THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Scattered Spider Expands Attacks, Aviation Sector on Alert

A new report from Check Point Research reveals that the Scattered Spider cybercrime group, infamous for targeted phishing and social engineering campaigns, is escalating its attacks on both enterprise organizations and the aviation sector. Investigators have identified novel phishing domain patterns connected to recent airline breaches, providing actionable detection indicators for defenders. The expansion into aviation increases the urgency for organizations in at-risk sectors to bolster proactive countermeasures and monitoring capabilities.

Source: Checkpoint Blog


Google Chrome Actively Exploited Zero-Day; CISA Adds to KEV Catalog

Google urgently patched a security vulnerability in Chrome (CVE‑2025‑6554), which was reportedly under active exploitation in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also added this Chromium V8 flaw to its Known Exploited Vulnerabilities (KEV) catalog, urging organizations to expedite updates to avoid exploitation. This underscores the ongoing targeting of browser supply chains and the value of prompt patching for endpoint security.

Source: HelpNet Security / Security Affairs


Critical NetScaler (Citrix) ADC Vulnerabilities Exploited in the Wild

Researchers have observed attackers actively exploiting three critical vulnerabilities (CVE-2025-5349, CVE-2025-5777, CVE-2025-6543) affecting Citrix NetScaler ADC and Gateway appliances. The vulnerabilities enable remote compromise, with attackers reportedly moving quickly to establish persistent footholds before fixes are widely applied. Organizations using affected Citrix products are strongly advised to patch immediately and conduct compromise assessments.

Source: Wiz


Hunters International Ransomware Gang Shuts Down, Releases Decryption Keys

The Hunters International ransomware group has unexpectedly announced its shutdown and published free decryption keys for all victims. While specifics behind the decision remain unclear, this development may provide relief for impacted organizations but also raises questions about residual risks and the potential diffusion of the group’s tactics to other criminal actors.

Source: Security Affairs


Alleged 0-Day SSO and Fortinet Exploits, Allianz Data Breach Surface on Dark Web

Security researchers have uncovered an alleged zero-day redirect vulnerability in major Single Sign-On (SSO) platforms and fresh exploit activity targeting legacy Fortinet vulnerabilities. In addition, Allianz suffered a reported data breach, and a dark web service offering social media bans has emerged. Organizations with SSO or Fortinet deployments should monitor for updates and assess exposure.

Source: SocRadar


Japan Q1 Cyber Threats: Phishing Dominates, Supply Chain Attacks Escalate

The latest JPCERT incident report shows a 10% spike in cyber incidents in Japan, with phishing attacks comprising 87% of confirmed cases. Notable trends include targeted supply chain exploits—such as the sophisticated exploitation of Ivanti VPN vulnerabilities using advanced malware—and a sharp increase in website defacements. These findings highlight the persistence of phishing and the growing complexity of attacks on critical infrastructure and supply chains.

Source: Cyble


Mobile Threats Spike: Android Malware Surges with Crypto Theft, Adware, and Banking Trojans

New analysis indicates a significant uptick in Android threats for Q2, with criminal groups distributing malware—including adware, banking trojans, and crypto-stealing Trojans—via fake apps, firmware, and spyware. This mobile malware surge requires heightened vigilance from enterprises supporting BYOD policies and all Android users to ensure apps are sourced from trusted ecosystems only.

Source: HackRead


You May Also Be Interested In...
Cybersecurity — July 7, 2025 | Briefing24