THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### Major Cybersecurity News: Emerging Threats and Key Developments #### 1. Microsoft OneDrive File Picker Vulnerability Exposes Users to Risks Security researchers have discovered a critical flaw in Microsoft's OneDrive File Picker that allows third-party applications to access users' entire cloud storage, rather than just a specific file. This over-permissive access stems from broad OAuth scopes and misleading consent screens, raising significant privacy concerns. This vulnerability underscores the importance of restricting permissions and ensuring transparent consent processes in cloud services. [Read More](https://hackread.com/onedrive-file-picker-flaw-gives-apps-full-access-to-user-drives/) #### 2. Chinese APT41 Exploits Google Calendar for Stealthy Malware C2 Google has disclosed that Chinese state-sponsored hackers, APT41, have been using Google Calendar for command-and-control operations in their malware campaign. The malware, known as TOUGHPROGRESS, was distributed via spear-phishing emails. This technique exploits trusted cloud services for C2, making detection challenging and highlighting the need for robust email security protocols. [Read More](https://thehackernews.com/2025/05/chinese-apt41-exploits-google-calendar.html) #### 3. Data Broker Giant LexisNexis Suffers Massive Data Breach LexisNexis, a major data broker, confirmed a cyberattack exposing sensitive information of over 364,000 individuals. The breach was facilitated through unauthorized access to a third-party software development platform, raising concerns about the security of outsourced technology services. [Read More](https://www.bleepingcomputer.com/news/security/data-broker-lexisnexis-discloses-data-breach-affecting-364-000-people/) #### 4. New Botnet Targets Linux IoT Devices A new botnet called PumaBot is actively exploiting Linux-based IoT devices by brute-forcing SSH credentials to spread malware and mine cryptocurrency. This threat showcases the increasing sophistication of attacks targeting IoT environments, emphasizing the need for securing SSH access with strong passwords and other protective measures. [Read More](https://securityaffairs.com/178399/apt/new-pumabot-targets-linux-iot-devices.html) #### 5. Pakistan Arrests 21 in Major Malware Operation Pakistani authorities have arrested 21 individuals linked to the 'Heartsender' malware service, which had been operational for over a decade, primarily supporting organized crime groups. This arrest signifies a major crackdown on cybercrime networks exploiting malware for financial gain. [Read More](https://krebsonsecurity.com/2025/05/pakistan-arrests-21-in-heartsender-malware-service/) ### You May Also Be Interested In... - **ASUS Router Backdoor Exploit:** Over 9,000 ASUS routers affected by persistent SSH backdoors, even after firmware updates. [Details](https://www.helpnetsecurity.com/2025/05/28/asus-router-backdoors-affect-9k-devices-persist-after-firmware-updates) - **Adidas Data Breach Details:** Adidas confirms breach exposing customer data via third-party systems. [More Info](https://www.forbes.com/sites/larsdaniel/2025/05/28/adidas-admits-data-breach-following-third-party-attack) - **Massive WooCommerce Plugin Vulnerability Impact:** Over 100,000 WordPress sites at risk due to critical Wishlist plugin vulnerability. [Read More](https://thehackernews.com/2025/05/over-100000-wordpress-sites-at-risk.html) - **Apple Blocks Billions in App Store Fraud:** Apple reports blocking $2 billion in fraudulent transactions in 2024 alone. [Explore](https://bleepingcomputer.com/news/apple/apple-blocked-over-9-billion-in-app-store-fraud-since-2020/)
Cybersecurity — May 29, 2025 | Briefing24