THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Cloudflare Blocks Largest DDoS Attack in History

Cloudflare successfully mitigated a record-breaking distributed denial-of-service (DDoS) attack that peaked at 7.3 Tbps, delivering 37.4 terabytes of data in just 45 seconds against a hosting provider. This massive attack, which surpasses previous records, highlights the escalating scale and intensity of DDoS threats targeting internet infrastructure and service providers worldwide. Security teams should review their mitigation readiness as attackers increasingly pursue critical infrastructure with high-volume attacks.

Source: SecurityWeek


16 Billion Passwords Exposed in Historic Credential Leak

Researchers have identified what appears to be the largest recorded data breach, with 16 billion login credentials exposed, likely due to widespread infostealer campaigns. The sheer scale of this leak underscores the urgent need for robust credential hygiene, enforced password changes, and the rapid adoption of phishing-resistant multifactor authentication across organizations to limit downstream impacts from credential stuffing and account takeovers.

Source: Forbes Security


Aflac Hit in Wave of Insurance Sector Cyberattacks

Insurance giant Aflac confirmed a cybersecurity incident potentially affecting sensitive data, making it the latest target in a broader campaign—linked to the Scattered Spider group—against major US insurance providers. The attack comes on the heels of warnings and breaches across the sector, underscoring the persistent targeting of financial services and highlighting the need for improved detection and response protocols in high-value verticals.

Source: Bleeping Computer


Banana Squad Targets Developers with Trojanized GitHub Repositories

Researchers uncovered a sophisticated malware campaign dubbed “Banana Squad,” involving more than 67 trojanized GitHub repositories that masquerade as hacking tools but deploy Python-based stealer malware. The campaign, targeting both developers and gamers, exemplifies the ongoing risks of open-source supply chain attacks and emphasizes the importance of repository vetting and threat intelligence integration to prevent developer compromise.

Source: The Hacker News


Critical Linux Privilege Escalation Flaws Expose Major Distributions

Newly discovered local privilege escalation vulnerabilities (e.g., CVE-2025-6018) affect major Linux distributions and could let attackers gain root access. Organizations relying on Linux should urgently review advisories, patch systems, and reevaluate detection controls to mitigate the risk of privilege escalation on end-user and server devices.

Source: Security Affairs


Massive Data Breach Hits Krispy Kreme—Over 160,000 Impacted

A ransomware attack on Krispy Kreme has resulted in the exfiltration of data belonging to 161,676 individuals, including current and former employees and their family members. The breach is notable for its impact on sensitive data, further highlighting the risks ransomware groups pose to organizations with large employee and customer datasets.

Source: SecurityWeek


Qilin Ransomware Offers Legal 'Call a Lawyer' Button to Pressure Victims

The Qilin ransomware group has introduced a “Call a Lawyer” feature, providing affiliates with legal counsel during ransom negotiations to increase pressure on victims. This development signals the increasing sophistication and professionalization of ransomware operations, as threat actors adopt business-like tactics for extortion.

Source: The Hacker News


You May Also Be Interested In...
Cybersecurity — June 21, 2025 | Briefing24