack that used a fake CAPTCHA prompt to trick students and instructors into installing malware on their devices.Source: Bleeping Computer
May 11, 2025Global Crossing Airlines Group Airline carrying out deportation flights confirms cyber attack to SECAnonymousAn airline involved in deportation flights on behalf of the Trump administration confirmed reports of a cybersecurity incident with the U.S. Securities and Exchange Commission (SEC). Global Crossing Airlines Group said a cyber attack on May 5 gave hackers access to “systems supporting portions of its business applications.” The filing with the SEC confirms reporting from the news outlet 404 Media, which was contacted by a hacker with information allegedly stolen from the company about ICE deportation flights.Source: The Record
May 12, 2025Alabama governmentAlabama says ‘cybersecurity event’ could disrupt state government servicesUnknownAlabama’s government faced a cybersecurity event that caused disruptions to government website access or other communications.Source: The Record
May 13, 2025Ukrainian governmentNorth Korean hackers target Ukrainian government in new espionage campaignThe group, tracked as TA406North Korean state-backed hackers have targeted Ukrainian government entities in a new espionage campaign, likely aimed at gathering intelligence on Russia’s war efforts, researchers have found.Source: The Record
May 13, 2025Steel company NucorCybersecurity incident forces largest US steelmaker to take some operations offlineUnknownNorth Carolina-based steel company Nucor said it temporarily halted production operations at some locations because of a recent cybersecurity incident and is working to restart them.Source: The Record
May 14, 2025Lecardo ClinicRussian hospital faces multi-day shutdown as pro-Ukraine group claims cyber attackHacker group 4B1DA private hospital in the Russian republic of Chuvashia experienced a multi-day disruption this week likely linked to a cyber attack claimed by a pro-Ukraine hacker group as Lecardo Clinic announced a “technical failure” that led to a three-day shutdown of its operations.Source: The Record
May 19, 2025Arla FoodsArla Foods confirms cyber attack disrupts production, causes delaysUnknownArla Foods has confirmed that it was targeted by a cyber attack that has disrupted its production operations. It clarified that the attack only affected its production unit in Upahl, Germany, though it expects this will result in product delivery delays or even cancellations.Source: Bleeping Computer
May 20, 2025CellcomMobile carrier Cellcom confirms cyber attack behind extended outagesUnknownWisconsin wireless provider Cellcom has confirmed that a cyber attack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025. The incident disrupted voice and SMS services for customers across Wisconsin and Upper Michigan, leaving subscribers unable to make phone calls or send text messages.Source: Bleeping Computer
May 22, 2025Cetus ProtocolHacker steals $223 million in Cetus Protocol cryptocurrency heistUnknownThe decentralised exchange Cetus Protocol announced that hackers have stolen $223 million in cryptocurrency and that it is offering a deal to stop all legal action if the funds are returned.Source: Bleeping Computer
May 27, 2025SimpleHelpDragonForce ransomware abuses SimpleHelp in MSP supply chain attackDragonForceThe DragonForce ransomware operation successfully breached a managed service provider and used its SimpleHelp remote monitoring and management (RMM) platform to steal data and deploy encryptors on downstream customers’ systems. It is believed that the threat actors exploited a chain of older SimpleHelp vulnerabilities tracked as CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726 to breach the system.Source: Bleeping Computer
May 28, 2025Victoria’s SecretVictoria’s Secret takes down website after security incidentUnknownFashion giant Victoria’s Secret took down its website and some store services due to an ongoing security incident.Source: Bleeping Computer
May 30, 2025Russian Internet Service provider ASVTDDoS incident disrupts internet for thousands in MoscowUnknownTens of thousands of people in Moscow and nearby areas lost internet access for several days after a major DDoS attack targeted the Russian Internet Service provider ASVT — an incident the company called one of the most severe of the year.Source: The Record
May 28, 2025Cork ProtocolMore than $12 million stolen from crypto platform Cork ProtocolUnknownHackers stole more than $12 million worth of cryptocurrency from the decentralised finance (DeFi) platform Cork Protocol in a cyber attack.Source: The Record
May 31, 2025Catholic healthcare organisation: St. Joseph Hospital and St. Mary’s Health System and St. Joseph Hospital.Hospitals in Maine, New Hampshire limit services after cyber attack on Catholic health organisationUnknownThree hospitals run by Catholic healthcare organisation Covenant Health are dealing with a cyber attack that forced the facilities to shut off all access to data systems. A spokesperson for Covenant Health confirmed that a cyber attack impacted two hospitals in Maine — St. Joseph Hospital and St. Mary’s Health System — and one in New Hampshire, which is also called St. Joseph Hospital.Source: The Record

New Ransomware/Malware Discovered in May 2025

New RansomwareSummary
“Bring Your Own Installer” EDR bypass techniqueA new “Bring Your Own Installer” EDR bypass technique is being exploited in attacks to bypass SentinelOne’s tamper protection feature, allowing threat actors to disable endpoint detection and response (EDR) agents to install the Babuk ransomware.
Second version of StealC, 2.2.4The creators of StealC, a widely-used information stealer and malware downloader, have released its second major version, bringing multiple stealth and data theft enhancements.
New phishing kit called ‘CoGUI’A new phishing kit named ‘CoGUI’ sent over 580 million emails to targets between January and April 2025, aiming to steal account credentials and payment data as the messages impersonate major brands like Amazon, Rakuten, PayPal, Apple, tax agencies, and banks.
A botnet malware named PumaBotA newly discovered Go-based Linux botnet malware named PumaBot is brute-forcing SSH credentials on embedded IoT devices to deploy malicious payloads.
A new remote access trojan (RAT) named NodeSnakeThe Interlock ransomware gang is deploying a previously undocumented remote access trojan (RAT) named NodeSnake against educational institutes for persistent access to corporate networks.

Vulnerabilities Discovered & Patches Released in May 2025

DateNew Flaws/FixesSummary
May 02, 2025EX1064599Microsoft has resolved an issue with a machine learning model that mistakenly flagged emails from Gmail accounts as spam in Exchange Online. 
May 06, 2025CVE-2025-3248The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organisations to apply security updates and mitigations as soon as possible. 
May 06, 2025CVE-2024-7399Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. 
May 06, 2025CVE-2025-30065A proof-of-concept exploit tool has been publicly released for a maximum severity Apache Parquet vulnerability, making it easy to find vulnerable servers.
May 07, 2025CVE-2025-29824The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. 
May 07, 2025CVE-2025-27007Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on targeted sites. 
May 08, 2025CVE-2025-20188Cisco has fixed a maximum severity flaw in IOS XE Software for Wireless LAN Controllers by a hard-coded JSON Web Token (JWT) that allows an unauthenticated remote attacker to take over devices. 
May 12, 2025CVE-2025-27920A Türkiye-backed cyberespionage group exploited a zero-day vulnerability to attack Output Messenger users linked to the Kurdish military in Iraq. 
May 12, 2025CVE-2025-3462 and CVE-2025-3463The ASUS DriverHub driver management utility was vulnerable to a critical remote code execution flaw that allowed malicious sites to execute commands on devices with the software installed. 
May 14, 2025CVE-2025-31324Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers. 
May 16, 2025CVE-2025-4664CISA warned U.S. federal agencies to secure their systems against ongoing attacks exploiting a high-severity vulnerability in the Chrome web browser. 
May 22, 2025CVE-2025-4428Chinese hackers have been exploiting a remote code execution flaw in Ivanti Endpoint Manager Mobile (EPMM) to breach high-profile organizations worldwide. 
May 22, 2025CVE-2025-0994Chinese-speaking hackers have exploited a now-patched Trimble Cityworks zero-day to breach multiple local governing bodies across the United States.
May 22, 2025CVE-2025-34027, CVE-2025-34026, CVE-2025-34025Critical vulnerabilities in Versa Concerto that are still unpatched could allow remote attackers to bypass authentication and execute arbitrary code on affected systems. 

Warnings/Advisories/Reports/Analysis

DateNew Flaws/FixesSummary
May 02, 2025EX1064599Microsoft has resolved an issue with a machine learning model that mistakenly flagged emails from Gmail accounts as spam in Exchange Online. 
May 06, 2025CVE-2025-3248The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organisations to apply security updates and mitigations as soon as possible. 
May 06, 2025CVE-2024-7399Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. 
May 06, 2025CVE-2025-30065A proof-of-concept exploit tool has been publicly released for a maximum severity Apache Parquet vulnerability, making it easy to find vulnerable servers.
May 07, 2025CVE-2025-29824The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. 
May 07, 2025CVE-2025-27007Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on targeted sites. 
May 08, 2025CVE-2025-20188Cisco has fixed a maximum severity flaw in IOS XE Software for Wireless LAN Controllers by a hard-coded JSON Web Token (JWT) that allows an unauthenticated remote attacker to take over devices. 
May 12, 2025CVE-2025-27920A Türkiye-backed cyberespionage group exploited a zero-day vulnerability to attack Output Messenger users linked to the Kurdish military in Iraq. 
May 12, 2025CVE-2025-3462 and CVE-2025-3463The ASUS DriverHub driver management utility was vulnerable to a critical remote code execution flaw that allowed malicious sites to execute commands on devices with the software installed. 
May 14, 2025CVE-2025-31324Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers. 
May 16, 2025CVE-2025-4664CISA warned U.S. federal agencies to secure their systems against ongoing attacks exploiting a high-severity vulnerability in the Chrome web browser. 
May 22, 2025CVE-2025-4428Chinese hackers have been exploiting a remote code execution flaw in Ivanti Endpoint Manager Mobile (EPMM) to breach high-profile organisations worldwide. 
May 22, 2025CVE-2025-0994Chinese-speaking hackers have exploited a now-patched Trimble Cityworks zero-day to breach multiple local governing bodies across the United States.
May 22, 2025CVE-2025-34027, CVE-2025-34026, CVE-2025-34025Critical vulnerabilities in Versa Concerto that are still unpatched could allow remote attackers to bypass authentication and execute arbitrary code on affected systems. 

Concluding Remarks :

Ready to strengthen your defenses against the ever-evolving cyber threat landscape? Don’t leave your business vulnerable to the next wave of attacks.

At Synergy IT Solutions Group, we understand the unique challenges and escalating threats facing US businesses in this dynamic landscape. Our comprehensive cybersecurity services are specifically designed to empower your organization to not only prevent attacks but also to respond effectively and minimize disruption when the inevitable occurs. From developing robust and actionable Cyber Incident Response Plans and conducting realistic Cyber Tabletop Exercises tailored to US-specific threats and regulations, to providing continuous threat monitoring, vulnerability management, and expert guidance on building a resilient security posture, Synergy IT is your trusted partner in navigating the complexities of the modern cyber battlefield.

Don’t wait until your business becomes the next headline – contact Synergy IT Solutions Group today and let our US-based cybersecurity experts help you train like you’re next, ensuring your team is ready to execute, not freeze, when faced with the stark realities of a cyber crisis.

Source : https://www.cm-alliance.com/cybersecurity-blog/may-2025-biggest-cyber-attacks-ransomware-attacks-and-data-breache.

Contact : 

 

Synergy IT solutions Group 

 

US : 167 Madison Ave Ste 205 #415, New York, NY 10016 

 

Canada : 439 University Avenue, 5th Floor, Toronto, ON M5G 1Y8 

 

US :  +1(917) 688-2018 

Canada : +1(905) 502-5955 

 

Email  :  

info@synergyit.com 

sales@synergyit.com 

 

info@synergyit.ca 

sales@synergyit.ca 

 

Website : https://www.synergyit.ca/   ,  https://www.synergyit.com/ 

 

Comments

Popular posts from this blog

January 2025: Recent Cyber Attacks, Data Breaches, Ransomware Attacks

Major Cyber Attacks, Ransomware Attacks and Data Breaches of June 2025

Top Cybersecurity Consulting Companies in the United States