Expert Insights Cybersecurity Industry News Recap: 9 – 16 January 2025

Last updated on Jun 6, 2025 1 Minute To Read
Joel Witts Written by Joel Witts
Laura Iannini Technical Review by Laura Iannini
Expert Insights Cybersecurity Industry News Recap: 9 – 16 January 2025

📰 Headlines

  • The FBI and the DoJ have removed China-linked PlugX malware from more than 4,200 US computers. (The Record)
  • Microsoft’s Digital Crimes Unit (DCU) has announced it is taking legal action to disrupt cybercriminals targeting it’s AI services. (Microsoft)
  • A malware campaign has compromised over 5,000 WordPress sites, adding rogue admins, installing malicious plugins and stealing data. (Bleeping Computer)
  • Researchers have uncovered a new malvertising campaign targeting Google Ads advertisers by attempting to phish credentials via fraudulent Google Ads. (THN)

🎣 Vulnerabilities, Bugs, & Hacks

  • CISA has warned agencies to patch a BeyondTrust command injection vulnerability (CVE-2024-12686) being actively exploited in attacks. (BleepingComputer)
  • Apple has recently patched a macOS vulnerability that allowed hackers to install malicious kernel drivers. (BleepingComputer)
  • Arctic Wolf researchers have observed a recent campaign targeting publicly exposed management interfaces on Fortinet FortiGate Firewalls. (ArcticWolf)
  • A weakness in Google’s OAuth login feature could enable attacks that register ‘abandoned’ domains access to former employee accounts linked to SaaS platforms. (BleepingCompter)
  • Cybercriminals are adopting new social-engineering methods to circumvent iMessage’s built-in phishing link protection feature. (BleepingComputer)

🏛️ Policy & Legislation

  • President Biden has issued a new executive order governing AI use for cyber defense and aiming to tighten cyber regulations for federal agencies. (Politico)
  • CISA has reported a ‘surge’ in enrolment to its Cyber Hygiene service from critical infrastructure organizations over the last two years. (Cyberscoop)
  • The UK Government is considering implementing new legislation for a ban on ransomware payments by the public sector and by operators of critical national infrastructure. (SecurityWeek)
  • The European General Court has fined the European Commission (the executive arm of the EU) for violating EU data privacy laws. (THN)

🚨 Vendor News & Announcements

  • Darktrace will acquire cloud threat hunting platform Cado Security. Darktrace was acquired by Thoma Bravo for $5.3 billion in October. (CRN)
  • Security awareness provider Hook Security has acquired Haekka, a Slack-based security training platform. (Hook Security)

📟 Product Releases & Patches

  • Microsoft’s January ‘Patch Tuesday’ included security updates for 159 flaws, including 8 zero-day vulnerabilities. (BleepingComputer)
  • Ivanti recently released patches for its Connect Secure VPN appliances to fix a zero-day threat allowing remote attacks to execute arbitrary code. (SecurityWeek)
  • Adobe has rolled out patches for multiple vulnerabilities affecting Photoshop, Substance 3D Stager, Illustrator for iPad, Adobe Animate, and the Adobe Substance 3D Designer. (SecurityWeek)

🎙️ Expert Insights: Interviews

Don’t miss this week’s round of interviews & roundups with cybersecurity experts and thought leaders.

That’s all for this week! 👋

If you have any feedback or stories to share, get in touch with [email protected].

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.

Technical Review Technical Review
Laura Iannini
Laura Iannini Cybersecurity Analyst

Laura Iannini is a Cybersecurity Analyst at Expert Insights. With deep cybersecurity knowledge and strong research skills, she leads Expert Insights’ product testing team, conducting thorough tests of product features and in-depth industry analysis to ensure that Expert Insights’ product reviews are definitive and insightful.

Laura also carries out wider analysis of vendor landscapes and industry trends to inform Expert Insights’ enterprise cybersecurity buyers’ guides, covering topics such as security awareness training, cloud backup and recovery, email security, and network monitoring. Prior to working at Expert Insights, Laura worked as a Senior Information Security Engineer at Constant Edge, where she tested cybersecurity solutions, carried out product demos, and provided high-quality ongoing technical support.

Laura holds a Bachelor’s degree in Cybersecurity from the University of West Florida.