The National Cyber Security Directorate strengthened its role as competent authority at national level in the national civilian cyberspace in 2024, with a constant focus on managing cybersecurity risks and incidents.
The work of the DNSC was carried out in cooperation with public institutions, the private sector, the academic sector and institutional partners, supporting efforts to strengthen cyber resilience at national level.
Study on the regulation of social media platforms
Social media platforms are no longer just communication channels – they influence how we inform ourselves, form our opinions and react to events. From distributing deceptive content to coordinated influence campaigns, these platforms can impact public discourse, trust in institutions, and information security. This document explores how these platforms can be regulated to limit abuses without restricting freedom of expression. The European regulations (Digital Services Act, Code of Practice), how Romania applies them and what shortcomings exist are presented.
Trends in academic publications on cybersecurity in the energy sector
This report analyses academic publications (2020-2025) on cybersecurity in the energy sector, which is essential in light of digitalisation and the risks associated with critical infrastructure. The aim is to identify trends and provide strategic recommendations.
The analysis covers 423 articles from the academic database for Scopus publications (ian. 2020 – Apr. 2025) using bibliometric tools and search terms aligned with the definition and taxonomy specific to the sectors of interest within NIS2 and GEO 155/2024.
Critical cybersecurity vulnerability identified in Microsoft Sharepoint
CVE-2025-53770 is a critical RCE vulnerability (CVSS 9.8) affecting Microsoft SharePoint Server (2016, 2019, Subscription Edition). It can be operated without authentication via __VIEWSTATE, allowing code execution, cryptographic key theft and web shell installation. The operation persists even after the update if the MachineKey keys are not regenerated. Patches are available for 2019 and Subscription Edition. It is recommended to activate AMSI, Microsoft Defender, isolate outdated servers and monitor suspicious traffic and files.
Travel agencies on the Dark Web: a new risk for users and brands
Criminal groups illegally sell airline tickets and hotel reservations obtained with stolen cards, loyalty points or compromised credentials. The phenomenon affects not only consumers but also SMEs, self-organising employees and legitimate platforms at risk of brand abuse and loss of trust. Furthermore, the use of false identities and counterfeit documents in the booking process complicates investigative efforts and increases the risk of cross-border fraud.
Major cybercrime network dismantled following international investigation
Europol has announced the arrest of administrator XSS.is, a Russian-speaking forum active for more than 12 years, used for the sale of stolen data, hacking tools and illegal services. The operation, coordinated by the French police in collaboration with Ukrainian authorities and Europol, took place in Kiev on 22 July 2025 and included the takeover of the public domain of the platform. With over 50,000 registered users, XSS.is has been one of the most important hubs of cyber criminal networks in the last decade.
New Coyote malware exploits Windows functionality to steal bank data
Akamai researchers have identified a new variant of the Coyote banking trojan, the first known malware to misuse Windows’ UI Automation (UIA) accessibility framework to extract sensitive information. This variant targets users in Brazil and is configured to collect credentials associated with over 75 financial institutions and crypto exchange platforms.
UI Automation is an integral part of the .NET Framework and is originally intended to support assistive technologies for people with disabilities, such as screen readers. Its exploitation by Coyote raises new alarm signals on how legitimate functionalities can be diverted for malicious purposes.
Cyber Attack on U.S. Nuclear Weapons Agency Through SharePoint Vulnerabilities
The National Nuclear Security Administration (NNSA) networks, part of the U.S. Department of Energy, have been compromised by unknown cyber actors by exploiting a chain of recently patched vulnerabilities in Microsoft SharePoint. The NNSA manages the United States’ nuclear arsenal and is instrumental in responding to nuclear and radiological emergencies, both domestically and internationally. A spokesperson for the Department of Energy confirmed the incident and the unauthorized access detected last week.
CISA warns: Critical vulnerabilities in SysAid actively exploited by hackers
The Cybersecurity and Infrastructure Agency (CISA) has issued a warning about the active exploitation of two XML External Entity (XXE) vulnerabilities in the SysAid ITSM platform, which may allow attackers to take control of administrator accounts.
The vulnerabilities, identified as CVE-2025-2775 and CVE-2025-2776, were reported at the end of 2024 by researchers at watchTowr Labs and corrected in March by SysAid On-Prem version 24.4.60. Shortly after the patch was published, researchers also published a demo code showing how easily these breaches can be exploited to access local files that may contain sensitive information.
Lumma malware is back in business after large-scale government operation
After an international action in May resulted in the seizure of more than 2,300 domains and essential components of its infrastructure, the Lumma malware-as-a-service operation is gradually starting to return to activity.
Although the network was significantly affected, the authors did not permanently stop the work. On XSS forums, they confirmed the incident, claiming that the main server was not captured, although it was remotely deleted, and the restoration process was already underway in early June. The re-emergence of this infostealer underscores the ability of cyber groups to quickly reconfigure and maintain operationality despite coordinated actions by the authorities.
Hackers begin exploiting critical vulnerabilities in Cisco ISE
Cisco has confirmed that cyber actors have begun trying to exploit recently discovered critical vulnerabilities in the Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which enable remote code execution without authentication.
Vulnerabilities can be exploited by sending modified API requests or uploading manipulated files, giving attackers the ability to run arbitrary commands with root privileges. Operation began less than a month after the release of the security patches, underlining the importance of immediately updating the affected systems.
Deepfake in everyday life: what do you need to know?
Deepfakes are audio and video content generated with the help of artificial intelligence, designed to mimic as faithfully as possible the voice, mimicry or appearance of a real person. These materials can be used for entertainment, but also for dangerous purposes, such as manipulating public opinion, spreading disinformation or committing fraud. Recognising specific signs – such as unnatural facial movements, eye asymmetry or distorted backgrounds – becomes essential for maintaining safety in the digital environment. It is recommended that users be vigilant, check the source of the material, do not share suspicious content without confirmation, use dedicated detection tools and report any suspicious material to the competent authorities.
Source: https://www.dnsc.ro/citeste/stirile-din-cybersecurity-17-07-2025
Discover more from #News247WorldPress
Subscribe to get the latest posts sent to your email.

