THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
### Cybersecurity Daily Briefing — June 11, 2025 #### TOP STORIES **Active Exploitation of Microsoft Zero-Day (CVE-2025-33053): Espionage Group Targets Turkish Defense** A critical Windows zero-day (CVE-2025-33053) was weaponized against a major Turkish defense organization, with Check Point attributing the operation to Stealth Falcon, a UAE-linked espionage group. Microsoft patched the flaw on June Patch Tuesday. The attack abused internet shortcut files to trigger malware leveraging Windows WebDAV, highlighting supply chain and phishing risks. - [Check Point analysis](https://blog.checkpoint.com/research/inside-stealth-falcons-espionage-campaign-using-a-microsoft-zero-day/) - [CISA/Microsoft warning](https://therecord.media/microsoft-cisa-zero-day-turkish-defense-org) - [Patch Tuesday coverage](https://cyberscoop.com/microsoft-patch-tuesday-june-2025/) **Microsoft Patch Tuesday: 66 Flaws, Actively Exploited Zero-Day, Multiple Critical RCEs** June's Patch Tuesday addressed 66 vulnerabilities, including 10 rated critical. CVE-2025-33053 (WebDAV RCE) is under active exploitation, and other critical bugs impact KDC Proxy, Netlogon (domain controllers), Office (Preview Pane), SMB, Remote Desktop, and cryptographic components. Experts recommend urgent patching—especially for internet-facing and privileged systems. - [Detailed vulnerability breakdown](https://www.thezdi.com/blog/2025/6/10/the-june-2025-security-update-review) - [CrowdStrike analysis](https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2025/) - [Patch list and priorities](https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2025-patch-tuesday-fixes-exploited-zero-day-66-flaws/) **Multiple Actively Exploited Vulnerabilities—Roundcube, Erlang/OTP SSH, and Wazuh SIEM — Patch Now** - **Roundcube Webmail (CVE-2025-49113):** Over 80,000 servers are exposed to a critical RCE exploit. Patch released, but mass exploitation observed. - [SecurityWeek overview](https://www.securityweek.com/exploited-vulnerability-impacts-over-80000-roundcube-servers/) - [Socradar deep dive](https://socradar.io/cve-2025-49113-roundcube-vulnerability-rce/) - **Erlang/OTP SSH (CVE-2025-32433):** An authentication bypass (9.8/10 CVSS), actively attacked, allowing unauthenticated remote code execution. - [The Hacker News](https://thehackernews.com/2025/06/cisa-adds-erlang-ssh-and-roundcube.html) - **Wazuh SIEM (CVE-2025-24016):** Akamai warns of Mirai botnets exploiting a critical RCE flaw in Wazuh open-source SIEM/XDR, actively used to join servers to botnets. Immediate patching vital. - [The Register report](https://www.theregister.com/2025/06/10/critical_wazuh_bug_exploited_in/) - [CyberNews summary](https://cybernews.com/security/wazuh-servers-targeted-by-mirai-botnets/) **Salesforce Industry Cloud: Five Zero-Days and Multiple Misconfigurations Threaten Thousands of Orgs** Researchers uncovered five zero-days and 15 misconfigurations in Salesforce Industry Cloud, exposing organizations to unauthorized data access and business disruption. Enterprises using industry-specific Salesforce offerings should review configurations and patch immediately. - [SecurityWeek article](https://www.securityweek.com/five-zero-days-15-misconfigurations-found-in-salesforce-industry-cloud/) - [The Hacker News](https://thehackernews.com/2025/06/researchers-uncover-20-configuration.html) **Data Breach at Texas DOT Exposes 300,000 Crash Reports** A hacker compromised Texas DOT’s Crash Records Information System, stealing 300,000 accident reports with personal data. The agency urges vigilance against fraud and phishing targeting recent Texas drivers. - [The Register report](https://www.theregister.com/2025/06/10/texas_accident_report_theft/) - [BleepingComputer coverage](https://www.bleepingcomputer.com/news/security/texas-dept-of-transportation-breached-300k-crash-records-stolen/) - [SecurityWeek article](https://www.securityweek.com/hackers-stole-300000-crash-reports-from-texas-department-of-transportation/) **Executive Order Rewrites U.S. Cybersecurity Policy and Digital ID Rules** A new executive order from the Trump administration rolls back Biden-era digital identity and secure software mandates, drawing private sector concern about weakened standards and potential for increased identity fraud in contractor settings. - [The Register summary](https://www.theregister.com/2025/06/10/trump_cybersecurity_eo_digital_ids/) - [SC Magazine](https://www.scworld.com/news/trump-executive-order-alters-biden-era-cybersecurity-regulations/) **Google Account Recovery Flaw Let Attackers Discover User Phone Numbers** A recently patched flaw in Google’s account recovery allowed brute-forcing of users’ linked phone numbers using partial numbers and display names—risking targeted phishing and SIM swapping. Google has remediated the bug; users should avoid linking unnecessary personal details. - [SecurityWeek story](https://www.securityweek.com/vulnerabilities-exposed-phone-number-of-any-google-user/) - [BleepingComputer details](https://www.bleepingcomputer.com/news/security/google-patched-bug-leaking-phone-numbers-tied-to-accounts/) - [Forbes guidance](https://www.forbes.com/sites/zakdoffman/2025/06/10/googles-gmail-update-yes-delete-your-phone-number-now/) --- ### You May Also Be Interested In... - **Critical SAP NetWeaver Flaw Patched—Privilege Escalation Risk** [SecurityWeek](https://www.securityweek.com/critical-vulnerability-patched-in-sap-netweaver/) - **FIN6 “Skeleton Spider” Uses Fake Resumes & Cloud Storage in Malware Delivery** [DomainTools Investigation](https://dti.domaintools.com/skeleton-spider-trusted-cloud-malware-delivery/) - **High-Profit Ransomware Attacks Target Sensors, Food Supply Chains** [SecurityWeek—Sensata ransomware](https://www.securityweek.com/sensitive-information-stolen-in-sensata-ransomware-attack/) [TechCrunch—UNFI/Whole Foods incident](https://techcrunch.com/2025/06/10/ongoing-cyberattack-at-us-grocery-distributor-giant-unfi-affecting-customer-orders/) - **Common Mobile Device Threat Vectors—Trends & Mitigation** [TrustedSec analysis](https://trustedsec.com/blog/common-mobile-device-threat-vectors) - **Cloud Security Can’t Keep Up With Tech Adoption—Threats Growing** [SC Magazine report](https://www.scworld.com/brief/cloud-security-cant-keep-up-with-tech-adoption) - **IoT Camera Exposures: 40,000 Feeds Streaming Sensitive Data** [The Register](https://www.theregister.com/2025/06/10/40000_iot_cameras_exposed/) - **Facebook Malvertising: Over 4,000 Domains Spoofing Brands Detected** [SC Magazine](https://www.scworld.com/news/facebook-malvertising-reveals-4k-domains-spoofing-68-brands) --- Stay vigilant, patch quickly, and consider reviewing your organization’s exposure in light of these developments. For breaking alerts, threat intelligence, and incident response best practices, follow our daily briefing. *Compiled by [Your Name], Cybersecurity Newsletter Editor.*
Cybersecurity — June 10, 2025 | Briefing24