THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Key Stories **1. Massive DDoS Attack Hits KrebsOnSecurity** A near-record DDoS attack on KrebsOnSecurity clocked over 6.3 terabits per second, marking a potential new capability of IoT botnets. This attack highlights the growing scale and sophistication of DDoS threats, emphasizing the need for enhanced network security defenses. [Read more](https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/) **2. Exploitation of Ivanti EPMM Vulnerabilities** Wiz Research has detected ongoing exploitation of vulnerabilities (CVE-2025-4427 and CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM), facilitating unauthenticated remote code execution. This highlights the urgent need for enterprises to patch systems and reinforce their cybersecurity posture. [Read more](https://www.wiz.io/blog/ivanti-epmm-rce-vulnerability-chain-exploited-in-the-wil-cve-2025-4427-cve-2025-4) **3. OpenPGP.js Vulnerability Allows Message Spoofing** A critical flaw (CVE-2025-47934) in OpenPGP.js permits attackers to spoof message signatures, compromising encrypted communications. Users are urged to update to the latest version to mitigate this significant risk. [Read more](https://www.theregister.com/2025/05/20/openpgp_js_flaw/) **4. Ransomware Attack Forces Kettering Health to Cancel Procedures** Kettering Health system experienced a ransomware attack causing a massive system outage, leading to canceled procedures. This incident underscores the vulnerability of healthcare systems to cyberattacks and the importance of proactive ransomware defenses. [Read more](https://www.securityweek.com/ransomware-attack-forces-kettering-health-to-cancel-procedures/) **5. UK’s Legal Aid Agency Data Breach** The Legal Aid Agency in the UK confirmed a data breach following a cyberattack, potentially exposing sensitive data. This breach demonstrates the critical necessity for robust defensive and detection strategies in governmental bodies. [Read more](https://securityaffairs.com/178088/data-breach/uks-legal-aid-agency-discloses-data-breach-following-april-cyber-attack.html) ### You May Also Be Interested In... - **China's MarsSnake Backdoor Launched in Recent Attacks**: A China-linked APT used a new MarsSnake backdoor against a Saudi Arabian target, signaling heightened cyber espionage activities. [Read more](https://securityaffairs.com/178105/malware/china-linked-unsolicitedbooker-used-new-backdoor-marssnake.html) - **Samsung Galaxy Owners Surprised by Android Update**: Samsung's unforeseen Android update brings new features but also potential security concerns for Galaxy users. [Read more](https://www.forbes.com/sites/zakdoffman/2025/05/21/samsung-surprises-galaxy-owners-with-android-update-decision/) - **Meta’s New AI Tool Evaluates Bug Fixing Efficiency**: AutoPatchBench, Meta's benchmark for AI bug-fixing tools, could revolutionize automated software patching. [Read more](https://www.helpnetsecurity.com/2025/05/21/autopatchbench-meta-test-ai-bug-fixing-tools/) - **Peter Green Chilled Hit by Ransomware**: This attack on a major UK food distributor causes significant disruptions, highlighting the need for better protective measures in supply chains. [Read more](https://therecord.media/peter-green-chilled-ransomware-uk-logistics-company) Stay informed and vigilant with the latest in cybersecurity news and developments.
Cybersecurity — May 21, 2025 | Briefing24