XStore Documentation

May 22, 2025 – Cyber Briefing

👉 What’s going on in the cyber world today?

Function confusion threatens serverless clouds, 3AM ransomware uses vishing and email bombs, and GitLab patches critical DoS and SAML flaws. Santa Fe loses $324K to fraud, ransomware disrupts Belgian housing, and a cyberattack paralyzes France’s Hauts-de-Seine. Global crackdown hits Lumma stealer, India fast-tracks cybercrime FIRs, and the EU sanctions Russia over hybrid cyber threats.

Listen to the full podcast


🚨 Cyber Alerts

1. Function Confusion Hits Serverless Clouds

A new vulnerability dubbed “function confusion” lets attackers exploit serverless cloud services like Google Cloud. By manipulating package installation scripts they execute malicious commands to gather sensitive system data. Cisco Talos found this affects major providers including AWS and Azure proving a widespread weakness. Firms must enhance package monitoring and scrutinize dependencies to counter this serverless threat.

2. 3AM Ransomware Email Bomb and Vishing Threat

A 3AM ransomware affiliate targets firms using email bombing and spoofed IT support voice phishing. Attackers trick employees into granting remote access via Quick Assist to deploy backdoors like QDoor. They used QEMU for evasion and exfiltrated 868GB of data though Sophos blocked the ransomware encryptor. This group linked to Conti and Royal highlights needs for better defenses and employee awareness.

3. GitLab Patch Stops Service Disruption Risks

GitLab issued critical security patches for eleven vulnerabilities across its platforms including denial of service flaws. The most severe flaw CVE-2025–0993 allows server resource exhaustion while others target Kubernetes. This update also addresses authentication bypass like a SAML weakness and CI/CD variable exposure. GitLab mandates immediate upgrades and security reviews emphasizing continuous vulnerability management.

For more alerts, click here!

💥 Cyber Incidents

For more incidents, click here!

Click to See Tools

📢 Cyber News

For more news, click here

📈Cyber Stocks

On May 21, 2025, Zscaler fell 1.28%, CrowdStrike Holdings dropped 1.70%, while Palo Alto Networks, Fortinet, and SentinelOne declined 6.80%, 1.86%, and 3.43% respectively.

💡 Cyber Tip

📚 Cyber Book

Click to Check Events

Copyright © 2025 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

SubstackLinkedInTwitterRedditInstagramFacebookYouTube, and Medium.

Get Help

Online Scam Prevention & Recovery

Schedule a free consultation

A free 15-min cybersecurity consultation