THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Cityworks Zero-Day Exploited by Chinese Hackers A zero-day vulnerability in Trimble Cityworks, exploited by Chinese threat actor UAT-6382, has targeted US local government networks. This vulnerability, identified as CVE-2025-0994, has been actively used to deliver malware, including Cobalt Strike and VShell, to infiltrate municipal entities. The threat actor, identified as UAT-6382, showcases the ongoing international cybersecurity threat landscape, particularly towards critical infrastructure within the US. Cybersecurity professionals in similar sectors should stay vigilant and ensure systems are updated and patched promptly to mitigate potential threats. [Read more on SecurityWeek](https://www.securityweek.com/cityworks-zero-day-exploited-by-chinese-hackers-in-us-local-government-attacks/) ### DanaBot Malware Network Disrupted The US Department of Justice announced a successful disruption of the DanaBot malware network. The operation unsealed charges against 16 individuals connected to Russia-based cybercrime operations, implicating them in a long-standing malware-as-a-service operation that resulted in significant financial damages. This development highlights the importance of international cooperation in cybersecurity enforcement and disruption operations. Entities using anti-malware systems should verify that signature databases are updated to recognize DanaBot and its derivatives. [Read more on KrebsOnSecurity](https://krebsonsecurity.com/2025/05/oops-danabot-malware-devs-infected-their-own-pcs/) ### Critical Windows Server 2025 Vulnerability A major vulnerability, titled "BadSuccessor," in Windows Server 2025 is currently unpatched, posing a severe risk to Active Directory domains. This security flaw allows a trivial exploitation leading to full domain compromise. Security teams are advised to assess their Windows Server environments and implement mitigations where possible until an official patch is released by Microsoft. [Read more on HelpNet Security](https://www.helpnetsecurity.com/2025/05/22/unpatched-windows-server-vulnerability-allows-active-directory-users-full-domain-compromise/) ### Lumma Stealer Malware Network Taken Down An international law enforcement operation led by the FBI and other global partners has successfully disrupted the Lumma Stealer malware network, seizing 2,300 domains used for command-and-control operations. This action represents a strong collaborative effort to combat cyber threats targeting widespread credentials. Organizations are encouraged to review their security postures and educate staff on phishing attempts. [Read more on ESET Blog](https://www.welivesecurity.com/en/eset-research/danabot-analyzing-fallen-empire/) ### You May Also Be Interested In... - [Chinese Hackers Exploit Ivanti Vulnerabilities Against Critical Sectors](https://www.securityweek.com/chinese-spies-exploit-ivanti-vulnerabilities-against-critical-sectors/) - [AI-Generated Deepfake Frauds Erode Digital Trust](https://www.helpnetsecurity.com/2025/05/23/ai-powered-fraud-threat/) - [Global Dark Web Sting Sees 270 Arrested](https://ciso2ciso.com/global-dark-web-sting-sees-270-arrested-source-www-infosecurity-magazine-com/) By keeping abreast of these developments, cybersecurity professionals can better understand the evolving threats and strategies to mitigate them effectively in their organizations.
Cybersecurity — May 23, 2025 | Briefing24