Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Hikvision Releases 2026 Cybersecurity White Paper, Fostering Digital T...
North Korea-linked phishing campaign targets developers through malici...
Zero-day exploit disclosed hours after massive Patch Tuesday release
Bringing cybercriminals to justice in APAC
Cyber resilience – a national security imperative
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Bringing cybercriminals to justice in APAC

      Bringing cybercriminals to justice in APAC

      Thursday, June 11, 2026, 10:30 AM Asia/Singapore | Features
    • Featured

      Cyber resilience – a national security imperative

      Cyber resilience – a national security imperative

      Wednesday, June 10, 2026, 3:09 PM Asia/Singapore | Features
    • Featured

      Asia Pacific’s unique cyberthreats

      Asia Pacific’s unique cyberthreats

      Monday, June 8, 2026, 5:04 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

Malware & RansomwareNews

Worried about rising ransomware threats? Patch actively exploited vulnerabilities fast

By CybersecAsia editors | Thursday, March 20, 2025, 9:29 AM Asia/Singapore

Worried about rising ransomware threats? Patch actively exploited vulnerabilities fast

Proactive threat hunting and fast response to accurately detected suspicious lateral movements of attackers should also be de facto: threat report

Based on information from openly available sources*, a cybersecurity firm has found that February 2025 had 962 cases of ransomware attacks analyzed — a 126% increase of claimed victims year-over-year compared to the same month’s figures analyzed by the same firm in 2024.

Of the 962 cases analyzed, 335 were claimed by the Clop (Cl0p) group: a 300% jump compared to data sources analyzed from January 2025.

It has been asserted that Clop (and other ransomware groups) have shifted tactics to focus on opportunistic attacks using newly discovered software vulnerabilities in edge network devices rather than on specific firms or industries. The idea is that “cybercriminals, regardless of whether they are financially motivated or state-affiliated, focus on finding vulnerabilities that meet certain criteria”:

  • The vulnerabilities have high-risk CVSS scores (>7.0)
  • The vulnerabilities allow attackers to remotely take control of a system
  • The vulnerabilities affect software that is accessible from the Internet
  • An exploit developer or malicious actor has already published the proof of concept for the exploitation process

Based on the above hypotheses, “less than 24 hours following the vulnerability’s public disclosure, threat actors launch automated scanners that scour the internet and establish remote access to vulnerable systems. After this initial access blitz, threat actors begin the second stage of the attack – the manual hacking of victims. This second stage takes time. Attackers need to figure out which systems are worth their effort, and then they have to manually hack their way deeper, typically using Living Off the Land techniques to evade detection. This delay means the actual ransomware attack or data theft typically happens weeks or even months after threat actors gain initial access.”

The really practical findings by Bitdefender, the firm that released its monthly threat debrief for February 2025, are that organizations should strengthen three defenses against ransomware risks in general: prioritizing patching of actively exploited vulnerabilities; proactive threat hunting for hidden threats and backdoors; and combining EDR/XDR with SOC/MDR.

*Specified as “things like news reports and research – with data gathered by analyzing Data Leak Portals” where claims cannot be independently verified

Share:

PreviousNew ransomware group exploits firewall vulnerabilities: Is your affected firewall patched?
NextMindsprint Appoints Suresh Sundararajan as Chief Executive Officer

Related Posts

Who needs Halloween when cybercriminals go Trick-or-Treating all year round?

Who needs Halloween when cybercriminals go Trick-or-Treating all year round?

Wednesday, November 2, 2022

Mobile malware is playing ‘hide and steal’: threat report

Mobile malware is playing ‘hide and steal’: threat report

Friday, March 6, 2020

The growing dangers of money mule accounts in APAC

The growing dangers of money mule accounts in APAC

Monday, February 8, 2021

Cybersecurity budgets in APJ rising since 2019, but look what happened

Cybersecurity budgets in APJ rising since 2019, but look what happened

Thursday, September 22, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Hikvision Releases 2026 Cybersecurity White Paper, Fostering Digital Trust in the AIoT Era

    Friday, June 12, 2026
    HANGZHOU, China, June 12, 2026 …Read More »
  • Cohesity Gains Access to Anthropic’s Claude Mythos Preview Through Project Glasswing

    Tuesday, June 9, 2026
    Strengthening the Cohesity Data Cloud …Read More »
  • Cohesity Gains Access to Anthropic’s Claude Mythos Preview Through Project Glasswing

    Tuesday, June 9, 2026
    Strengthening the Cohesity Data Cloud …Read More »
  • Uhale Adopts Quokka’s Q-mast to Strengthen Application Security Testing

    Tuesday, June 9, 2026
    Integration of automated security testing …Read More »
  • Uhale Adopts Quokka’s Q-mast to Strengthen Application Security Testing

    Tuesday, June 9, 2026
    Integration of automated security testing …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.