THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Emerging Ransomware Threat: VanHelsing The ransomware landscape continues to evolve with the emergence of VanHelsing, which leverages TOR sites for ransom negotiations and data leaks—first identified in March 2025. This new strain highlights the increasing sophistication arms race between cybercriminals and defenders. Understanding VanHelsing's modus operandi can inform defenses. - **Source**: [Fortinet](https://www.fortinet.com/blog/threat-research/ransomware-roundup-vanhelsing) ### Critical Chrome Vulnerability Actively Exploited A high-severity vulnerability in Google Chrome (CVE-2025-4664) is being exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalog. The flaw stems from insufficient policy enforcement, allowing cross-origin data leaks that can lead to full account takeovers. Users should update immediately to mitigate risks. - **Source**: [Help Net Security](https://www.helpnetsecurity.com/2025/05/16/cisa-recently-fixed-chrome-vulnerability-exploited-in-the-wild-cve-2025-4664/) ### Ivanti Faces Zero-Day Exploits Two zero-day vulnerabilities (CVE-2025-4427 and CVE-2025-4428) are actively exploited in Ivanti Endpoint Manager Mobile. These flaws enable pre-authenticated remote code execution. Organizations using Ivanti EPMM should apply patches urgently to prevent potential breaches. - **Source**: [Rapid7](https://blog.rapid7.com/2025/05/16/etr-ivanti-epmm-exploit-chain-exploited-in-the-wild/) ### EU Court Bans Tracking-Based Ads In a significant policy ruling, the Brussels Court of Appeal has declared tracking-based online ads illegal due to inadequate consent models. This decision could shift the advertising landscape significantly and poses compliance challenges for global advertisers targeting EU users. - **Source**: [Recorded Future](https://therecord.media/eu-court-rules-tracking-based-ads-illegal) ### Japan Enacts New Cyber Law Japan has passed a law allowing offensive cyber operations, a significant policy shift aiming to strengthen national defense. This positions Japan alongside major Western powers in terms of cyber capabilities and could influence regional cyber defense dynamics. - **Source**: [Recorded Future](https://therecord.media/japan-enacts-new-law-allowing-offensive-cyber-operations) ### Pro-Ukraine Group Targets Russian Developers A fake Python debugger backdoors systems with a focus on Russian developers, attributed to pro-Ukraine groups. Such cyber-operations underscore the ongoing geopolitical cyber conflicts and highlight the need for vigilance in software supply chains. - **Source**: [HackRead](https://hackread.com/ukraine-group-russian-developers-python-backdoor/) ### Data Broker Protection Rule Withdrawn The CFPB has withdrawn a 2024 rule aimed at regulating the sale of personal information by data brokers. This policy change raises privacy concerns and calls for renewed advocacy to protect consumer data. - **Source**: [MalwareBytes Blog](https://www.malwarebytes.com/blog/news/2025/05/data-broker-protection-rule-quietly-withdrawn-by-cfpb) ### You May Also Be Interested In... - **CISA Critical Alert**: [Chrome 0-Day Warning](https://www.forbes.com/sites/daveywinder/2025/05/16/cisa-issues-critical-chrome-0-day-alert-dont-wait-to-update-browser/) by Forbes Security. - **Ransomware on UK NHS**: [NHS Suppliers Warned](https://therecord.media/uk-nhs-suppliers-ransomware-letter) by Recorded Future. - **Coinbase Breach Fallout**: [Hackers Expose High-Profile Data](https://www.bloomberg.com/news/articles/2025-05-16/coinbase-hackers-used-bribery-in-scheme-to-access-customer-data) by Bloomberg Cyber. These articles provide key insights into the current cyber threat landscape and regulatory changes that impact cybersecurity practices across industries.
Cybersecurity — May 17, 2025 | Briefing24