Expert Insights Cybersecurity Industry News Recap: 23 – 30 January

Last updated on Jun 6, 2025 1 Minute To Read
Joel Witts Written by Joel Witts
Laura Iannini Technical Review by Laura Iannini
Expert Insights Cybersecurity Industry News Recap: 23 – 30 January

📰 Headlines

  • DeepSeek, the Chinese startup AI company making global headlines this week, was forced to temporarily limit signups due to ‘large-scale cyber-malicious attacks’ on Monday. US tech stocks tumbled after reports of DeepSeek’s advanced capabilities and low spending. (Axios)

  • International law enforcement agencies have seized domains for several infamous hacking forums including ‘Cracked’ and ‘Nulled,’ which are ‘widely regarded’ as hubs for cybercriminal activity. (BleepingComputer)

  • A GenAI tool called ‘GhostGPT’ is being offered to cybercriminals to help generate malicious code and phishing emails. (Abnormal)

  • UnitedHealth confirms 190 million Americans were affected by the Change Healthcare data breach last year, making it the largest breach of medical data in US history. (TechCrunch)

🎣 Vulnerabilities, Scams, & Hacks

  • Telecommunications firm TalkTalk has confirmed it has fallen victim to a data breach involving a third-party platform. The incident was revealed after a threat actor wrote on a hacking forum that they were offering the sale of information of 18.8 million TalkTalk customers. (SecurityWeek)

  • Nearly 1,000 fake Reddit and WeTransfer pages are being used to spread Lumma Stealer malware, according to Sekoia.io threat research. (SCWorld)

  • A Texas county serving 37,000 residents has issued a declaration of disaster after a cybersecurity breach “involving a virus that has affected several internal systems.” (TheRecord)

  • A threat actor is targeting German & Polish speaking users via phishing emails carrying malicious attachments including a previously undocumented .NET backdoor that leverages the Tor network to evade detection. (HelpNetSecurity)

  • Zimperium has tracked a phishing campaign impersonating the United States Postal Services, exclusively targeting mobile devices, using PDFs to hide malicious links designed to steal credentials & data. (Zimperium)

🚨 Vendor News & Announcements

  • NinjaOne intends to acquire cloud-data backup provider Dropsuite for approximately $252 million USD. NinjaOne CEO Sal Sferlazza said: “Dropsuite will help our customers be more successful by extending data protection from the endpoint to SaaS applications, automating and simplifying backup, and filling critical data protection gaps.” (NinjaOne)

  • Exposure Management leader Tenable has signed an agreement to acquire Vulcan Cyber for approximately $137 million USD. Vulcan Cyber’s capabilities will augment Tenable’s exposure management platform. (Tenable)

  • Email security vendor Barracuda has announced new email security capabilities aimed at protecting against account takeover attacks. (CRN)

  • JumpCloud has acquired Stack Identity, a next-gen identity and access management solution. The acquisition will deepen JumpCloud’s existing capabilities in the identity security space. (JumpCloud)

📟 Product Releases & Patches

  • Phishing attack alerts are being added to Microsoft Teams for all customers by mid-February. (BleepingComputer)

  • Microsoft is previewing a “scareware blocker” feature named Defender SmartScreen for Edge web browsers which uses machine learning to prevent tech support scams. (BleepingComputer)

  • Google has announced a new ‘Identity Check’ feature for Android that locks sensitive settings behind biometric authentication when outside trusted locations. (BleepingComputer)

  • Apple has released security updates to fix a zero-day vulnerability (CVE-2025-24085) tagged as actively exploited in attacks targeting iPhones. (BleepingComputer)

🏛️ Policy, Law, & Legislation

  • The EU has sanctioned three Russian nationals for allegedly carrying out “malicious cyber activities” against Estonia. (THN)

  • The US department of Health and Human Services (HHS) has launched a consultation on enhancing cybersecurity measures for health data covered by HIPAA. (CSO)

  • The DoJ has indicted 5 people for running a ‘laptop farm’ used in a North Korean IT worker scam that affected at least 64 companies. (TheRecord)
  • Over 30 industry groups are calling for Congress to enact federal data privacy legislation that will override the current system of state defined data privacy legislation. (TheRecord)

🎙️ Expert Insights: Latest From Us

Don’t miss this week’s round of interviews & insights with cybersecurity experts and thought leaders.

That’s all for this week! 👋

Do you have any stories to share with Expert Insights, or any feedback on the format of this newsletter? Please let us know.

Contact [email protected]

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.

Technical Review Technical Review
Laura Iannini
Laura Iannini Cybersecurity Analyst

Laura Iannini is a Cybersecurity Analyst at Expert Insights. With deep cybersecurity knowledge and strong research skills, she leads Expert Insights’ product testing team, conducting thorough tests of product features and in-depth industry analysis to ensure that Expert Insights’ product reviews are definitive and insightful.

Laura also carries out wider analysis of vendor landscapes and industry trends to inform Expert Insights’ enterprise cybersecurity buyers’ guides, covering topics such as security awareness training, cloud backup and recovery, email security, and network monitoring. Prior to working at Expert Insights, Laura worked as a Senior Information Security Engineer at Constant Edge, where she tested cybersecurity solutions, carried out product demos, and provided high-quality ongoing technical support.

Laura holds a Bachelor’s degree in Cybersecurity from the University of West Florida.