Top Tech Headlines – July 29, 2025
It's a big day in tech and cybersecurity. From large-scale cyberattacks and critical software flaws to the latest in AI-powered browsers and digital video creation, here's everything you need to know to stay safe, smart, and up to speed.
National Guard Mobilized After Cyberattack Cripples St. Paul, Minnesota
After a severe cyberattack brought down city systems in St. Paul last Friday, Minnesota Governor Tim Walz has activated the National Guard to assist in response and recovery efforts. The incident highlights the growing threat to municipal infrastructure, with public services and communications temporarily disrupted.
Russian Airline Aeroflot Grounds Flights Following Cyber Incident
A sophisticated cyberattack has disrupted Aeroflot, Russia’s flagship carrier, forcing over 60 flight cancellations. While operations are slowly resuming, the attack exposes ongoing vulnerabilities in critical transportation systems.
Hackers Exploit SAP NetWeaver Bug to Deploy New Linux Malware
Threat actors have exploited a zero-day vulnerability (CVE-2025-31324) in SAP NetWeaver to deploy Auto-Color malware targeting a chemical manufacturer. The affected environment highlights the continued risk posed by enterprise-grade software vulnerabilities—especially in industrial sectors.
Microsoft Edge Gets an AI Boost with Copilot Mode
Edge now includes “Copilot Mode,” an AI-powered feature aimed at transforming your browser into a smarter assistant. Currently experimental, the upgrade could make Microsoft Edge a more attractive option for users comfortable with AI-driven browsing support.
Telecom Giant Orange Discloses System Breach
French telecom leader Orange reported a cyberattack affecting systems across its network. They detected the breach last week and are currently assessing damages—highlighting ongoing challenges telecoms face in securing high-traffic infrastructure.
FBI Seizes $2.4M in Bitcoin Tied to New Chaos Ransomware Group
The FBI has confiscated nearly 23 Bitcoins from Chaos ransomware affiliates, who have targeted U.S. companies. The operation underscores growing efforts to financially disable cybercrime groups, even as ransomware-as-a-service (RaaS) re-emerges.
Phishing Attacks Bypass So-Called 'Phishing-Resistant' MFA
So much for ‘phishing-proof’. New research shows how hackers are bypassing advanced MFA protections using downgrade and OAuth manipulation attacks. Security tools like Push Security are helping block these evolving tricks.
Lovense App Bug Leaks Private Emails of Users
A serious flaw in the Lovense sex toy app exposes user email addresses with just their usernames, potentially enabling harassment and doxxing. A reminder: IoT privacy isn't just a tech issue—it's a human one, too.
Google Veo 3 Launches Publicly for Powerful AI Video Creation
Google has rolled out Veo 3, its most advanced AI video generation tool, to the public via Vertex AI. Creators can now generate polished videos with minimal input, marking a major step in AI-assisted content development.
AI Tools Up, Trust Down: Developers Question Reliability
Dev adoption of AI tooling continues to rise, but confidence in their accuracy is falling off a cliff, according to new surveys. The takeaway? Use AI to assist—not replace—your judgment as a developer.
China Dominates Cellular IoT Market with Massive Scale
A new report shows China is leading the global cellular IoT connectivity space, with domestic carriers and infrastructure outpacing Western counterparts. The shift has implications for device makers and network security analysts worldwide.
China Ramps Up City-Level Funding in Ongoing AI Race with U.S.
Shanghai has launched a $139 million initiative to boost domestic AI innovation, part of China's broader strategy to stay competitive with U.S. firms. City-based funding is accelerating the AI arms race, with geopolitical shifts at stake.
Why Your Wi-Fi Might Be the Smartest Sensor in the House
New smart home tech is leveraging Wi-Fi to detect motion and presence—without relying on cameras. The emerging potential of ambient sensing opens low-privacy-impact applications, from elderly care to home automation.
Google's AI Search Overviews Raise Visibility Concerns for Law & Finance Sites
AI-generated overviews in Google Search may reduce traffic to high-stakes websites like legal or financial services. SEO pros are rethinking strategies to remain visible and trusted as AI reshapes how users get information.
Intel Spinning Off Network and Edge Business
Intel will turn its Network and Edge Group into a standalone business, with plans to bring in outside investors. The move aims to sharpen strategic focus while unlocking value in edge computing technologies.
Critical Access Bypass Exploit Patched in Base44 Platform
Wiz researchers disclosed a flaw in Base44 that let hackers access private apps through public IDs. Wix has issued a quick fix, but it’s a timely reminder to segment app-level access permissions carefully.
Fake Verification Campaign Targets PyPI Developers
Phishing emails impersonating Python’s PyPI are making rounds, tricking developers into divulging credentials via lookalike domains. If you're publishing to PyPI, now’s a good time to double-check those emails.
Chaos Ransomware Emerges, Targets U.S. Firms Post-BlackSuit
With BlackSuit taken down, Chaos ransomware fills the void, hitting U.S. companies with fresh demands—some as high as $300,000. The group is known for stealthy entries and evasive malware tactics.
Browsers Emerge as Major Attack Surfaces in 2025
As SaaS adoption soars, browsers have become attackers’ go-to targets for credential theft and session hijacking. SSO and weak browser-based MFA setups are now prime hunting grounds for cybercriminals.
Fake Mobile Apps Target Users in Wide Malware Campaign Across Asia
Fake Android and iOS apps are harvesting data and extorting users across Asia’s mobile networks. Users are encouraged to download only from trusted marketplaces and be wary of permissions.
JavaScript Injection Still Lurking, Even with React
The recent Polyfill.io compromise shows modern frameworks like React haven’t eliminated cross-site scripting. Developers need new strategies and tools to defeat modern JavaScript-based attacks.
Critical PaperCut Flaw Added to CISA’s Known Exploited Vulnerabilities List
A CSRF vulnerability in PaperCut NG/MF has been actively exploited and added to CISA’s KEV catalog. Immediate patching is now required for federal systems, reinforcing the need for timely software maintenance.
Want to stay ready for anything? From data recovery to bootable OS installs, our Ultimate USBs have your back. Check out our tools today.
```