## Cybersecurity Daily Briefing – June 13, 2025
### Major Developments & Emerging Threats
#### **1. Paragon ‘Graphite’ Spyware Confirmed in Zero-Click iOS Journalist Attacks**
A Citizen Lab forensic investigation has confirmed Israeli firm Paragon’s “Graphite” spyware was used in targeted, zero-click attacks against European journalists—compromising even fully-updated iPhones through an Apple Messages flaw (CVE-2025-43200). Apple discreetly patched the bug in February, but revelations deepen concerns over the proliferation of nation-state-grade surveillance tools. [Read more: SecurityWeek](https://www.securityweek.com/paragon-graphite-spyware-linked-to-zero-click-hacks-on-newest-iphones/) | [Citizen Lab](https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/) | [TechCrunch](https://techcrunch.com/2025/06/12/researchers-confirm-two-journalists-were-hacked-with-paragon-spyware/)
#### **2. Critical ‘EchoLeak’ Zero-Click AI Flaw Hit Microsoft 365 Copilot**
Microsoft patched CVE-2025-32711, a “zero-click” vulnerability dubbed EchoLeak in the Microsoft 365 Copilot AI assistant. Attackers could steal sensitive data via email with no interaction required—posing major risks for enterprises adopting AI tools for daily workflows. All organizations using Copilot should ensure they’ve updated. [More: SecurityWeek](https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/) | [TheHackerNews](https://thehackernews.com/2025/06/zero-click-ai-vulnerability-exposes.html) | [CyberNews](https://cybernews.com/security/clever-attack-makes-microsoft-copilot-spy-on-users/)
#### **3. Unpatched SimpleHelp RMM Exploited in Utility Service Ransomware Attacks**
CISA warns of active exploitation of unpatched SimpleHelp remote monitoring & management (RMM) software, resulting in ransomware attacks and service disruptions at utility billing providers. Patch issued in January, but lagging updates leave organizations at continued risk. [Details: SecurityWeek](https://www.securityweek.com/simplehelp-vulnerability-exploited-against-utility-billing-software-users/) | [The Register](https://go.theregister.com/feed/www.theregister.com/2025/06/12/cisa_simplehelp_flaw_exploit_warning/)
#### **4. Discord Invite System Abuse Enables Stealthy Multi-Stage Attacks**
Researchers uncovered a global threat campaign abusing Discord's invite system, allowing threat actors to “reanimate” expired/deleted invites and redirect users to malicious servers. Sophisticated multi-stage attacks leverage fake bots, phishing, and legitimate services like GitHub to hide malware delivery—mainly targeting cryptocurrency users. [Read: Check Point](https://blog.checkpoint.com/research/hijacked-trust-how-malicious-actors-exploited-discords-invite-system-to-launch-global-multi-stage-attacks/) | [CyberNews](https://cybernews.com/security/hackers-steal-and-reanimate-discord-invite-links/)
#### **5. LockBit Panel Leak Exposes Ransomware’s Reach in China**
A major leak of LockBit’s affiliate panel data shows that Chinese organizations are now among the most targeted by the notorious RaaS operation. Leaked financials offer insight into the operation's true profitability and international focus. [Coverage: HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/12/lockbit-data-leak-targets-ransoms/)
#### **6. Over 80,000 Microsoft Entra ID Accounts Targeted via TeamFiltration Framework**
A surge in brute-force attacks is targeting Microsoft Entra ID (formerly Azure AD) using the open-source TeamFiltration pentesting tool. Hundreds of organizations are affected—a reminder to review access controls and MFA settings. [Details: BleepingComputer](https://www.bleepingcomputer.com/news/security/password-spraying-attacks-target-80-000-microsoft-entra-id-accounts/) | [HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/12/researchers-warn-of-ongoing-entra-id-account-takeover-campaign/)
---
### High-Impact Vulnerabilities & Patching News
- **Trend Micro patches critical remote code execution flaws impacting Apex Central & Endpoint Encryption PolicyServer products. Immediate update strongly advised.**
- [SecurityWeek](https://www.securityweek.com/critical-vulnerabilities-patched-in-trend-micro-apex-central-endpoint-encryption-policyserver/)
- [BleepingComputer](https://www.bleepingcomputer.com/news/security/trend-micro-fixes-six-critical-flaws-on-apex-central-endpoint-encryption-policyserver/)
- **CoreDNS issued fix for CVE-2025-47950, a server crash flaw in DNS-over-QUIC. Patch now.** [SCMagazine](https://www.scworld.com/brief/coredns-addresses-flaw-enabling-server-crashes)
- **Fortinet released 14 vulnerability fixes across multiple products as part of Patch Tuesday.** [SCMagazine](https://www.scworld.com/brief/over-a-dozen-fortinet-vulnerabilities-fixed)
- **Mitel MiCollab vulnerabilities allow unauthenticated remote hacking—ensure affected systems are patched.** [SecurityWeek](https://www.securityweek.com/critical-vulnerability-exposes-many-mitel-micollab-instances-to-remote-hacking/)
---
### Policy & Guidance
- **NIST Releases Practical Zero Trust Implementation Guide.**
NIST has published SP 1800‑35, offering 19 real-world examples of zero trust architectures using off-the-shelf tools. Strong resource for organizations progressing from theory to implementation. [Read: HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/13/zero-trust-implementation-guide/) | [CISO2CISO](https://ciso2ciso.com/nist-publishes-new-zero-trust-implementation-guidance-source-www-infosecurity-magazine-com/)
---
### Ransomware, Malware & Surveillance
- **Operation Secure: INTERPOL takes down 20,000 infostealer IPs in Asia, claiming 32 arrests and notifying over 200,000 victims.** [SecurityWeek](https://www.securityweek.com/interpol-targets-infostealers-20000-ips-taken-down-32-arrested-216000-victims-notified/)
- **Fog ransomware incident in Asia deployed legitimate employee monitoring software and other novel, legitimate tools, raising concerns over detection of “grayware” in attacks.** [SecurityWeek](https://www.securityweek.com/fog-ransomware-attack-employs-unusual-tools/) | [BleepingComputer](https://www.bleepingcomputer.com/news/security/fog-ransomware-attack-uses-unusual-mix-of-legitimate-and-open-source-tools/)
- **VexTrio operation linked to massive WordPress site exploitation and a global ad fraud network.** [TheHackerNews](https://thehackernews.com/2025/06/wordpress-sites-turned-weapon-how.html) | [KrebsOnSecurity: AdTech Empire](https://krebsonsecurity.com/2025/06/inside-a-dark-adtech-empire-fed-by-fake-captchas/)
---
### Noteworthy Data Leaks, Exposures & Systemic Risks
- **Over 40,000 internet-connected security cameras globally are vulnerable to remote hacking; US leads in unprotected feeds.** [Security Affairs](https://securityaffairs.com/178908/iot/40000-security-cameras-remote-hacking.html) | [HackRead](https://hackread.com/us-tops-list-unsecured-cameras-exposing-homes-offices/)
- **Two critical flaws in SinoTrack GPS devices expose vehicles to remote tracking and control.** [Security Affairs](https://securityaffairs.com/178922/security/sinotrack-gps-device-flaws-allow-remote-vehicle-control-and-location-tracking.html) | [SCMagazine](https://www.scworld.com/brief/cisa-significant-flaws-impacting-sinotrack-gps-devices/)
- **Major compromise at UK NHS temp staffing body (NHS Professionals)—Active Directory database stolen, highlighting serious organizational security gaps.** [The Register](https://www.theregister.com/2025/06/12/compromise_nhs_professionals/)
---
### Industry Trends & Insights
- **API Security Blind Spots:** StackHawk launches tools for sensitive data identification across APIs, addressing the chronic lack of API visibility in large organizations. [HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/13/stackhawk-sensitive-data-identification-provides-visibility-into-high-risk-apis/)
- **No-Code & Agentic AI Risks:** CISOs urged to evaluate security implications of agentic AI and abstraction layers in no-code/low-code platforms. [HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/13/amichai-shulman-nokod-security-no-code-environments-security/) [HelpNetSecurity: Agentic AI](https://www.helpnetsecurity.com/2025/06/13/ciso-agentic-ai/)
- **Public Sector Lags in Patch Timelines:** 78% of public organizations operate with critical flaws unpatched for >1 year. [HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/13/public-sector-software-vulnerabilities/)
---
### **You May Also Be Interested In...**
- **Interpol Targets Infostealers: 20,000 IPs Taken Down**
[SecurityWeek](https://www.securityweek.com/interpol-targets-infostealers-20000-ips-taken-down-32-arrested-216000-victims-notified/)
- **Operation Practical Zero Trust: NIST Releases New Guidance**
[HelpNetSecurity](https://www.helpnetsecurity.com/2025/06/13/zero-trust-implementation-guide/)
- **EchoLeak Puts Microsoft 365 Copilot in the Spotlight**
[SecurityWeek](https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/)
- **VexTrio: WordPress Sites Repurposed for Global Scams**
[TheHackerNews](https://thehackernews.com/2025/06/wordpress-sites-turned-weapon-how.html)
- **New Attack Bypasses LLM Moderation Using Tiny Text Changes**
[TheHackerNews](https://thehackernews.com/2025/06/new-tokenbreak-attack-bypasses-ai.html)
- **June Patch Tuesday: 67 Bugs Remediated**
[Sophos](https://news.sophos.com/en-us/2025/06/13/june-patch-tuesday-digs-into-67-bugs/)
---
Stay vigilant, prioritize critical patching, and review AI tool integrations for new classes of risk.
*Curated by the Cybersecurity Daily Newsroom — for feedback or tip submissions, contact our editorial team.*