THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Trojanized SonicWall NetExtender App Steals VPN Credentials

Organizations are being warned about a trojanized version of SonicWall's SSL-VPN NetExtender application, used to exfiltrate VPN credentials from unsuspecting users. Threat actors are distributing the compromised installer via lookalike websites, highlighting the persistent risk of downloading software from unofficial sources. If your organization relies on SonicWall VPN, ensure every installation came directly from SonicWall and review credential security immediately.

Source: Help Net Security


Critical WinRAR Vulnerability Patched—Users Urged to Update Quickly (CVE-2025-6218)

A high-risk directory traversal vulnerability in WinRAR (CVE-2025-6218) could allow remote attackers to execute arbitrary code on affected machines. The flaw has been patched in WinRAR 7.12 beta 1, and users are strongly encouraged to update immediately, as attackers can exploit this flaw to compromise Windows systems by simply tricking users into opening malicious archive files.

Source: Help Net Security


Chinese APT ‘Salt Typhoon’ Campaign Hits Canadian Telecom in Espionage Operation

A joint US-Canadian advisory confirms that the Chinese state-sponsored Salt Typhoon (also known as APT) compromised a major Canadian telecom provider in February. The campaign, active for up to two years, targets telecom and internet infrastructure, leveraging compromised devices—including SOHO routers—to build a global espionage network. This incident highlights escalating China-backed threat activity against North American infrastructure and the urgent need for robust segmentation and device hardening.

Source: SCMagazine


Sophisticated Spyware Found in Apple App Store and Google Play, Stealing Photos and Possibly Crypto Data

Researchers uncovered "SparkKitty" spyware on both the Apple App Store and Google Play, capable of stealing all photos from infected mobile devices and potentially targeting stored cryptocurrency wallet information. The campaign, active since early 2024, underlines the persistent risks of malicious apps slipping through official store reviews and the vital need for organizations to carefully review employee device management and mobile security policies.

Source: HackRead


Russia's APT28 Deploys New Malware via Signal Chats Against Ukraine

Ukraine’s CERT and global researchers report that Russian state-sponsored group APT28 (aka Fancy Bear/Forest Blizzard) used Signal encrypted chats to deliver new malware variants (BeardShell and SlimAgent) in targeted attacks on government officials. While Signal itself remains uncompromised, this novel social engineering technique demonstrates how secure messaging platforms can be exploited as delivery channels in advanced persistent threat scenarios.

Source: SecurityWeek


US House Bans WhatsApp on Staff Devices Citing Security Concerns

The US House of Representatives has formally banned the use of WhatsApp on government-issued devices, citing security gaps in how the messaging app handles and encrypts data. The move reflects growing concern about third-party communication tools in government, following similar restrictions on generative AI apps and software with unclear data protection practices.

Source: Bleeping Computer


New WordPress Malware Campaign Imitates Cloudflare to Skim Credit Cards

A sophisticated malware operation has been uncovered targeting WordPress websites, hiding malicious code on checkout pages via a rogue Core plugin that masquerades as a Cloudflare component. This campaign, active since 2023, specializes in stealing credit cards and credentials using advanced anti-detection tactics—sending a clear signal to ecommerce platforms to review plugin authenticity, monitor file integrity, and implement strong endpoint protection.

Source: HackRead


You May Also Be Interested In...

Cybersecurity — June 25, 2025 | Briefing24