THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
## Daily Cybersecurity Briefing – June 15, 2025 ### Microsoft Patches Exploited Zero-Day; Mirai Botnets Target Wazuh Servers **Microsoft has addressed a zero-day vulnerability (CVE-2025-33053) actively exploited for cyber espionage. Additionally, researchers warn that Mirai botnets are exploiting a critical remote code execution flaw (CVE-2025-24016) in unpatched Wazuh XDR/SIEM servers.** Recommended action: Patch all affected Microsoft products and update Wazuh servers immediately. [Full story](https://www.helpnetsecurity.com/2025/06/15/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/) (HelpNet Security) --- ### FBI Issues Smartphone Warning – Malicious Text Campaigns Surge **The FBI warns that millions of malicious texts targeting both iPhone and Android users are circulating, urging recipients to delete such messages immediately.** These scams often attempt credential theft and malware installation. [Full story](https://www.forbes.com/sites/zakdoffman/2025/06/15/fbi-confirms-iphone-and-android-warning-delete-these-new-texts/) (Forbes Security) --- ### Google Urges 2 Billion Gmail Users to Reset Passwords **Google is telling all Gmail users to change their passwords now due to ongoing credential-stuffing attacks and security threats.** [Full story](https://www.forbes.com/sites/daveywinder/2025/06/14/change-your-gmail-password-now-google-tells-2-billion-users/) (Forbes Security) --- ### Critical Updates for Google Messages and Popular Mobile Apps **Over 1 billion users are affected by a security update to Google Messages aimed at closing a critical vulnerability.** Experts also urge users to urgently update specific apps exposing sensitive data. - [Google Messages update](https://www.forbes.com/sites/daveywinder/2025/06/15/critical-google-messages-security-update-for-1-billion-users-confirmed/) (Forbes) - [High-risk app list](https://www.forbes.com/sites/zakdoffman/2025/06/15/update-every-app-on-your-phone-thats-on-this-list/) (Forbes) --- ### Major Data Breach: 7.4 Million Paraguayan Citizen Records Leaked **PII of 7.4 million Paraguayan citizens has appeared for sale on the dark web, exposing sensitive information to cybercriminals.** This sizable leak demonstrates ongoing global risks of mass data exposure. [Full story](https://ciso2ciso.com/paraguay-suffered-data-breach-7-4-million-citizen-records-leaked-on-dark-web-source-securityaffairs-com/) (CISO2CISO / Security Affairs) --- ### Apple Messages Zero-Day Actively Exploited **Apple has confirmed that a now-patched vulnerability (CVE-2025-43200) in its Messages app was actively exploited to target journalists, likely via Paragon’s Graphite spyware.** Update all Apple devices promptly to secure against this threat. [Full story](https://ciso2ciso.com/apple-confirmed-that-messages-app-flaw-was-actively-exploited-in-the-wild-source-securityaffairs-com/) (CISO2CISO / Security Affairs) --- ### CISA Warns: Ransomware Targeting SimpleHelp RMM **CISA is tracking a “pattern” of ransomware attacks exploiting SimpleHelp remote monitoring and management (RMM) platforms.** Organizations using SimpleHelp should review security configurations and monitor for compromise. [Full story](https://ciso2ciso.com/cisa-reveals-pattern-of-ransomware-attacks-against-simplehelp-rmm-source-www-darkreading-com/) (CISO2CISO / Dark Reading) --- ### WestJet Hit by Cyberattack, Operations Disrupted **Canada’s second-largest airline, WestJet, is investigating a cyberattack that has caused internal system outages.** Affects ticketing, operations, and potentially customer data. [Full story](https://www.bleepingcomputer.com/news/security/westjet-investigates-cyberattack-disrupting-internal-systems/) (BleepingComputer) --- ### Ransomware Trends: Fog Attackers Use Unusual Toolset; Anubis Adds Wiper - **Fog Ransomware** operators recently used uncommon penetration testing and monitoring tools in a targeted attack, complicating defense and detection. [Full story](https://ciso2ciso.com/unusual-toolset-used-in-recent-fog-ransomware-attack-source-securityaffairs-com/) (CISO2CISO / Security Affairs) - **Anubis Ransomware** now includes a wiper module: paying the ransom won’t restore your files. [Full story](https://www.bleepingcomputer.com/news/security/anubis-ransomware-adds-wiper-to-destroy-files-beyond-recovery/) (BleepingComputer) --- ### Policy & Vulnerability Updates - **Trend Micro** has patched critical vulnerabilities (RCE, authentication bypass) in Apex Central and Endpoint Encryption platforms. [Details](https://ciso2ciso.com/trend-micro-fixes-critical-bugs-in-apex-central-and-tmee-policyserver-source-securityaffairs-com/) (CISO2CISO / Security Affairs) - **Palo Alto Networks** fixed multiple privilege escalation flaws and integrated Chrome security patches. [Details](https://securityaffairs.com/179000/security/palo-alto-networks-fixed-multiple-privilege-escalation-flaws.html) (Security Affairs) - **TeamFiltration** pentesting tool abused in large-scale Entra ID account takeover campaigns. [Details](https://ciso2ciso.com/teamfiltration-abused-in-entra-id-account-takeover-campaign-source-www-securityweek-com/) (CISO2CISO / SecurityWeek) --- ### Industry Tools & Research - **Kali Linux 2025.2** now available with Bloodhound CE, CARsenal, and 13 new security tools. [Release details](https://www.helpnetsecurity.com/2025/06/14/kali-linux-2025-2-released-bloodhound-ce-carsenal/) (Help Net Security) - **GenAI-powered Attacks:** Criminals are rapidly leveraging generative AI for deepfakes, malware, and social engineering, straining security guardrails. [Analysis](https://www.govtech.com/blogs/lohrmann-on-cybersecurity/guardrails-breached-the-new-reality-of-genai-driven-attacks) (GovTech) --- ### You May Also Be Interested In… - [Simple Click on Malicious Link Exposes Precise Geolocation](https://cybernews.com/security/phishing-exposes-precise-smartphone-geolocation/) — Social engineering tricks smartphone users into sharing real-time location. (CyberNews) - [New Way to Covertly Track Android Users](https://ciso2ciso.com/new-way-to-covertly-track-android-users-source-www-schneier-com/) — Researchers expose tracking methods used by Meta & Yandex. (Schneier) - [Discord Invite Link Hijacking Delivers Malware](https://ciso2ciso.com/discord-invite-link-hijacking-delivers-asyncrat-and-skuld-stealer-targeting-crypto-wallets-sourcethehackernews-com/) — Vanity link abuse targets crypto wallets. (The Hacker News) - [How to Delete Your 23andMe Data](https://techcrunch.com/2025/06/14/23andme-files-for-bankruptcy-how-to-delete-your-data/) — Privacy after 23andMe’s bankruptcy and breaches. (TechCrunch) - [Dutch Police Identify Young Users on Hacking Forum](https://ciso2ciso.com/dutch-police-identify-users-as-young-as-11-year-old-on-cracked-io-hacking-forum-source-www-bitdefender-com/) — Law enforcement tracks users as young as 11 on cracked.io. (Bitdefender) --- Stay patched and stay vigilant! *— The Cybersecurity Daily Briefing Team*
Cybersecurity — June 15, 2025 | Briefing24