live
00:00

Threat Landscape Briefing – March 2025

In this month’s briefing we explore:

  • Hackers Exploit Cityworks RCE Bug to Breach Microsoft IIS Servers (00:56)
    • Threat actors are actively exploiting a high-severity deserialization flaw to remotely execute commands on Microsoft IIS servers.
    • See how Info-Tech can help with Threat Preparedness Using MITRE ATT&CK®.
  • When Ransom Notes Become Recruitment Tools (04:32)
  • Gcore DDoS Radar Reveals 56% Year-Over-Year Increase in DDoS Attacks (07:19)
  • Cryptocurrency Heist of the Century (10:05)
    • Bybit has requested assistance from top cybersecurity experts to recover 1.5 billion dollars of cryptocurrency stolen in a significant digital theft.
    • Check out our Assess and Manage Security Risks blueprint.
  • Code Injection Attack Caused by Disclosure of Machine Keys (13:28)
    • More than 3,000 publicly exposed ASP.NET machine keys have been identified by Microsoft, which could be compromised by threat actors in code injection attacks against enterprise servers.
    • Learn how your organization can Embed Security Into the DevOps Pipeline.

If you have a question or would like to receive these monthly briefings via email, submit a request here.

Featured Speakers

Michel Hebert

Practice Lead, Industry Research
Read Bio

Carlos Rivera

Principal Research Advisor, Security & Privacy
Read Bio

Ahmad Jowhar

Research Specialist, Security & Privacy
Read Bio

Fritz Jean-Louis

Principal Cybersecurity Advisor
Read Bio

Jonathan Nelson

Principal Advisory Director
Read Bio

Visit our IT Critical Response Resource Center
Over 100 analysts waiting to take your call right now: +1 (703) 340 1171