TL;DR: Supply chain compromise, blockchain-hosted malware, SIM swap fraud, and ransomware defined the week of 14 to 21 October 2025, with key statistics including 600,000+ exposed F5 BIG-IP devices, 1,600 Vocus customers affected, and 36% year-over-year ransomware growth, according to FireCompass. The pattern is clear: attackers are chaining identity abuse, infrastructure exposure, and operational disruption faster than conventional monitoring can respond.
NHIMG editorial — based on content published by FireCompass: Weekly Report: New Hacking Techniques and Critical CVEs 14 Oct - 21 Oct 2025
By the numbers:
- 1,600 customers compromised in Vocus breach
- 34 SIM swaps executed via email compromise
Questions worth separating out
Q: What breaks when email compromise can trigger SIM swap fraud?
A: Email compromise becomes a gateway to number porting, password recovery, and SMS-based second factor abuse.
Q: Why do standing recovery channels increase fraud risk?
A: Standing recovery channels create a permanent path around normal authentication controls.
Q: How should security teams detect exploitation of blockchain-based malware C2?
A: Teams should look for unusual JSON-RPC egress, process behaviour that correlates with blockchain queries, and command retrieval patterns that do not match legitimate application use.
Practitioner guidance
- Harden management-plane exposure Isolate internet-facing management interfaces for perimeter and infrastructure devices, and treat source-code or admin-plane exposure as an urgent containment event, not a routine patching task.
- Remove SMS from high-risk recovery paths Require hardware-backed or app-based factors for sensitive accounts, and redesign SIM change or number port approvals so that email compromise cannot unlock downstream authentication.
- Constrain script execution paths Apply PowerShell Constrained Language Mode, alert on Base64 decoding in terminal sessions, and block copy-paste execution prompts that simulate error remediation steps.
What's in the full article
FireCompass's full blog post covers the operational detail this post intentionally leaves for the source:
- The week-by-week incident breakdown with additional context on the F5, Vocus, and Askul cases
- Technical notes on EtherHiding, ClickFix, and LinkPro that are beyond this summary
- The source article's expanded dark web observations, including ransomware group activity and credential trading
- FireCompass's own practitioner commentary on how these patterns map to current offensive technique trends
👉 Read FireCompass's weekly report on new hacking techniques and critical CVEs →
AI in cybersecurity weekly report: what practitioners need to act on?
Explore further
Identity abuse is now an operational attack layer, not just a prelude to intrusion. The Vocus chain shows how email compromise can be turned into SIM swap fraud, then into recovery-channel abuse for other services. That means identity proofing, account recovery, and telecom change controls now sit inside the attack surface, not outside it. Practitioners should treat recovery workflows as security-critical assets.
A question worth separating out:
Q: How should organisations respond when a supplier has already been compromised?
A: Contain the identity path before focusing only on the breach narrative. Revoke exposed credentials, rotate shared secrets, disable dormant integrations, and inspect downstream systems that accepted the supplier's access. The immediate goal is to cut off reused trust, because the attacker usually wins by staying inside the delegated relationship.
👉 Read our full editorial: AI in cybersecurity weekly report shows breach chains and NHI risk