THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
UK Fines 23andMe £2.3 Million for Major Data Breach

The UK Information Commissioner’s Office has fined genetic testing giant 23andMe £2.31 million ($3.12 million) following a 2023 cyberattack that exposed genetic data for millions of users. The breach underscored critical lapses in data security controls for sensitive information, raising questions about industry-wide protections for special category data and consent practices.

Source: Bleeping Computer


Critical Veeam Backup & Replication Flaw Allows Remote Code Execution

Veeam has patched a severe vulnerability (CVE-2025-23121, CVSS 9.9) in its Backup & Replication product that allows authenticated domain users to execute code remotely on backup servers. This vulnerability puts backup infrastructure—often the last line of defense against ransomware—at increased risk. Immediate action is advised to apply the patches.

Source: Bleeping Computer


Scattered Spider Hackers Pivot to US Insurance Sector After Retail Attacks

Google’s Threat Intelligence Group and other sources have issued warnings as the notorious “Scattered Spider” group shifts its focus toward insurance companies, following high-profile attacks on retail targets. Incidents indicate sophisticated social engineering used to breach help desks, with ransomware disruptions impacting firms like Erie Insurance and threatening sector-wide outages.

Source: CyberNews


TP-Link Router and Apple Product Flaws Added to CISA’s Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added AI-exploited flaws affecting Apple products and several discontinued TP-Link router models to its KEV catalog. These actively exploited vulnerabilities present significant risks for organizations still relying on legacy devices, underlining the urgent need for patching or replacing unsupported hardware.

Source: Security Affairs


Sitecore CMS Pre-Auth RCE Flaw Threatens Enterprise Deployments

Security researchers have disclosed a critical exploit chain in Sitecore Experience Platform allowing unauthenticated remote code execution using a hardcoded password. Enterprises using Sitecore are urged to address these vulnerabilities rapidly, as this CMS is widely deployed by major global organizations for content management and marketing.

Source: TheHackerNews


Langflow AI Server Vulnerability Exploited by Flodrix Botnet for DDoS Attacks

A recently patched remote code execution flaw in the Langflow AI platform is being actively exploited to deliver the Flodrix botnet, which is then used for distributed denial-of-service (DDoS) assaults. The campaign highlights growing attacker focus on AI and ML platforms as target vectors, and the need for swift response to vulnerabilities in emerging technologies.

Source: SecurityWeek


Taiwan Organizations Targeted by Sophisticated Phishing Campaigns Deploying Custom Malware

FortiGuard Labs has uncovered a coordinated phishing attack against companies in Taiwan using tax-themed lures. Attackers deploy custom malware—such as Winos 4.0 and HoldingHands RAT—designed for persistent access. This campaign points to the escalating sophistication and persistence of regional cyber threats linked to geopolitics.

Source: Fortinet


You May Also Be Interested In...
Cybersecurity — June 18, 2025 | Briefing24