THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Nova Scotia Power Ransomware Attack Nova Scotia Power has confirmed a ransomware attack, despite having not paid the demanded sum. The attack, initially disclosed nearly a month ago, highlights ongoing vulnerabilities within the energy sector to cyber threats. This incident underscores the importance for critical infrastructure entities to bolster their cybersecurity defenses against ransomware attacks, which are increasingly aimed at utilities and services critical to public operations. [Read more](https://securityaffairs.com/178323/data-breach/nova-scotia-power-confirms-it-was-hit-by-ransomware-but-hasnt-paid-the-ransom.html) ### Emergence of AsyncRAT Rewritten in Rust The notorious AsyncRAT malware has undergone a major transformation; it is now rewritten in Rust to help evade analysis and detection. This update makes the RAT harder for security teams to track, given Rust's complexity and efficiency in producing low-level machine code. Organizations need to step up their anti-malware solutions to detect potential threats and protect sensitive data. [Read more](https://feeds.feedblitz.com/~/918988475/0/gdatasecurityblog-en~Reborn-in-Rust-AsyncRAT-makes-a-move-to-counter-analysis) ### DragonForce Exploits SimpleHelp Vulnerabilities DragonForce hackers have targeted vulnerabilities in the remote management software SimpleHelp, affecting numerous Managed Service Providers (MSPs) and their clients. This incident reveals the critical risk associated with RMM software, emphasizing the need for stringent security measures and regular vulnerability assessments to prevent exploitation by threat actors. [Read more](https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/) ### Commvault Zero-Day Threat A zero-day vulnerability in Commvault's SaaS offerings is being exploited as part of a wider attack campaign. The vulnerability allows unauthorized access, leading to compromised SaaS applications. Companies using Commvault are urged to implement patches and enhance monitoring for potential breaches. This situation highlights the persistent risk that zero-day vulnerabilities pose to cloud and SaaS environments. [Read more](https://ciso2ciso.com/cisa-flags-commvault-zero-day-as-part-of-wider-saas-attack-campaign-source-www-csoonline-com/) ### China-linked APT Targets Ivanti EPMM A China-linked Advanced Persistent Threat (APT) group, UNC5221, has been exploiting vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM) systems. These flaws have been aimed at critical sectors, including industries across North America, Europe, and Asia-Pacific. It underscores the need for organizations using Ivanti products to install patches swiftly and review their security measures. [Read more](https://securityaffairs.com/178285/apt/china-linked-apt-unc5221-started-exploiting-ivanti-epmm-flaws-shortly-after-their-disclosure.html) ### You May Also Be Interested In... - [How AI agents reshape industrial automation and risk management](https://www.helpnetsecurity.com/2025/05/27/michael-metzler-siemens-ai-agents-industrial-environments/) - [94 billion browser cookies stolen and sold on dark web](https://cybernews.com/security/stolen-browser-cookies-sold-telegram/) - [Russia-Linked Hackers target Tajikistan Government with weaponized Word documents](https://thehackernews.com/2025/05/russia-linked-hackers-target-tajikistan.html)
Cybersecurity — May 27, 2025 | Briefing24