• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Support
Screen Connect
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Altec
        • Avalara
        • AvidXchange
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • Fortis
        • FreightPOP
        • Microsoft 365
        • Netstock
        • Ottimate
        • Sage Fixed Assets
        • Sage HRMS
        • Sage Intacct Payroll powered by ADP
        • Savant WMS
        • Scanco
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Bizinsight
        • Concur
        • Crystal Reports
        • Fraxion
        • Fusion RMS
        • FYISoft
        • JobOps
        • KnowledgeSync
        • Lockstep Collect
        • Nectari
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage Intelligence
        • Scissortail HCM
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Time & Billing Pro
        • Timekeeper
        • True Sky
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed Services
        • IT Support
        • Cloud Hosting
        • Infrastructure-as-a-Service
        • Managed Cloud Services
        • vCIO
        • Acumatica Infrastructure
      • IT Solutions
        • Backup & Continuity
        • Cybersecurity
        • Email Hosting
        • Microsoft 365 Services
        • Virtualization
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

May 2025 Cybersecurity News Recap

May 22, 2025 by Hector

Home » Cybersecurity » May 2025 Cybersecurity News Recap

Wooden letters spelling "MAY" above a black 2025 calendar page with decorative coral floral design on gray background

Cybersecurity news continues to emerge and develop at an alarming pace in 2025, with the month of May being no different. This recap of top stories from SWK Technologies covers several uncovered malware campaigns, including major ransomware attacks against healthcare and other critical infrastructure industries. The good news is that in spite of these rampant cyber incidents, there remains solutions available to help navigate the current security landscape, and many institutions and organizations are actively working to identify and combat these threats as they emerge.

Here are the top cybersecurity articles selected by SWK from May 2025:

Ransomware Takes Down Ohio Healthcare Network’s Systems for Days

Kettering Health, a nonprofit organization that manages over a dozen hospitals and other medical facilities, published a statement on Tuesday, May 20 that they were experiencing a “system-wide technology outage,” later confirmed to have originated from a cyber attack. The incident resulted from unauthorized access to their network, and brought down online patient portals and phones systems as well as forcing their medical centers to cancel or reschedule all elective procedures. It was also confirmed the same day that several scam calls claiming to be from Kettering were related to the attack, which additionally forced the nonprofit to cease all calls regarding payment to avoid confusing patients.

Though Kettering Health declined to provide a comment, CNN claims to have obtained a note indicating the outage resulted from a breach and ransomware infection carried out by the Interlock gang. This group has become notorious for several recent high-profile attacks, with a sizable portion of these targeting the healthcare industry. The immediate and potential fallout of the Kettering outage is a likely reflection of why – simply locking down some systems or data can have severe operational consequences, not even mentioning the physical effects for patients, and victims in this sector are always going to have a greater incentive to find a quick resolution that could include giving into the extortion.

Printers Spread Malware to Customer Networks

Procolored, a digital printing solutions provider based in China, was found to have offered software drivers for their printers that were infected with multiple malware strains. The widespread infections first came to light when a YouTuber that received a $6000 device from the company for review was alerted to the presence of viruses on the drivers by Windows Defender and Google Chrome’s antivirus tools, which he then brought to the attention of security researchers. This led to investigator discovering that the file sharing database Procolored used to host their file downloads contained evidence of multiple infections that went back at least 6 months.

Some of the malware identified came from known strains, but others were brand new versions that had never been caught in the wild by researchers previously. One in particular could modify executable files and allow itself to self-replicate within a network, which researchers suspect is what led to the widespread infection in the first place. Procolored has since removed all of the infected downloads from their website after initially denying their presence.

College Student Pleads Guilty to Cyber Extortion Attack

A student who had been studying at Assumption University in Worcester, MA has plead guilty to charges pertaining to hacking, stealing information from and extorting two U.S.-based organizations, including education software publisher, PowerSchool. Matthew Lane is accused of being part of a group that actively stole data of millions of students and teachers collected by PowerSchool and others, and later attempted to blackmail the solutions provider into paying a ransom on the threat of leaking the files. Lane is now facing multiple charges that include “…cyber extortion conspiracy; cyber extortion; unauthorized access to protected computers; and aggravated identity theft.”

Though one case of many, the relative swiftness at which Lane was charged does seem to reflect a pattern of renewed focus from law enforcement on cybercrime and a faster reaction time when culprits are identified. The federal government has already processed over 100 such cases in 2025, though by the FBI’s own statistics, these types of crimes have only continued to increase over the past year.

Hackers Exploit CVE Flaws in SAP NetWeaver

German software publisher SAP announced the discovery of a critical CVE bug present in their NetWeaver platform in April 2025, before uncovering another exploitable flaw a few weeks later in May. Both vulnerabilities affect Visual Composer Development Servers and potentially allow hackers to gain unauthorized backdoor access to the entire hosted environment, which can then enable entry into additional connected applications like Industrial Control Systems (ICS). Even while investigators had identified the first exploit and before the second was found, bad actors were already found taking advantage of the former and quickly picked up on the latter.

SAP has worked to release patches for both flaws as of this writing, but security researchers previously warned the public that thousands of servers were likely vulnerable to the exploit and several attacks had been confirmed before the systems were patched. If you own or have a system connected to SAP NetWeaver, SWK recommends ensuring your software is up to date with the latest security patches, and contacting your support partner or an MSSP (managed security services provider) ASAP.

Malware Campaigns Target Cloud Resources of Major Institutions

Various malware distribution campaigns have been identified by researchers targeting different victims over online channels, with perhaps of the largest of these going after multiple cloud hosting services. This latter campaign by the cybercriminal group Hazy Hawk aimed to exploit DNS (Domain Name System) misconfigurations in various inactive cloud environments – including some hosted by Cloudflare, GitHub and Akamai – to hijack domains of popular brands that could be used to spread malware to unsuspecting victims.

Exploiting misconfiguration is a common attack vector for more sophisticated hackers looking to break into cloud networks, though not an easy one by any means as most public clouds are frequently secured against this type of attack. However, flaws still appear every once in a while, such as with the SAP NetWeaver example earlier in this blog or the NetSuite SuiteCommerce incident from 2024.

Keep Up with the Latest Cybersecurity News

The stories featured in this recap are still only a fraction of the major cybersecurity news that popped up in May 2025, including additional ransomware campaigns targeting retailers, more hacks against public institutions and other malware traps on popular websites. The increasing pace of these incidents continues to shift the security landscape in new ways – but staying on top of the latest developments will help your business to prepare for emerging threats and adapt your cybersecurity posture to meet them.

Contact SWK here to discover how we can help you stay informed on the latest security trends and what measures your business must implement to guard against evolving cyber risks.

Category: Cybersecurity, Blog, News and Events

Sidebar

Recent Posts

  • May 2025 Cybersecurity News Recap
  • How Your ERP Software Impacts Tariff Costs
  • How a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth
  • Why Financial Services Firms Need Phishing Defense
  • Acumatica General Ledger Training – Key Tips & Tricks
  • Sage Intacct vs. Sage 500: Best ERP for CFOs and Financial Leaders
  • What is the Relationship Between Cybersecurity and Cyber Insurance? 

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Wooden letters spelling "MAY" above a black 2025 calendar page with decorative coral floral design on gray background

May 2025 Cybersecurity News Recap

Read moreMay 2025 Cybersecurity News Recap
Cargo ship "Tokyo Triumph" loaded with shipping containers in various colors, representing international trade and supply chains affected by tariffs impacting manufacturing operations.

How Your ERP Software Impacts Tariff Costs

Read moreHow Your ERP Software Impacts Tariff Costs
Recreational Play Structure

How a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth

Read moreHow a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2025 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.I understand