THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### DragonForce Ransomware: Redefining Hybrid Extortion in 2025 A new ransomware group, DragonForce, is making waves with its hybrid extortion tactics. Emerging from hacktivist roots, this group exhibits an ideologically ambiguous approach, blending technological agility with opportunistic methods. It marks a significant shift in ransomware dynamics, challenging traditional boundaries and targeting a wide range of sectors. Learn more about DragonForce's evolution and their potential impact. [Read more](https://blog.checkpoint.com/security/dragonforce-ransomware-redefining-hybrid-extortion-in-2025/). ### Critical Vulnerabilities in Samsung MagicINFO and Langflow Under Attack Two significant vulnerabilities are currently under active exploitation. A vulnerability in Samsung's MagicINFO digital display management software is being leveraged to deploy Mirai bot malware. Additionally, Langflow, an AI tool, suffers from a remote code execution flaw that poses a serious threat to organizations using the tool. Immediate patching is advised to prevent potential breaches. [Samsung MagicINFO Exploit](https://www.helpnetsecurity.com/2025/05/06/exploited-vulnerability-software-managing-samsung-digital-displays-cve-2024-7399/), [Langflow Exploit Details](https://securityaffairs.com/177481/hacking/u-s-cisa-adds-langflow-flaw-to-its-known-exploited-vulnerabilities-catalog). ### Android Vulnerabilities and Zero-Day Exploitations Google has released patches addressing 47 Android vulnerabilities, including a significant zero-day that has been actively exploited. Users are urged to update immediately to secure their devices against these threats. These vulnerabilities highlight the urgent need for continuous security updates. [Full details on the update](https://www.malwarebytes.com/blog/news/2025/05/android-fixes-47-vulnerabilities-including-one-zero-day-update-as-soon-as-you-can). ### NSO Group to Pay WhatsApp $168 Million Over Pegasus Hacks A jury has ordered the controversial NSO Group to compensate WhatsApp $168 million for spyware infections caused by its Pegasus software. This landmark case underscores the ongoing battle between digital privacy advocates and surveillanceware developers. [Detailed coverage](https://therecord.media/jury-orders-nso-to-pay-meta-168-million-over-whatsapp-hack). ### US Warns of Threats Targeting ICS/SCADA Systems in Oil and Gas Industries The U.S. government has issued warnings regarding ongoing cyber intrusion attempts aimed at industrial control systems (ICS) and SCADA infrastructure within the oil and gas sector. This alert calls for heightened security measures to safeguard these critical systems from sophisticated threat actors. [Learn more](https://www.securityweek.com/us-warns-of-hackers-targeting-ics-scada-at-oil-and-gas-organizations/). ### You May Also Be Interested In... - **CISA Flags Two SonicWall Flaws as Actively Exploited**: Patching these is crucial to prevent remote command injections. [Read more](https://www.scworld.com/brief/cisa-flags-two-sonicwall-flaws-as-actively-exploited). - **Microsoft Dynamics 365 Phishing Scam**: A sophisticated phishing campaign is exploiting system trust to deceive users. [Details here](https://blog.checkpoint.com/research/microsoft-dynamics-365-customer-voice-phishing-scam). - **Ransomware and AI Threat Evolution in 2025**: Kaspersky's forecast on how ransomware groups are evolving with AI. [Explore more](https://securelist.com/state-of-ransomware-in-2025/116475/). This newsletter captures only a fraction of today's critical cybersecurity developments. Stay vigilant and keep your systems protected!
Cybersecurity — May 7, 2025 | Briefing24