THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Emerging Threat: Sophisticated Malware Campaigns and Exploits **Headline**: [Multilayered Email Attack: How a PDF Invoice and Geo-Fencing Led to RAT Malware](https://www.fortinet.com/blog/threat-research/multilayered-email-attack-how-a-pdf-invoice-and-geofencing-led-to-rat-malware) FortiGuard Labs reveal a new sophisticated malware campaign exploiting PDF invoices and geo-fencing to deploy Remote Administration Tools (RATs) for malicious purposes. This highlights the growing trend of leveraging legitimate software functionalities in cyber attacks, increasing the challenge for detection and mitigation efforts. Source: Fortinet ### Critical Vulnerabilities: SonicWall and Cisco Flaws Exploited **Headline**: [Yet another SonicWall SMA100 vulnerability exploited in the wild (CVE-2025-32819)](https://www.helpnetsecurity.com/2025/05/08/sonicwall-sma100-vulnerability-exploited-cve-2025-32819/) SonicWall's patched vulnerabilities are being exploited in the wild, involving sophisticated chaining of flaws for remote code execution. This includes CVE-2025-32819, a zero-day exploit that had previously been targeted in attacks. Source: Help Net Security **Headline**: [Cisco patches maximum severity vulnerability in IOS XE Software](https://www.scworld.com/news/cisco-patches-maximum-severity-vulnerability-in-ios-xe-software) Cisco has addressed a critical flaw in its IOS XE Software, allowing remote attackers to gain control over devices via a hard-coded JSON Web Token. The complexity and potential impact make immediate patching crucial for affected enterprises. Source: SCMagazine ### Legal and Policy Updates: Meta vs. NSO and CISA Alerts **Headline**: [WhatsApp hack: Meta wins payout over NSO Group spyware](https://www.malwarebytes.com/blog/news/2025/05/whatsapp-hack-meta-wins-payout-over-nso-group-spyware) Meta's legal victory over NSO Group results in a $170 million payout for the misuse of spyware, highlighting growing accountability within the commercial surveillance market. Source: MalwareBytes Blog **Headline**: [U.S. CISA adds GoVision device flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/177599/security/u-s-cisa-adds-govision-device-flaws-to-its-known-exploited-vulnerabilities-catalog.html) The latest update from CISA's Known Exploited Vulnerabilities catalog emphasizes the urgent need to address flaws in GoVision devices, highlighting ongoing risks to critical infrastructure. Source: Security Affairs ### You May Also Be Interested In... - [Google links new LostKeys data theft malware to Russian cyberspies](https://www.bleepingcomputer.com/news/security/google-links-new-lostkeys-data-theft-malware-to-russian-cyberspies) - [Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell](https://thehackernews.com/2025/05/chinese-hackers-exploit-sap-rce-flaw.html) - [CISA Warns of Cyberattacks Against Critical Oil and Gas Infrastructure](https://www.securitymagazine.com/articles/101607-cisa-warns-of-cyberattacks-against-critical-oil-and-gas-infrastructure)
Cybersecurity — May 9, 2025 | Briefing24