THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### High-Risk Security Vulnerabilities in Cisco IOS XE WLC Security experts have published technical details about a critical flaw in Cisco IOS XE Wireless LAN Controller (WLC), tracked as CVE-2025-20188, which could allow attackers to execute arbitrary code remotely. The vulnerability had already led to major security alerts earlier in May, and with the public release of technical details, the likelihood of active exploitation is increasing. Organizations using affected Cisco systems are urged to apply the latest security patches immediately. [Read more](https://www.securityweek.com/technical-details-published-for-critical-cisco-ios-xe-vulnerability/). ### NIST's New Metric for Software Vulnerabilities The National Institute of Standards and Technology (NIST) is developing a new metric for assessing software vulnerabilities that are likely to be exploited by attackers. This new system aims to provide security teams with better predictive capabilities, allowing for more prioritized patching efforts. The initiative comes in light of increasing cyber threats and vulnerabilities in critical systems, such as those discovered in NASA’s open-source software. [Read more](https://www.helpnetsecurity.com/2025/06/01/week-in-review-nist-proposes-new-vulnerabilities-metric-flaws-in-nasas-open-source-software/). ### Covenant Health Cyberattack A cyberattack targeted three hospitals operated by Covenant Health, forcing them to shut down all systems to contain the incident. The attack underscores the continuing vulnerability of healthcare institutions to cyber threats, raising concerns about data protection and patient safety measures. As investigations are ongoing, stakeholders are advised to strengthen security protocols to mitigate such risks. [Read more](https://securityaffairs.com/178507/uncategorized/a-cyberattack-hit-hospitals-operated-by-covenant-health.html). ### Python and NPM Packages Backdoored A major cross-ecosystem attack discovered by Checkmarx involves backdoored Python and NPM packages targeting both Windows and Linux platforms. This sophisticated malware campaign highlights the increasing trend of software supply chain attacks, emphasizing the need for stringent security checks and the adoption of Software Bill of Materials (SBOM) standards across development environments. [Read more](https://hackread.com/backdoors-python-npm-packages-windows-linux/). ### Authorities Bust Counter Antivirus Service In a significant law enforcement operation, authorities have dismantled the counter antivirus service AVCheck, often used by cybercriminals to test malware against antivirus detection. This takedown marks a critical step in disrupting criminal networks' ability to refine malware and assures cybersecurity professionals of continued efforts to reduce malware propagation. [Read more](https://www.securityweek.com/authorities-take-down-counter-antivirus-service-avcheck/). ### You May Also Be Interested In... - **YARA 4.5.3 Release**: Tackling subtle bugs in malware pattern matching. [Read more](https://isc.sans.edu/diary/rss/31976). - **Alleged Leader of Conti and TrickBot Unmasked**: A major breakthrough in tackling organized cybercrime. [Read more](https://www.securityweek.com/alleged-conti-trickbot-gang-leader-unmasked). - **Google’s 7-Day Gmail Account Hack Warning**: Users urged to act quickly to maintain email control. [Read more](https://www.forbes.com/sites/daveywinder/2025/06/02/googles-7-day-gmail-account-hack-warning---act-now). Stay informed and vigilant as the cyber landscape continues to evolve.
Cybersecurity — June 2, 2025 | Briefing24