THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
### Critical Lumma Stealer Malware Network Disrupted by Collaborative Effort Authorities including the US, European, and Japanese agencies, with Microsoft and Cloudflare, have successfully dismantled the Lumma Stealer malware network by shutting down over 2,300 domains. The Lumma Stealer operational network, a significant player offering info-stealing services to cybercriminal groups worldwide, was responsible for credential theft, financial data pilferage, and further malicious payload deployments. The achievement signifies a substantial win in disrupting global cybercrime frameworks and safeguarding potentially millions of devices from exploitation. [Read more](https://www.helpnetsecurity.com/2025/05/21/lumma-stealer-malware-as-a-service-operation-disrupted/) ### High-Severity Vulnerabilities Patched in GitLab and Atlassian Both GitLab and Atlassian have addressed multiple vulnerabilities, including critical ones, in their recent updates, reinforcing their commitment to maintaining secure platforms for user data and operations. The patches cover over a dozen security flaws, with the high-severity bugs affecting essential functions. Users are urged to apply these patches swiftly to mitigate potential exploits and ensure system integrity. [More details here](https://www.securityweek.com/gitlab-atlassian-patch-high-severity-vulnerabilities/) ### Russian APT28 Intensifies Attacks on Western Logistics Aiding Ukraine The CISA has issued warnings over escalating threats from the Russian-linked APT28 group targeting Western logistics and technology companies assisting Ukraine. This heightened activity poses significant risks to supply chains involved in transporting weaponry, medical aid, and other critical supplies into Ukraine. The operations underscore the ongoing geopolitical tensions and the use of cyber espionage as a tactical instrument by state-sponsored entities. [Full article](https://therecord.media/western-intelligence-alert-russia-hackers-logistics-fancy-bear-apt28) ### Significant Zero-Day Exploit in Cityworks Software The zero-day exploit in Cityworks, identified as CVE-2025-0994, has been actively leveraged by Chinese-speaking threat actor UAT-6382 using TetraLoader to deploy malware. This vulnerability underlines the critical need for public infrastructure reliant on Cityworks to immediately implement mitigation measures to defend against these malicious campaigns. [Find out more](https://blog.talosintelligence.com/uat-6382-exploits-cityworks-vulnerability/) ### Emerging Threats in AI Deployment and Operations A significant portion of organizations are pushing forward with GenAI deployments, often lacking the necessary security frameworks to protect these advanced AI environments. Thales identifies the pace of development without adequate security as a chief concern. Meanwhile, organizations are already prioritizing spending in GenAI due to its transformative potential, despite mounting data integrity and trustworthiness challenges. [Explore the full report](https://www.helpnetsecurity.com/2025/05/22/genai-adoption-security-concern/) ### You May Also Be Interested In... - **UK Retail Cyberattacks Under Investigation by Police**: The UK's National Crime Agency probes a series of cyberattacks impacting major retail companies. [Read more](https://therecord.media/uk-retail-cyberattacks-nca-investigation) - **Marks & Spencer Cyberattack Financial Impact**: Marks & Spencer forecasts a £300 million loss due to a recent cyberattack, with effects expected to last until July. [Full story](https://therecord.media/m-s-says-cyberattack-hit-to-profits-300m) - **Vulnerability Exploit in OpenPGP.js**: A critical flaw, CVE-2025-47934, allows attackers to spoof signatures in OpenPGP.js, prompting immediate need for updated secure implementations. [Learn more](https://securityaffairs.com/178131/uncategorized/a-openpgp-js-flaw-lets-attackers-spoof-message-signatures.html) - **Redis Server Cryptojacking Campaign Unveiled**: New attacks on Redis servers using the XMRig miner have sparked concerns over cryptojacking vulnerabilities. [Details here](https://www.scworld.com/brief/vulnerable-redis-servers-targeted-for-cryptojacking)
Cybersecurity — May 22, 2025 | Briefing24