THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Cisco Unified Communications Manager Zero-Day Allows Root Access

Cisco has patched a maximum-severity vulnerability (CVE-2025-20309) in its Unified Communications Manager (Unified CM) platforms, caused by hardcoded root credentials. The flaw allows unauthenticated remote attackers to gain root access and execute arbitrary commands, posing a severe risk to enterprise communications systems. Organizations should apply the patches immediately, as exploitation is straightforward and could result in full system compromise.

Source: Help Net Security


Chinese "Houken" APT Exploits Multiple Ivanti Zero-Days to Breach French Organizations

France's cyber agency ANSSI has revealed that a China-linked advanced persistent threat (APT) group, dubbed Houken, used several Ivanti Cloud Services Appliance (CSA) zero-day vulnerabilities to infiltrate French government, telecom, media, finance, and transport sectors. The campaign, actively targeting these critical sectors since September 2024, highlights the urgent need for patch management and monitoring in organizations using affected Ivanti products.

Source: Security Affairs


Hunters International Ransomware Group Shuts Down, Issues Free Decryptors

The prolific Hunters International ransomware gang announced its shutdown, offering decryption keys to all its victims as a parting gesture. While this may provide relief to recent breach victims, security researchers caution this may just be a rebranding tactic often seen among ransomware operators, who are likely to return under a new name or affiliate with another group.

Source: Bleeping Computer


Over 40 Malicious Firefox Extensions Steal Cryptocurrency Wallets

Researchers have identified over 40 trojanized Firefox browser extensions targeting cryptocurrency wallets. These malicious extensions, often disguised as legitimate wallet tools, exfiltrate wallet keys and seed phrases, allowing attackers to drain digital assets from unsuspecting users. The campaign underscores the ongoing risk posed by malicious third-party browser add-ons, especially as the number of browser-based crypto users continues to expand.

Source: The Hacker News


Amazon Prime Day Sparks Surge in Phishing: 87% of "Amazon"-Related Domains Are Malicious

Ahead of Amazon Prime Day 2025, researchers observed over 1,000 new domains mimicking Amazon, with 87% flagged as malicious or suspicious. Cybercriminals are leveraging Prime Day hype to deploy phishing attacks, create fake checkout pages, and steal customer payment details. Both consumers and organizations should remain vigilant against targeted scams during high-profile shopping events.

Source: Checkpoint Blog


CatWatchful "Stalkerware" Leak Exposes 62,000 User Credentials—and Victim Data

A vulnerability in the CatWatchful child monitoring/stalkerware app led to a massive data exposure, leaking logins and plaintext passwords for more than 62,000 users, alongside victim information. The breach adds to growing concerns over stalkerware tools’ inability to secure highly sensitive personal data and highlights the ethical and security risks these apps pose.

Source: ArsTechnica


Massive Android Ad Fraud and Spyware Operations Uncovered

A global mobile ad fraud operation comprising 352 Android apps, dubbed IconAds, was disrupted after being found to deliver out-of-context ads and evade user detection. In parallel, nearly 100,000 Android devices were compromised in a widespread malware campaign ("Qwizzserial") delivered through Telegram channels masquerading as financial aid outlets, emphasizing the persistent risk from mobile malware and fraud on Android platforms.

Source: The Hacker News


You May Also Be Interested In...

Cybersecurity — July 4, 2025 | Briefing24