THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Critical Vulnerabilities in Microsoft, Fortinet, and Ivanti Products On Patch Tuesday, Microsoft released fixes for 78 security flaws, including five actively exploited zero-day vulnerabilities, one of which allows remote code execution by leveraging a memory corruption vulnerability in the Windows scripting engine. Fortinet addressed a critical stack-based overflow vulnerability in FortiVoice systems that led to remote code execution, while Ivanti fixed two EPMM vulnerabilities that were previously exploited in targeted attacks. Cybersecurity professionals are urged to apply these patches promptly to mitigate risk. - Read more about Microsoft updates: [Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited](https://thehackernews.com/2025/05/microsoft-fixes-78-flaws-5-zero-days.html) - Details on Fortinet vulnerabilities: [Fortinet Patches CVE-2025-32756 Zero-Day](https://thehackernews.com/2025/05/fortinet-patches-cve-2025-32756-zero.html) - Insights on Ivanti patches: [Ivanti Patches EPMM Vulnerabilities](https://thehackernews.com/2025/05/ivanti-patches-epmm-vulnerabilities.html) ### Emerging Cyber Threat: North Korea Targets Ukrainian Entities Proofpoint and other cybersecurity researchers have reported that North Korean hackers, known as Konni APT, have been targeting Ukrainian government entities to collect intelligence. This cyber-espionage campaign follows historical targeting patterns but indicates a strategic pivot towards understanding Ukraine's defense capabilities amid the ongoing conflict with Russia. - Discover more at: [North Korean APT Targets Ukraine](https://thehackernews.com/2025/05/north-korean-konni-apt-targets-ukraine.html) ### EU Launches European Vulnerability Database (EUVD) ENISA announced the operational status of the European Vulnerability Database, designed to augment digital security by providing centralized access to vulnerability data. This initiative is part of the broader NIS2 Directive to enhance cybersecurity across the EU, offering a complementary resource to the existing MITRE CVE program. - Explore more: [Europe's new vulnerability database 'EUVD'](https://cybernews.com/security/europe-launches-vulnerability-database-euvd-enisa-mitre-cve-funding/) ### Marks & Spencer Confirms Data Breach Marks & Spencer confirmed personal data theft in a cyberattack attributed to a ransomware group. The breach affected customer data but reportedly spared payment card details. This incident highlights the ongoing threat of ransomware and the importance of robust data protection strategies. - Full story here: [Marks & Spencer confirms customer data was stolen](https://www.techcrunch.com/2025/05/13/marks-spencer-confirms-customers-personal-data-was-stolen-in-hack/) ### You May Also Be Interested In... 1. **Apple's Latest Security Updates**: Apple pushes critical updates for iOS and macOS, addressing multiple vulnerabilities. - [Read more at Forbes](https://www.forbes.com/sites/kateoflahertyuk/2025/05/13/ios-185-apple-just-gave-all-iphone-users-33-reasons-to-update-now/) 2. **SAP Vulnerabilities**: SAP releases critical patches for May, including a vulnerability impacting Visual Composer. - [Read more at Onapsis](https://onapsis.com/blog/sap-security-patch-day-may-2025/) 3. **Phishing Campaign Alert**: Google services exploited to send phishing emails appearing to originate from Google's no-reply addresses. - [Discover more at Kaspersky](https://www.kaspersky.com/blog/dkim-replay-attack-through-google-oauth/53392/)
Cybersecurity — May 14, 2025 | Briefing24