Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In a cybersecurity roundup published September 5, 2025, SecurityWeek described scammers using Grok to surface scam links, a long-running impersonation campaign against U.S. manufacturers, and Google’s denial of reports about a broad Gmail security warning. The stories also covered a Pentagon–Microsoft support arrangement, supplier-risk guidance from CISA, a Baltimore payment scam, and other reported incidents.
How scammers used Grok to surface scam links
According to Guardio researcher Nati Tal, scammers worked around X’s ban on links in promoted posts by placing a link in a post’s From field. They then asked Grok, “where is this video from?” Grok responded with a clickable link to the criminals’ website.
The technique depended on attacker-controlled post metadata: Grok’s answer turned that metadata into a route to the scam site. It is a reminder that an AI response can amplify misleading or malicious material when it treats social content as trustworthy context.
How the ZipLine campaign targeted U.S. manufacturers
SecurityWeek, summarizing Check Point reporting, said the ZipLine campaign used fake domains resembling legitimate companies to approach U.S. manufacturing firms. Rather than sending a single obvious lure, attackers exchanged business-like emails with victims for weeks, building apparent trust before delivering custom MixShell malware.
#1 Best Overall
That sequence matters: the impersonation and extended correspondence were part of the attack, not incidental setup. A familiar-looking company name or a plausible business conversation is not proof that a sender or domain is genuine.
What happened with Pentagon systems and Microsoft’s China-based support
Microsoft had used engineers in China to maintain U.S. Defense Department systems, with cleared “digital escorts” supervising their work. Microsoft said it would stop using China-based teams for Pentagon technical assistance because of the possibility of sensitive-data exposure. The Department of Defense then ended the arrangement and requested an audit of code submitted by the Chinese nationals.
The reported concern was supplier and personnel access to sensitive systems; the roundup did not describe this as a confirmed compromise. The requested code audit was a follow-up measure, not evidence by itself that malicious code had been found.
What the CISA supplier-risk tool asks organizations to assess
CISA announced a free Software Acquisition Guide: Supplier Response Web Tool for organizations assessing software suppliers. It covers four areas:
Rank #3
- Governance and attestation
- Software supply-chain practices
- Secure development and deployment
- Vulnerability management
For procurement and third-party-risk teams, these categories provide a practical structure for asking suppliers how they manage software risk. The announcement describes an assessment tool, not a guarantee that a supplier or product is secure.
What the Gmail security reports got wrong
Google said reports of a broad warning about a major Gmail security issue were false. It said Gmail protections block the vast majority of phishing and malware-delivery attempts aimed at its users. SecurityWeek’s account did not establish a new Gmail breach or vulnerability; it covered Google’s rebuttal to the warning reports.
Rank #4
Other incidents and reported impacts
| Organization or incident | Reported impact | Qualification |
|---|---|---|
| Vital Imaging | Roughly 260,000 people | Reported in a 2025 disclosure; the investigation was ongoing, according to the roundup. |
| City of Baltimore payment scam | Roughly $1.5 million sent to a scammer; more than $720,000 recovered | The roundup reported the city’s payments and recovery figures. |
| Qantas breach | More than 5 million customers affected | Impact was reported by the company. Executive compensation reductions totaled A$800,000. |
| Bridgestone Americas cyberattack | Some manufacturing plants were affected | At the time of the roundup, the company said its investigation had found no evidence that customer data was compromised. |
Why France fined Google €325 million
France’s data-protection authority, CNIL, fined Google €325 million in 2025 over consent violations involving Gmail advertisements and cookies placed when people created Google accounts. SecurityWeek quoted CNIL as saying the penalty concerned “displaying advertisements between Gmail users’ emails without their consent and for placing cookies when creating Google accounts, without valid consent of French users.”
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

