Cybersecurity Storm: Hacks, Ransomware and Crackdowns Rock the Globe (July 23–24, 2025)
Storm-2603, a China-linked cyber-espionage group, exploited a zero-day in Microsoft SharePoint Server (Toolshell) and by July 23 had breached at least 400 organizations, including DHS, DOE’s NNSA, the Department of Education, and NIH, with some hacked servers later seeded with LockBit and Warlock ransomware. The FBI, CISA, HHS, and MS-ISAC issued a joint alert about Interlock ransomware, first seen in late 2024, using drive-by downloads from compromised sites and a ‘ClickFix’ social-engineering tactic to exfiltrate data and then encrypt, often directing victims to a Tor-based ransom site. The United Kingdom on July 23 proposed a ban on ransomware payments by