THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Linux Vulnerabilities Enable Root Access Across Major Distributions

Researchers have discovered two critical local privilege escalation vulnerabilities—CVE-2025-6018 and CVE-2025-6019—that allow attackers to gain root access on major Linux distributions. These flaws can be chained, letting unprivileged users escalate privileges, impacting the security posture of countless systems worldwide and underscoring the urgent need for immediate patching and monitoring for exploitation.

Source: Security Affairs


Massive 16 Billion Credential Exposure—Not New, Still Dangerous

Researchers report a staggering 16 billion login credentials recently found online, likely harvested over time by infostealers and compiled from multiple breaches. While many are previously leaked, this “mother of all breaches” is a stark warning about password reuse and the continued risk to enterprises and individuals from credential stuffing attacks.

Source: Bleeping Computer


Cloudflare Blocks Largest-Ever DDoS Attack at 7.3 Tbps

Cloudflare reports successfully mitigating a record-breaking distributed denial-of-service (DDoS) attack peaking at 7.3 terabits per second, delivering 37.4 terabytes in under a minute. The attack, which targeted a hosting provider, highlights the rising scale of DDoS threats against infrastructure providers and the necessity for robust distributed defense mechanisms.

Source: TheHackerNews


China-linked Salt Typhoon Group Breaches Viasat Satellite Networks

The Salt Typhoon APT, attributed to China, has successfully hacked into the networks of global satellite communications firm Viasat. This breach, part of a wider campaign targeting the telecoms sector, underlines the strategic value of satellite networks in cyber-espionage and the persistent vulnerability of critical infrastructure to state-backed actors.

Source: Bleeping Computer


Krispy Kreme Discloses Breach Impacting Over 160,000 Individuals

Krispy Kreme has confirmed that its November 2024 ransomware attack led to the breach of sensitive personal and financial data belonging to more than 160,000 people. The incident took months to investigate and demonstrates ongoing risks of data theft, identity fraud, and the need for continuous security improvements in consumer-facing enterprises.

Source: SecurityWeek


AI-Powered Coding Assistants Introduce Software Supply Chain Risks

The growing reliance on AI-based coding tools like GitHub Copilot and ChatGPT streamlines development but poses new software supply chain risks. Research highlights that “hallucinated” code suggestions may prompt developers to import non-existent—or even malicious—dependencies, increasingly opening the door to supply chain compromise.

Source: Checkpoint Blog


Banana Squad Campaign Drops Data-Stealers via Fake GitHub Repositories

Security researchers have uncovered a campaign—dubbed "Banana Squad"—using more than 67 trojanized GitHub repositories to distribute data-stealing malware disguised as Python-based hacking tools. The operation targets both developers and gamers, underlining the escalating abuse of open-source platforms for malware distribution and supply chain infiltration.

Source: TheHackerNews


You May Also Be Interested In...
China-linked group Salt Typhoon breached satellite firm Viasat
Cloudflare Tunnels Abused in New Malware Campaign
CISOs flag gaps in GenAI strategy, skills, and infrastructure
Cybersecurity — June 20, 2025 | Briefing24