THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Citrix NetScaler 'CitrixBleed 2' and Zero-Day Vulnerabilities: Immediate Action Required

Citrix has disclosed multiple critical vulnerabilities in its NetScaler ADC and Gateway appliances – most notably CVE-2025-5777, dubbed “CitrixBleed 2,” and CVE-2025-6543, a zero-day now under active exploitation. These flaws allow unauthenticated attackers to hijack session tokens and potentially bypass multi-factor authentication (MFA), making current login safeguards irrelevant. Emergency patches are available and should be applied urgently as attackers are already exploiting the vulnerabilities in the wild.

Source: SecurityWeek


Law Enforcement Cracks Down on BreachForums – Top Admins Arrested

Authorities in France, supported by U.S. and UK agencies, have arrested key administrators linked to the notorious BreachForums cybercrime marketplace. The takedown targeted individuals operating under aliases like “ShinyHunters” and “IntelBroker,” linked to massive data leaks and sales of stolen credentials. This global operation signals a major disruption in underground data trading and a warning to cybercriminals worldwide.

Source: RecordedFuture


SonicWall NetExtender App Trojanized for Credential Theft

Researchers warn that attackers are distributing a trojanized version of SonicWall’s NetExtender SSL VPN client, laced with infostealer malware. Victims running the fake installer—often sourced from unofficial download sites—unwittingly expose sensitive VPN credentials, opening the door to later network intrusions and data breaches. SonicWall urges users to verify download sources and update any potentially compromised installations.

Source: SecurityWeek


AI Evasion: Malware Authors Target Generative AI Defenses

Malware developers are now embedding prompt injection and adversarial natural-language into their code to trick AI-powered detection tools. Check Point Research highlights the first documented malware purposely designed to influence generative AI into misclassifying malicious code as benign. This signals a new category of threats—and an escalating cat-and-mouse game between innovative attackers and defenders leveraging advanced machine learning security.

Source: Check Point Blog


Spear-Phishing Surge Targets High-Profile Individuals in Iran-Israel Tensions

APT42 (aka Charming Kitten/Educated Manticore), aligned with Iran’s Revolutionary Guard Corps, has launched sophisticated spear-phishing and credential theft campaigns against Israeli public figures, journalists, and cybersecurity professionals. These attacks use personalized social engineering and AI-powered phishing to harvest access credentials, underlining the need for heightened vigilance especially amid ongoing regional hostilities.

Source: Check Point Blog


Vulnerabilities in Popular Software Spark Supply Chain and SaaS Security Jitters

Recent research finds that over 10,000 SaaS apps may still be vulnerable to a nOAuth authentication bypass in Microsoft Entra environments, exposing organizations to account takeover attacks. Separately, 35 malicious npm packages attributed to North Korean actors are being used in ongoing supply chain attacks, directly targeting developers with infostealers and backdoors. These issues highlight systemic risks within the software ecosystem and the rising sophistication of state-linked attackers.

Source: TheHackerNews


AMI MegaRAC, Fortinet, D-Link Vulnerabilities Now Actively Exploited – CISA Urges Immediate Patch

CISA has added critical security flaws impacting AMI MegaRAC Baseboard Management Controller, D-Link DIR-859 routers, and Fortinet FortiOS to its Known Exploited Vulnerabilities catalog. The MegaRAC bug, in particular, is being weaponized to hijack or brick servers—posing infrastructure risks to organizations that delay patching. Federal agencies and enterprises should prioritize remediation before the July 17 deadline to avoid real-world attack fallout.

Source: SecurityWeek


You May Also Be Interested In...
Cybersecurity — June 26, 2025 | Briefing24