Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Report: more than half of APAC organizations experienced AI-related in...
Democratization of celebrity deepfake scams hits major social platform...
Taoping Reports Fiscal Year 2025 Results
Fake CAPTCHAs observed sending dozens of IRSF texts since 2020: case s...
Recent breach exposes supply chain risks via OAuth and secrets misclas...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      How AI is supercharging insider threats

      How AI is supercharging insider threats

      Wednesday, April 15, 2026, 12:29 PM Asia/Singapore | Features
    • Featured

      Q-Day is coming. Are you ready?

      Q-Day is coming. Are you ready?

      Tuesday, April 14, 2026, 12:40 PM Asia/Singapore | Features
    • Featured

      How lean defence teams turn endpoint insights into measurable risk reduction

      How lean defence teams turn endpoint insights into measurable risk reduction

      Monday, April 13, 2026, 3:15 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • Awards 2026
  • Directory
  • E-Learning

Select Page

Malware & RansomwareNews

Worried about rising ransomware threats? Patch actively exploited vulnerabilities fast

By CybersecAsia editors | Thursday, March 20, 2025, 9:29 AM Asia/Singapore

Worried about rising ransomware threats? Patch actively exploited vulnerabilities fast

Proactive threat hunting and fast response to accurately detected suspicious lateral movements of attackers should also be de facto: threat report

Based on information from openly available sources*, a cybersecurity firm has found that February 2025 had 962 cases of ransomware attacks analyzed — a 126% increase of claimed victims year-over-year compared to the same month’s figures analyzed by the same firm in 2024.

Of the 962 cases analyzed, 335 were claimed by the Clop (Cl0p) group: a 300% jump compared to data sources analyzed from January 2025.

It has been asserted that Clop (and other ransomware groups) have shifted tactics to focus on opportunistic attacks using newly discovered software vulnerabilities in edge network devices rather than on specific firms or industries. The idea is that “cybercriminals, regardless of whether they are financially motivated or state-affiliated, focus on finding vulnerabilities that meet certain criteria”:

  • The vulnerabilities have high-risk CVSS scores (>7.0)
  • The vulnerabilities allow attackers to remotely take control of a system
  • The vulnerabilities affect software that is accessible from the Internet
  • An exploit developer or malicious actor has already published the proof of concept for the exploitation process

Based on the above hypotheses, “less than 24 hours following the vulnerability’s public disclosure, threat actors launch automated scanners that scour the internet and establish remote access to vulnerable systems. After this initial access blitz, threat actors begin the second stage of the attack – the manual hacking of victims. This second stage takes time. Attackers need to figure out which systems are worth their effort, and then they have to manually hack their way deeper, typically using Living Off the Land techniques to evade detection. This delay means the actual ransomware attack or data theft typically happens weeks or even months after threat actors gain initial access.”

The really practical findings by Bitdefender, the firm that released its monthly threat debrief for February 2025, are that organizations should strengthen three defenses against ransomware risks in general: prioritizing patching of actively exploited vulnerabilities; proactive threat hunting for hidden threats and backdoors; and combining EDR/XDR with SOC/MDR.

*Specified as “things like news reports and research – with data gathered by analyzing Data Leak Portals” where claims cannot be independently verified

Share:

PreviousNew ransomware group exploits firewall vulnerabilities: Is your affected firewall patched?
NextMindsprint Appoints Suresh Sundararajan as Chief Executive Officer

Related Posts

Can your anti-phishing software detect these new URLO obfuscation techniques?

Can your anti-phishing software detect these new URLO obfuscation techniques?

Friday, September 12, 2025

Dealing with data security in the age of quantum supremacy

Dealing with data security in the age of quantum supremacy

Friday, March 20, 2020

No middle ground for DevOps adoption in government

No middle ground for DevOps adoption in government

Tuesday, June 16, 2020

Former-employee data breach exposes nearly 700,000 loan customers’ information

Former-employee data breach exposes nearly 700,000 loan customers’ information

Wednesday, September 17, 2025

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more
  • What AI worries keep members of the Association of Certified Fraud Examiners sleepless?

    What AI worries keep members of the Association of Certified Fraud Examiners sleepless?

    This case study examines how many anti-fraud professionals reported feeling underprepared to counter rising AI-driven …Read more

Bottom sidebar

Other News

  • Taoping Reports Fiscal Year 2025 Results

    Thursday, April 30, 2026
    Strategic Transformation Drives Platform Expansion, …Read More »
  • DESILO Launches World’s First Fully Homomorphic Encryption Library Integrating 5th-Generation FHE Scheme ‘GL’, Accelerating the Era of Private AI

    Tuesday, April 28, 2026
    SEOUL, South Korea, April 28, …Read More »
  • Tencent Cloud Cube Sandbox Goes Fully Open-Source, with Five Major Breakthroughs Enabling Large-Scale Agent Deployment

    Thursday, April 23, 2026
    Tencent Cloud’s Cube Sandbox goes …Read More »
  • Sparrow to Demonstrate AI-Driven Security and SBOM Management at Black Hat Asia 2026

    Wednesday, April 22, 2026
    SINGAPORE, April 21, 2026 /PRNewswire/ …Read More »
  • Relativity to Establish Singapore Entity, Expanding APAC Footprint

    Wednesday, April 22, 2026
    News Summary:  Relativity plans to …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.