THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗
### Daily Cybersecurity Briefing – June 11, 2025 #### Microsoft Patch Tuesday: Active Zero-Day Exploited by Nation-State Actors **Microsoft’s June Patch Tuesday** addressed 66 vulnerabilities (10 critical), including one zero-day (CVE-2025-33053, WebDAV RCE) actively exploited in the wild. This vulnerability enabled remote code execution via specially crafted .url files. Check Point and Microsoft linked its exploitation to Stealth Falcon—a known espionage group targeting the Middle East and Africa, with recent incidents involving a major Turkish defense organization. Another high-severity flaw in SMB Client (CVE-2025-33073) is publicly disclosed and likely to be weaponized soon. **Action:** Patch all affected Windows systems immediately, including EOL editions where out-of-band patches were issued. - [Crowdstrike’s analysis](https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2025/) - [ZDI Deep Dive & CVE List](https://www.thezdi.com/blog/2025/6/10/the-june-2025-security-update-review) - [Check Point report on zero-day use by Stealth Falcon](https://blog.checkpoint.com/research/inside-stealth-falcons-espionage-campaign-using-a-microsoft-zero-day/) - [Recorded Future coverage](https://therecord.media/microsoft-cisa-zero-day-turkish-defense-org) #### Wazuh SIEM/XDR: Mirai Botnets Exploiting Critical RCE (CVE-2025-24016) Akamai, CSO, and multiple vendors warn that **two active Mirai botnets (Lzrd & Resgod)** are exploiting a critical RCE in **Wazuh** servers, permitting remote code upload and execution. The bug (CVSS 9.9) is being leveraged to conscript systems into botnets. **Action:** Patch Wazuh (esp. versions 4.4.0–4.9.0) immediately and investigate logs for suspicious shell script or botnet activity. - [Akamai/CSO detailed report](https://www.helpnetsecurity.com/2025/06/10/unpatched-wazuh-servers-targeted-by-mirai-botnets-cve-2025-24016/) - [CSOOnline: PoC weaponization](https://ciso2ciso.com/mirai-botnet-weaponizes-poc-to-exploit-wazuh-open-source-xdr-flaw-source-www-csoonline-com/) #### Critical Roundcube Webmail, Erlang/OTP Flaws Now in CISA KEV CISA added newly exploited vulnerabilities in **Roundcube Webmail** (CVE-2025-49113, RCE, over 80,000 servers exposed) and the **Erlang/OTP SSH server** (CVE-2025-32433, missing auth bug enables unauthenticated RCE) to its KEV catalog. Mass scanning and exploitation has been observed. **Action:** Urgently patch Roundcube and Erlang/OTP deployments, check for signs of compromise. - [CISA notification](https://securityaffairs.com/178843/hacking/u-s-cisa-adds-roundcube-erlang-erlang-flaws-known-exploited-vulnerabilities-catalog.html) - [SecurityWeek analysis](https://www.securityweek.com/exploited-vulnerability-impacts-over-80000-roundcube-servers/) #### Google Account Phone Number Disclosure Flaw Fixed (CVE-2025-XXXX) Researchers demonstrated a now-fixed bug in Google’s account recovery flow that allowed attackers to brute-force and reveal linked phone numbers (low reward, but high privacy risk). Attackers could also obtain full display names by bypassing anti-bot defenses. **Action:** No immediate fix needed, but review Google account recovery policies and encourage users to monitor for SMS phishing (smishing). - [SecurityWeek coverage](https://www.securityweek.com/vulnerabilities-exposed-phone-number-of-any-google-user/) - [The Register summary](https://go.theregister.com/feed/www.theregister.com/2025/06/10/google_brute_force_phone_number/) #### Salesforce Industry Cloud: Five Zero-Days, Over 15 Misconfigurations Researchers have uncovered **five zero-days** and 15+ misconfiguration risks in Salesforce’s cloud CRM offerings, potentially exposing sensitive customer data across multiple verticals (healthcare, finance, etc.). **Action:** If you use Salesforce Industry Clouds, review latest vendor advisories, audit configurations, and apply all available fixes. - [SecurityWeek’s report](https://www.securityweek.com/five-zero-days-15-misconfigurations-found-in-salesforce-industry-cloud/) - [The Hacker News explanation](https://thehackernews.com/2025/06/researchers-uncover-20-configuration.html) #### Major Data Breach: 300,000 Texas Crash Reports Stolen Texas DOT confirmed a breach of its Crash Records Information System, exposing 300,000 crash reports with driver PII. TTPs suggest credential compromise, with threat of financial and targeting fraud. **Action:** Texas entities and affected individuals are urged to monitor for identity theft and review security around high-value databases. - [Bleeping Computer coverage](https://www.bleepingcomputer.com/news/security/texas-dept-of-transportation-breached-300k-crash-records-stolen/) - [The Register details](https://go.theregister.com/feed/www.theregister.com/2025/06/10/texas_accident_report_theft/) #### OpenAI, Nation-State Abuse, and AI Security OpenAI shut down 10 networks using generative AI for malicious activities, with operations linked to China, Russia, Iran, and North Korea. Meanwhile, 86% of LLM traffic is now ChatGPT, driving concerns around data sovereignty, tracking, and incident response. - [HackRead report](https://hackread.com/openai-shuts-down-ai-ops-china-russia-iran-nkorea/) - [HelpNetSecurity on LLM usage](https://www.helpnetsecurity.com/2025/06/11/chatgpt-usage-2025/) #### More Headlines Cyber Pros Should Note - **Adobe Patch Tuesday:** 254 vulnerabilities fixed across Experience Manager, Acrobat, InDesign. Some XSS and code execution rated Critical. [Details](https://thehackernews.com/2025/06/adobe-releases-patch-fixing-254.html) - **SINOTRACK GPS Vulnerabilities:** Flaws enable remote control and tracking of vehicles. [The Hacker News](https://thehackernews.com/2025/06/sinotrack-gps-devices-vulnerable-to.html) - **40,000 Exposed Security Cameras:** IoT cameras worldwide streaming unprotected feeds—including sensitive sites like factories and hospitals. [CyberNews](https://cybernews.com/security/researchers-find-thousands-exposed-security-cameras/) - **FIN6 Hacking Group:** Social engineering job recruiters via malware-laced resumes (More_eggs/“Skeleton Spider” campaign). [The Hacker News](https://thehackernews.com/2025/06/fin6-uses-aws-hosted-fake-resumes-on.html) - **SAP NetWeaver Critical Flaw Patched:** Privilege escalation, CVE-2025-42989, hotfix issued. [SecurityWeek](https://www.securityweek.com/critical-vulnerability-patched-in-sap-netweaver/) --- ### You May Also Be Interested In... - **“Peep show: 40K IoT cameras worldwide stream secrets to anyone with a browser”** [The Register](https://www.theregister.com/2025/06/10/40000_iot_cameras_exposed/) - **“Trump guts digital ID rules, claims they help 'illegal aliens' commit fraud”** [The Register](https://go.theregister.com/feed/www.theregister.com/2025/06/10/trump_cybersecurity_eo_digital_ids/) - **“Quasar RAT Delivered Through Bat Files”** [SANS ISC](https://isc.sans.edu/diary/rss/32036) - **“AI is a data-breach time bomb, reveals new report”** [Bleeping Computer](https://www.bleepingcomputer.com/news/security/ai-is-a-data-breach-time-bomb-reveals-new-report/) - **“Ransomware Attack Hits Sensata, Data Stolen”** [SecurityWeek](https://www.securityweek.com/sensitive-information-stolen-in-sensata-ransomware-attack/) --- **Stay patched, scrutinize cloud and IoT exposures, and be mindful of evolving supply chain and social engineering threats. For detailed technical breakdowns, see linked sources.**
Cybersecurity — June 11, 2025 | Briefing24