Weekly news threat forecast – Generalitat 24/11



Apart from its function, CATALONIA-CERT constantly monitors cybersecurity threats that affect the Agency's area of responsibility. In this sense, the evolution of these threats is compiled and analysed in accordance with the activity observed by the entire SOC/CERT in our territory. 

During this week, in the context of recent cyber threats:

  • The pro-Russian hacktivist group NoName057(16) intensifies DDoS attacks against institutions in Spain and Catalonia coinciding with Zelensky's visit, leaving several portals inaccessible.

  • CVE-2025-40601 allows remote DoS to be caused on SonicWall Gen7 and Gen8 firewalls via the SSLVPN module, rendering them inoperative if they are not up to date.

  • The "ballistic" attacker claims to have stolen internal documents and police data from a Spanish city council by exploiting a vulnerability from an external provider, despite having little credibility.



Below we list the5 main threats identified in the scope of the Generalitat, the forecast of their evolution and the news regarding these and other threats that we have analyzed during the last week. The objective is to share this vision so that the appropriate prevention, detection and protection measures can be taken to mitigate the most relevant threats in a prioritized way.

All the threats they carry are written ingarnet have been detected in the area or have been affected.



RELEVANT THREATS

  • ATTACKS ASSOCIATED WITH HACKTIVIST GROUPS



  • 24/11/2025 – Activity of the hacktivist group NoName057 against Spain and Catalonia following Zelensky's visit:Following the visit of the Ukrainian president to Spain to hold several meetings with the Spanish government, the pro-Russian hacktivist group NoName057, with more than two years of history, has intensified its activity against Spanish entities through DDoS attacks distributed through its DDoSia client. This group usually runs campaigns every 2-3 months, but activates new rounds when events that it considers relevant occur, such as in this case Zelensky's visit. The main targets of the attacks have been public institutions and companies linked to defence and mobility, both at the state and regional level.As a result, several web portals of these entities have been rendered inaccessible. The attacks are expected to continue throughout the Ukrainian president's visit. The SOC/CERT has contacted the affected entities to alert them, provide context about the threat and offer recommendations to mitigate the impact.



  • DENIAL-OF-SERVICE ATTACKS



  • 21/11/2025 – SonicWall vulnerability allows firewall saturation:At the end of November 2025, the CVE-2025-40601 vulnerability was identified in SonicOS, a memory overflow in the SSLVPN module that allows an unauthenticated attacker to cause a DoS and render Gen7 and Gen8 firewalls (both physical and virtual models) with versions older than those patched inoperative, affecting equipment such as the TZ, NSa, NSsp and NSv series, while Gen6 and some SMA are left out; While no active exploits have been detected, the flaw can disable perimeter protection and open a window of significant risk for any entity that relies on these devices.





  • BLACKHATS SEEK ACCESS TO SYSTEMS TO COMPROMISE INFORMATION



  • 20/11/2025 – Sale of data from a Spanish city council: An attacker who calls himself "ballistic" claims to have compromised systems linked to the Spanish City Council by taking advantage of a vulnerability in a third-party server used by the City Council. Through this access, according to the plaintiff's claims, he would have obtained internal documents from the city council and also access to a database with police information on citizens, although the latter, according to the plaintiff himself, had not yet been published openly. The incident is considered serious because it combines the leak of internal administrative documentation with unauthorized access to sensitive police data. However, the actor only has one post and joined the platform in the month of October 2025; For this reason, it does not have a recognized reputation and a solid assessment of the credibility of the publication or the veracity of the data cannot be made.



CATALONIA-CERT has compiled and provided indicators of commitment for intake in perimeter tools

We remain at your disposal in case you have any doubts or need support in this regard.







Content Blocks

Details

Comments

CERCA Ecosystem Information

CERCA Ecosystem Information

CERCA Communities
DEEPTECH Area