The TYREX Files – October 2025 Edition

Let’s dive into this month’s top cybersecurity news stories, share expert insights, and showcase some real-world examples of “USBs Gone Wild” β€” flashes of cybersecurity brilliance (or blunders).

Let’s keep those USBs clean!

Top Cybersecurity Stories/News

The cybersecurity highlights of the month.

1. The Era of AI-Generated Ransomware Has Arrived

Cybercriminals are now using generative AI to create more sophisticated and personalized ransomware. According to Anthropic’s threat intelligence team, this trend marks a major turning point in the cyber threat landscape. AI enables hackers to develop malware faster, automate reconnaissance phases, and create variants that are difficult to detect. While AI can also strengthen cybersecurity defenses, this technological arms race is fundamentally transforming the nature of ransomware attacks. Organizations must now prepare to face AI-generated threats that are more agile and adaptive than ever before. (Wired)

Our 2 Cents:

Ah, AI… We were promised it would revolutionize our lives, and here it is, revolutionizing cybercriminals’ lives instead! While everyone marvels at ChatGPT writing poetry, hackers are using it to mass-produce ransomware. The reality is that AI drastically lowers the barrier to entry: any script kiddie can now create sophisticated malware without being a coding genius. And the worst part? This AI vs. AI arms race is only just beginning. Bottom line: investing in “old school” but robust defenses like USB decontamination has never been more crucial, because even the most powerful AI can’t do anything against a device that was never allowed into the network in the first place!

2. Land Rover Cyberattack Shows How a Single Breach Can Halt Modern Manufacturing

Jaguar Land Rover recently suffered a massive cyberattack that forced the shutdown of its UK plants. According to Israeli cybersecurity experts, this was “no ordinary cyberattack” – it directly targeted production systems and the supply chain. The incident revealed how vulnerable modern manufacturing facilities are: a single breach can stop entire production lines, resulting in losses of millions of dollars per day. The attack required a phased and controlled restart of the plants, demonstrating the complexity of recovery after such intrusions. This event serves as a wake-up call for manufacturers worldwide about the critical interdependence between cybersecurity and industrial operations. (Jerusalem Post)

Our 2 Cents

What this article reveals is that many of these production lines were built in the 1980s… So, guess what’s the easiest way to infect them? 😏 USB drives! These OT systems don’t update via the cloud like your smartphone. Most of the time, technicians use USB devices to transfer software updates, configurations, or even diagnose equipment. A single compromised USB can infiltrate an entire production chain and bring it to its knees, exactly like what happened at JLR. And the worst part? These industrial systems are so sensitive that once infected, you can’t just “reboot” – you have to validate everything manually, system by system. That’s why prevention with USB decontamination stations isn’t an option, it’s an EXISTENTIAL NECESSITY for modern industry!

Related investigation

CYFIRMA’s detailed investigation reveals that the September 2025 JLR attack was preceded by earlier breaches, including a March 2025 incident where the HELLCAT ransomware group leaked 700 internal documents after compromising JLR’s network using stolen Jira credentials. A threat actor known as “Rey” posted the compromised data on dark forums, exposing development logs, source code, and employee information. Days later, another actor “APTS” claimed to have exploited Infostealer credentials dating back to 2021, leaking an additional 350 GB of sensitive data. A Telegram channel called “Scattered Lapsus$ Hunters” later claimed responsibility for the September attack, sharing screenshots of JLR’s internal IT systems. The investigation exposed internal domains like jlrint.com and hardcoded production systems at Solihull and Gaydon sites, highlighting potential weak points for lateral movement within JLR’s network. (CYFIRMA Investigation Report)

3. AI-Enabled Ransomware Attacks: CISOs’ Top Security Concern β€” With Good Reason

According to a new 2025 Security Priorities study, 38% of security leaders rank AI-enabled ransomware as their top concern. CrowdStrike’s 2025 State of Ransomware Survey reveals alarming trends: 78% of organizations experienced a ransomware attack within the past year, with attackers moving from intrusion to encryption in minutes rather than hours. The survey found that 82% of organizations believe generative AI makes phishing emails more challenging to identify, and 87% consider AI-generated social engineering tactics more convincing than traditional methods. Perhaps most concerning, 83% of paying victims were attacked again, and 93% had data stolen anyway. Phishing remains the most common attack vector at 45%, followed by vulnerability exploits at 40%. AI now touches every stage of the ransomware attack chain, from crafting convincing phishing campaigns to developing sophisticated malware, with ransomware-as-a-service providers increasingly leveraging AI-developed malware. (CSO Online)

Our 2 Cents:

This survey perfectly complements what we highlighted in our first story about AI-generated ransomware β€” we’re not just talking about theoretical threats anymore, we’re living them! The numbers are staggering: 78% of organizations hit, attackers moving from breach to encryption in MINUTES, and here’s the kicker β€” 83% of those who paid got hit AGAIN. It’s like paying a bully’s lunch money and expecting them to leave you alone! But here’s what really gets me: while everyone’s obsessing over AI-powered attacks coming through the network, they’re forgetting the oldest trick in the book β€” physical access via USB devices. You can have the most sophisticated AI-powered security system in the world, but if someone walks in with a compromised USB drive and plugs it into an OT system (like we saw with JLR), all that fancy AI detection becomes useless. The attack bypasses your entire digital defense perimeter! This is why layered security isn’t just a buzzword β€” it’s survival. Yes, invest in AI-powered detection, but for the love of cybersecurity, don’t forget to lock the physical door with USB decontamination!

4. LockBit Returns β€” and It Already Has Victims

Despite being disrupted during Operation Cronos in early 2024, the notorious LockBit ransomware group has resurfaced with a vengeance. Check Point Research identified a dozen organizations targeted in September 2025, with half infected by the newly released LockBit 5.0 variant (codenamed “ChuongDong”). The attacks span Western Europe, the Americas, and Asia, affecting Windows, Linux, and ESXi environments. LockBit 5.0 introduces multi-platform support, stronger evasion techniques, faster encryption routines, and randomized 16-character file extensions to evade detection. The group’s administrator, LockBitSupp, who evaded capture, announced the return on underground forums, calling for new affiliates to join by depositing roughly $500 in Bitcoin. The quick reappearance demonstrates that LockBit’s Ransomware-as-a-Service (RaaS) model has successfully reactivated its affiliate base, signaling that the group’s mature infrastructure and proven reputation among cybercriminals remain intact. (Check Point Blog)

Our 2 Cents

LockBit is back, and honestly, are we even surprised? You can take down their infrastructure, arrest some operators, but the core group just goes underground, regroups, and comes back stronger. It’s like playing whack-a-mole with a hydra! But here’s what really matters for our industry: LockBit’s success isn’t just about sophisticated network attacks β€” historically, LockBit affiliates have been known to use EVERY entry point available, including USB devices and removable media to gain initial access or move laterally within air-gapped networks. Remember, ransomware groups don’t care HOW they get in; they just want IN. While everyone’s focused on blocking network intrusions, these groups are perfectly happy to use an infected USB drive to bypass your entire digital perimeter β€” especially in OT environments where legacy systems can’t be easily patched. The return of LockBit 5.0 with its multi-platform support (Windows, Linux, ESXi) means they’re targeting EVERYTHING, including industrial systems that often rely on USB transfers for updates. Defense in depth isn’t optional anymore β€” it’s mandatory. And that depth MUST include physical device security!

GΓ©rard’s Top Cybersecurity Resources

To become a cybersecurity “informed” thought leader.

80% of Ransomware Attacks Now Use Artificial Intelligence – Groundbreaking research from MIT Sloan’s Cybersecurity program and Safe Security examined 2,800 ransomware attacks and discovered that 80% were powered by artificial intelligence. AI is being deployed to create malware, phishing campaigns, and deepfake-driven social engineering such as fake customer service calls. Large language models are generating code and phishing content, while AI enables password cracking and CAPTCHA bypass. The researchers emphasize that AI-powered cybersecurity tools alone won’t suffice, arguing for a comprehensive three-pillar defense approach: automated security hygiene (self-healing code, self-patching systems, zero-trust architecture), autonomous and deceptive defense systems (using machine learning for proactive threat identification), and augmented oversight with real-time data-driven insights for executives. The study highlights the fundamental cybersecurity challenge where attackers need only one entry point while defenders must protect all vulnerabilities. (MIT Sloan)

USBs Case Study: When Navigation Charts Become Trojan Horses

The Maritime USB Paradox

Here’s the reality: maritime infrastructure has experienced a 900% increase in cyberattacks since 2020, and USB devices are at the heart of this vulnerability. Why? Because unlike other industries, maritime operations can’t function without removable media.

A Day in the Life

A container ship docks at port. Within hours:

  • A harbor pilot boards with USB-loaded navigation charts
  • A technician updates engine firmware via USB diagnostic tools
  • Crew transfers data to air-gapped bridge systems
  • Maintenance personnel update propulsion software

Every single operation is essential. Every single USB is a potential attack vector. And here’s the kicker: vessels and port infrastructure can be compromised in seconds if infected removable media connects to critical systems.

Why Traditional Security Fails

USB devices connect directly to hardware, bypassing firewalls and intrusion detection systems. Endpoint detection often fails to identify USB threats in time. Your air-gapped bridge system? Not so safe when a compromised USB plugs directly into it.

The Real Threat

A sophisticated attacker doesn’t need to breach your network. They just:

  • Compromise a contractor’s USB drive
  • Wait for routine maintenance (happens constantly)
  • Infected USB connects to navigation or propulsion systems
  • Malware spreads to “secure” air-gapped systems
  • Attacker gains access to vessel controls, cargo data, or communications

Remember the JLR attack we discussed? Same playbook. But here, it’s not just a production line β€” it’s a moving vessel with crew, passengers, and potentially hazardous cargo.

The TYREX Maritime Solution

We designed our stations specifically for maritime realities:

  • TYREX SATELLITE β€” Wall-mounted, compact for bridge stations. Harbor pilot plugs in navigation charts, AI-powered engines detect firmware-level BadUSB attacks and zero-day exploits, charts transfer clean. Done.
  • TYREX MOBILE β€” MIL-STD-810G ruggedized portable unit for harsh maritime conditions. Engine room technician decontaminates firmware updates on-site before touching critical systems.
  • TYREX TOTEM β€” Kiosk at crew boarding areas. Creates a security checkpoint where every device gets sanitized before accessing the vessel. Large display shows safety protocols while decontaminating.

The Compliance Bonus

IMO Resolution MSC.428(98) requires shipping companies to address cyber risks from removable media. TYREX stations provide auditable evidence for Document of Compliance verification. You’re not just protecting vessels β€” you’re meeting regulations.

The Bottom Line

Maritime operations face a unique challenge: USB devices are mandatory, networks are often unavailable, and breaches can be catastrophic. You can’t ban USBs. Traditional security doesn’t work on air-gapped systems.

What you can do? Decontaminate every USB before it touches critical systems. TYREX stations operate fully air-gapped using existing threat definitions β€” perfect for vessels at sea.

Dive deeper: us.tyrex-cyber.com/usb-security/transportation/maritime

 

Sign up for the TYREX newsletter for expert analysis and guidance from TYREX USB security experts Gerard Varjacques and Christophe Bourel.