THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Here are today's key stories for your cybersecurity update: ### Cybercriminals Exploit AI Tools to Spread Malware Cisco Talos has discovered a new approach by cybercriminals where they disguise ransomware and malware as legitimate AI tool installers. Malwares such as CyberLock, Lucky_Gh0$t, and Numero were found masquerading as trusted AI tools, posing a risk to unsuspecting users. Cybersecurity professionals are advised to remain vigilant about downloading AI-related software. For more details, visit: [Cisco Talos](https://blog.talosintelligence.com/fake-ai-tool-installers/). ### U.S. Imposes Sanctions on 'Pig Butchering' Scam Operator The U.S. government has sanctioned Funnull Technology Inc., a cloud provider based in the Philippines, for its role in facilitating large-scale virtual currency investment scams known as "pig butchering." These scams have resulted in substantial financial losses for thousands of citizens. This move highlights a heightened focus on targeting infrastructures supporting major cybercriminal activities. More on this can be read at: [KrebsOnSecurity](https://krebsonsecurity.com/2025/05/u-s-sanctions-cloud-provider-funnull-as-top-source-of-pig-butchering-scams/). ### Victoria's Secret Website Down Due to Cyberattack Victoria's Secret has taken its website offline following a suspected cyberattack, highlighting the increasing threats facing the retail sector. The company is currently investigating the security incident as experts warn of growing cyber threats targeting major retailers in both the U.S. and abroad. Details are still emerging, and more information can be found here: [BleepingComputer](https://www.bleepingcomputer.com/news/security/victorias-secret-takes-down-website-after-security-incident/). ### APT41 Exploits Google Calendar for Malware Control China-based hacking group APT41 has been identified as using Google Calendar to execute a cyber-espionage campaign against various governments. This sophisticated maneuver involves leveraging the calendar app for command-and-control functions, showcasing the inventive tactics utilized by state-sponsored actors. Google has moved to dismantle this infrastructure. More on this development can be found at: [SCMagazine](https://www.scmagazine.com/brief/google-calendar-exploiting-apt41-attack-campaign-disrupted). ### Microsoft Suffers Update Glitches Microsoft's latest Patch Tuesday update is causing issues for Windows 11 users, particularly on virtual machines, causing them to fail to start correctly. The company is currently advising users to avoid the update while they work on a fix, illustrating the complications that can arise from routine security maintenance. Further details are available at: [The Register](https://go.theregister.com/feed/www.theregister.com/2025/05/29/microsoft_windows_problems/). ### You May Also Be Interested In... - "GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability" - [SecurityWeek](https://www.securityweek.com/greynoise-flags-9000-asus-routers-backdoored-via-patched-vulnerability/) - "UK Military to Establish New Cyber and Electromagnetic Command" - [RecordedFuture](https://therecord.media/uk-military-new-cyber-electromagnetic-command) - "ConnectWise Hit by Cyberattack; Nation-State Actor Suspected" - [TheHackerNews](https://thehackernews.com/2025/05/connectwise-hit-by-cyberattack-nation.html) Stay current with these stories to safeguard your cyber environment and stay ahead of threats.
Cybersecurity — May 30, 2025 | Briefing24