THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
### DanaBot Botnet Disrupted, QakBot Leader Indicted In a significant blow to global cybercrime, law enforcement agencies in collaboration with Europol and Eurojust have dismantled the DanaBot botnet and indicted key figures of the Qakbot malware operation. This massive operation, dubbed Operation Endgame, involved authorities from the US, Canada, and the EU and resulted in the disruption of the infrastructure supporting both malware networks. This operation underscores international commitment to combating cybercrime, with over 300 servers and 650 domains taken down. [Read more](https://www.helpnetsecurity.com/2025/05/23/operation-endgame-danabot-botnet-disrupted-qakbot-leader-indicted/) ### Chinese Cyber Espionage Leveraging Ivanti Vulnerabilities A report from EclecticIQ reveals a Chinese cyber espionage group has been exploiting Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities (CVE-2025-4427 and CVE-2025-4428) as zero-day flaws to breach EU and US organizations. Targeted entities include local government authorities and healthcare organizations, highlighting the continued focus of state-backed groups on critical sectors. Security experts advise rapid patching to mitigate these exploits. [Read more](https://www.helpnetsecurity.com/2025/05/23/chinese-cyber-spies-are-using-ivanti-epmm-flaws-to-breach-eu-us-organizations/) ### TikTok Videos Used to Spread Infostealer Malware Trend Micro researchers have uncovered a malicious campaign leveraging TikTok videos to distribute infostealer malware via a technique called ClickFix. This unconventional method uses TikTok’s vast reach and perceived credibility to trick users into executing commands that install the malware. This trend marks an evolution in social engineering tactics, as threat actors increasingly exploit popular platforms. [Read more](https://www.helpnetsecurity.com/2025/05/23/tiktok-videos-clickfix-tactic-infostealer-malware-infection/) ### Massive Data Breach Exposes 184 Million Passwords A massive, unsecured online database has exposed 184 million login credentials from major platforms like Google, Microsoft, and Facebook. The plaintext file lacked any encryption or security measures, posing a critical risk to users whose information has been compromised. This breach highlights the ongoing challenge of data protection and the need for robust security protocols. [Read more](https://www.zdnet.com/article/massive-data-breach-exposes-184-million-passwords-for-google-microsoft-facebook-and-more/) ### Operation RapTor: 270 Arrested in Dark Web Crackdown Operation RapTor has led to the arrest of 270 individuals involved in illegal activities on the dark web, marking a significant international effort to combat the trafficking of drugs, weapons, and counterfeit goods. This large-scale operation, spearheaded by Europol and US authorities, also resulted in the seizure of large amounts of cash and crypto assets. [Read more](https://therecord.media/global-law-enforcement-arrest-270-tied-to-dark-web-drug-sales) ### You May Also Be Interested In - **Signal Blocks Windows Recall:** Signal implements a new screen security feature to block screenshot captures by Microsoft's Windows Recall on Windows 11. [Read more](https://www.schneier.com/blog/archives/2025/05/signal-blocks-windows-recall.html) - **Researchers Exploit GitLab AI:** GitLab’s AI developer assistant manipulated to inject malicious code, demonstrating risks in AI-based coding tools. [Read more](https://arstechnica.com/security/2025/05/researchers-cause-gitlab-ai-developer-assistant-to-turn-safe-code-malicious/) - **SafeLine WAF for Zero-Day Protection:** SafeLine emerges as a leading open-source Web Application Firewall providing zero-day and bot attack defenses. [Read more](https://thehackernews.com/2025/05/safeline-waf-open-source-web.html) This briefing provides essential updates that cybersecurity professionals need today, addressing major incidents, vulnerabilities, and measures in the evolving threat landscape.
Cybersecurity — May 24, 2025 | Briefing24