THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗
**Cybersecurity Daily Briefing – June 14, 2025** --- ### Top Stories #### Apple Patches Zero-Click Exploit Used in Spyware Attacks on Journalists Apple has patched a high-severity zero-click vulnerability (CVE-2025-43200) in its Messages app that was actively exploited to deliver Paragon's "Graphite" spyware. Devices could be infected simply by receiving a malicious image or video—no user interaction required. Citizen Lab confirmed at least two European journalists’ iPhones were compromised in a targeted campaign attributed to mercenary spyware vendors. If you haven’t updated, patch your Apple devices immediately. - [Full details (Help Net Security)](https://www.helpnetsecurity.com/2025/06/13/ios-zero-click-attacks-used-to-deliver-graphite-spyware-cve-2025-43200/) - [Apple statement (Security Affairs)](https://securityaffairs.com/178962/mobile-2/apple-confirmed-messages-app-flaw-actively-exploited.html) - [Citizen Lab forensic findings (Schneier Blog)](https://www.schneier.com/blog/archives/2025/06/paragon-spyware-used-to-spy-on-european-journalists.html) #### Ransomware Actors Target SimpleHelp RMM Vulnerability in Retail Attacks CISA warns that ransomware gangs are actively exploiting unpatched instances of the SimpleHelp remote monitoring tool, leading to a series of double extortion attacks in the retail sector. Successful intrusions have resulted in service outages and data theft, emphasizing the critical importance of timely patching. - [CISA alert (The Record)](https://therecord.media/cisa-warns-of-simplehelp-ransomware-compromises) - [Technical details (The Hacker News)](https://thehackernews.com/2025/06/ransomware-gangs-exploit-unpatched.html) #### Trend Micro Fixes Multiple Critical Vulnerabilities — Patch Now Trend Micro has issued urgent patches for Apex Central and Endpoint Encryption PolicyServer, addressing several critical flaws (including multiple RCE and authentication bypass vulnerabilities). No in-the-wild exploitation observed yet, but exposure could allow attackers to take full control of affected appliances. - [Vendor advisory & security bulletin (Security Week)](https://www.securityweek.com/critical-vulnerabilities-patched-in-trend-micro-apex-central-endpoint-encryption-policyserver/) - [SOC Radar summary](https://socradar.io/trend-micro-fixes-rce-apex-central-tmee-policyserver/) #### Discord Flaw Lets Hackers Reuse Expired Invites to Distribute Malware Threat actors are hijacking expired or deleted Discord invite links to redirect users to malicious sites, distributing AsyncRAT and infostealers targeting crypto wallets. The mechanism abuses "vanity URL" registration and could make previously ‘safe’ links a new avenue for attacks, so monitor old invite links and alert users. - [Bleeping Computer coverage](https://www.bleepingcomputer.com/news/security/discord-flaw-lets-hackers-reuse-expired-invites-in-malware-campaign/) - [Technical analysis and mitigations (The Hacker News)](https://thehackernews.com/2025/06/discord-invite-link-hijacking-delivers.html) #### Massive Data Breach Hits Paraguay: 7.4 Million Citizen Records on Dark Web Resecurity uncovered 7.4 million records with PII of Paraguayan citizens for sale online, potentially exposing most of the country’s population. Given the sensitivity and volume, expect widespread targeting of identity and financial fraud. - [Coverage (Security Affairs)](https://securityaffairs.com/178970/data-breach/paraguay-suffered-data-breach-7-4-million-citizen-records-leaked-on-dark-web.html) #### ‘SmartAttack’: Smartwatches Used for Air-Gapped Data Exfiltration Researchers have uncovered a novel attack dubbed "SmartAttack," where smartwatches are harnessed for exfiltrating data from air-gapped systems via covert channels. While still a proof-of-concept, this underscores the expanding threat landscape posed by IoT devices even in secured environments. - [Attack details (SC Magazine)](https://www.scworld.com/news/smartwatches-tabbed-as-latest-vehicle-for-air-gapped-system-attacks) - [Related coverage (Forbes)](https://www.forbes.com/sites/daveywinder/2025/06/13/how-hackers-use-a-smartwatch-to-steal-highly-confidential-data/) #### Meta AI Chats Could Be Public by Default A privacy warning: Researchers have found that Meta AI conversations are being shared publicly by default, leading unwitting users—including those discussing sensitive topics—to inadvertently expose conversations online. - [Malwarebytes Blog report](https://www.malwarebytes.com/blog/news/2025/06/your-meta-ai-chats-might-be-public-and-its-not-a-bug) --- ### Quick Hits & Emerging Threats - **New Predator Spyware Activity:** Intellexa’s Predator spyware, previously sanctioned, is resurging with upgraded obfuscation tactics. [Details (SCM)](https://www.scworld.com/brief/new-predator-spyware-activity-identified) - **AI Moderation Bypassed:** TokenBreak, a novel technique, can defeat AI content moderation and guardrails in LLMs. [Analysis (SCM)](https://www.scworld.com/brief/ai-moderation-guardrails-circumvented-by-novel-tokenbreak-attack) - **Ransomware Hits Food Supply:** A cyberattack on United Natural Foods disrupted Whole Foods’ bread deliveries nationwide. [Story (Security Affairs)](https://securityaffairs.com/178991/hacking/a-cyberattack-on-united-natural-foods-caused-bread-shortages-and-bare-shelves.html) - **Microsoft Entra ID Campaigns:** Over 80,000 enterprise accounts targeted in global attack using TeamFiltration tool—defenders urged to check for signs of compromise. [More (Security Week)](https://www.securityweek.com/teamfiltration-abused-in-entra-id-account-takeover-campaign/) - **Apple/Google Store VPNs Linked to China:** Dozens of VPN apps in US app stores have undisclosed Chinese ownership, raising significant privacy risks. [More (CyberNews)](https://cybernews.com/security/apple-google-app-stores-host-chinese-vpns/) - **Cloud Outages:** A Google Cloud outage due to API mismanagement caused multi-platform disruptions. [More (BleepingComputer)](https://www.bleepingcomputer.com/news/google/google-links-massive-cloud-outage-to-api-management-issue/) --- ### Policy & Industry - **Denmark Moves to LibreOffice for Digital Sovereignty:** The Danish government is ditching Microsoft Office for open-source alternatives, citing risks from overdependence on US tech. [Story (The Record)](https://therecord.media/denmark-digital-agency-microsoft-digital-independence) - **Critical Vulnerabilities in Government Systems Unresolved:** Survey finds almost 80% of government agencies have left vulnerabilities unpatched for over a year. [SCMagazine report](https://www.scworld.com/brief/report-government-system-vulnerabilities-often-unresolved) - **Secure by Design Not Enough:** CISA stresses that securing software at design time must be followed by ongoing threat monitoring. [More (NextGov)](https://www.nextgov.com/cybersecurity/2025/06/secure-design-just-start-cisa-official-says/406063/) - **Trump Administration EO on Cybersecurity:** Industry responses highlight tension between new requirements and existing best practices. [Feedback round-up (Security Week)](https://www.securityweek.com/industry-reactions-to-trump-cybersecurity-executive-order-feedback-friday/) --- ### You May Also Be Interested In... - **Google Details Layered AI Prompt Injection Defenses** [Mitigating prompt injection in Gemini and Workspace apps (Google Security Blog)](http://security.googleblog.com/2025/06/mitigating-prompt-injection-attacks.html) - **40,000 IoT Security Cameras Exposed Online** [Research highlights global surveillance risk (InfosecurityMagazine)](https://www.securitymagazine.com/articles/101692-40-000-iot-security-cameras-are-exposed-online) - **JSFireTruck Campaign Infects 269,000+ Websites in a Month** [Palo Alto’s Unit 42 research (The Hacker News)](https://thehackernews.com/2025/06/over-269000-websites-infected-with.html) - **StackHawk Launches Sensitive Data ID for API Security** [Help Net Security](https://www.helpnetsecurity.com/2025/06/13/stackhawk-sensitive-data-identification/) --- **Stay vigilant. Patch, educate, monitor — and don’t forget to update your threat models for new attack surfaces like AI, cloud, and IoT.**
Cybersecurity — June 14, 2025 | Briefing24