THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
### Daily Cybersecurity Briefing — June 16, 2025 --- ### Major Ransomware Threat: Anubis Wiper Permanently Deletes Files The new Anubis ransomware variant is escalating danger for enterprise and consumer environments alike, now featuring wiper capabilities that make file recovery virtually impossible. Victims not only face extortion but the risk of irretrievable data loss. Organizations should review their incident response plans and ensure robust, tested backups are in place. - [Read more at SecurityWeek](https://www.securityweek.com/anubis-ransomware-packs-a-wiper-to-permanently-delete-files/) - [Forbes coverage: Backup now](https://www.forbes.com/sites/daveywinder/2025/06/16/this-new-ransomware-can-irrevocably-destroy-your-files---backup-now/) --- ### Predator Spyware Reemerges Despite Sanctions Commercial spyware Predator is back in the spotlight as researchers reveal new infrastructure and client activity in Mozambique, showing ongoing global proliferation despite US sanctions. Predator has been used for targeted surveillance, raising concerns for governments and private-sector targets. - [Details via Security Affairs](https://securityaffairs.com/179036/hacking/new-predator-spyware-infrastructure-revealed-activity-in-mozambique-for-first-time.html) --- ### WestJet Hit by Cyberattack Canada’s second-largest airline, WestJet, has confirmed it fell victim to a cyberattack affecting its internal systems and customer app. This incident underscores persistent threats facing the aviation sector and critical infrastructure. - [Coverage at SecurityWeek](https://www.securityweek.com/canadian-airline-westjet-hit-by-cyberattack/) - [More via Security Affairs](https://securityaffairs.com/179027/uncategorized/canadas-airline-westjet-is-containing-a-cyberattack.html) --- ### High-Severity Flaws Patched in Tenable Nessus Agent Tenable has released fixes for three high-severity vulnerabilities in its Nessus Agent, allowing for arbitrary code execution and file system manipulation with SYSTEM privileges. Cybersecurity professionals should prioritize updating to the latest versions to protect assessment and vulnerability management infrastructure. - [Patch advisory: SecurityWeek](https://www.securityweek.com/high-severity-vulnerabilities-patched-in-tenable-nessus-agent/) --- ### Supply Chain Attacks Target Open Source and Developer Ecosystems - Malicious PyPI package “chimera-sandbox-extensions” impersonates legitimate modules to capture AWS keys and sensitive environment data. - [TheHackerNews details](https://thehackernews.com/2025/06/malicious-pypi-package-masquerades-as.html) - Trend Micro exposes “Water Curse” — a group using GitHub repositories to spread weaponized open-source malware. - [Trend Micro MDR Analysis](https://www.trendmicro.com/en_us/research/25/f/water-curse.html) --- ### Mirai Botnets Exploiting Critical Wazuh XDR Vulnerability Active exploitation of a critical RCE flaw (CVE-2025-24016) in the Wazuh XDR/SIEM platform is being driven by at least two Mirai-based botnets. Immediate patching is urged for any unpatched Wazuh servers. - [Review at HelpNet Security](https://www.helpnetsecurity.com/2025/06/15/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/) --- ### New Data Breaches: T-Mobile US, SAP Israel, OKX, Vodafone Egypt & Major Apps Threat actors are claiming leaks or sales of user data involving Vodafone Egypt, SAP Israel, OKX, and T-Mobile US. Separately, India’s Zoomcar and VirtualMacOSX have reported breaches impacting millions. - [SOCRadar Intel](https://socradar.io/leak-vodafone-egypt-sap-israel-okx-and-t-mobile-us/) - [Zoomcar breach: CyberNews](https://cybernews.com/security/zoomcar-data-breach-millions-exposed/) - [VirtualMacOSX: HackRead](https://hackread.com/hackers-leak-virtualmacosx-customers-data-breach/) --- ### India’s Data Protection Law Imposes Stiff Penalties India’s Digital Personal Data Protection (DPDP) Act, 2023, introduces tough new compliance rules and fines. Security teams across industries handling Indian data should review policies and practices to ensure alignment. - [Tripwire coverage & CISO perspective](https://www.tripwire.com/state-of-security/brace-yourselves-game-changing-impact-indias-dpdp-act) --- ### CISOs: Understanding the AI Tech Stack and Red Teaming AI As AI becomes ubiquitous, security leaders are increasingly asked to guard systems they may not fully grasp. Recent resources and debates address how to secure the “AI tech stack,” and whether to build or buy red teaming frameworks for AI risks. - [CISO perspective: HelpNet Security](https://www.helpnetsecurity.com/2025/06/16/ciso-ai-tech-stack/) - [Red Teaming AI: SecurityWeek](https://www.securityweek.com/red-teaming-ai-the-build-vs-buy-debate/) --- ### You May Also Be Interested In… - [Microsoft fixes zero-day exploited in cyber espionage (CVE-2025-33053)](https://www.helpnetsecurity.com/2025/06/15/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/) - [Over 46,000 Grafana instances exposed to account takeover bug](https://www.bleepingcomputer.com/news/security/over-46-000-grafana-instances-exposed-to-account-takeover-bug/) - [Dutch police round up 126 users of hacking forum Cracked.io; 11-year-old among suspects](https://cybernews.com/security/dutch-police-interrogate-cracked-forum-users/) - [Dems demand audit of US CVE program as federal funding uncertain](https://go.theregister.com/feed/www.theregister.com/2025/06/15/cybersecurity_news_in_brief/) - [Google urges 2 billion Gmail users to change passwords amid new attacks](https://www.forbes.com/sites/daveywinder/2025/06/15/change-your-gmail-password-now-google-tells-2-billion-users/) --- **Stay vigilant and patch promptly. For more, follow the links above and subscribe for tomorrow’s top headlines.**
Cybersecurity — June 16, 2025 | Briefing24