THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft Patch Tuesday: July 2025 Delivers 130+ Security Fixes, Including Critical Zero-Day in SQL Server

Microsoft’s July 2025 Patch Tuesday brings a hefty set of updates, addressing at least 130 vulnerabilities—including 14 rated “critical” and one zero-day remote code execution flaw in Microsoft SQL Server (CVE-2025-49717). Also patched are serious bugs in the SPNEGO protocol and multiple Office components. While no vulnerabilities have been seen actively exploited yet, some have been publicly disclosed, raising the urgency for immediate patching—especially for organizations using SQL Server, SharePoint, and Office.

Source: Zero Day Initiative


CitrixBleed 2 (CVE-2025-5777): Exploits Public, Many Systems Remain Unpatched

Technical details and exploit code for the critical CitrixBleed 2 vulnerability in Citrix NetScaler ADC and Gateway (CVE-2025-5777; CVSS 9.3) are now public with evidence of in-the-wild exploitation since mid-June. Despite widespread advisories, researchers warn that a significant portion of NetScaler instances remain unpatched and at risk for data exposure and system compromise. Organizations should not only patch but also review for indicators of compromise, even if patched early.

Source: SecurityWeek


Anatsa Android Banking Trojan Returns: 90,000+ Targeted Users, Malicious Apps on Google Play

The Anatsa (aka TeaBot) banking trojan has resurfaced in North America, spreading via malicious apps masquerading as PDF viewers on the Google Play Store with over 90,000 installations. Once installed, Anatsa overlays real banking apps to steal credentials and drain accounts, bypassing multi-factor authentication protections. Security experts urge fast removal of suspicious apps and heightened scrutiny of mobile installations, especially for enterprise fleets.

Source: The Hacker News


Legitimate Red-Teaming Tool Shellter Used in Multi-Campaign Infostealer Attacks

Threat actors are abusing a leaked copy of the legitimate Shellter Elite red-team tool to bypass AV/EDR defenses and deliver infostealers such as Lumma, Arechclient2, Rhadamanthys, and SectopRAT. Campaigns leveraging Shellter have rapidly spread in the wild, illustrating the risks of leaked pentesting tools being co-opted for broad malware distribution. Organizations should update their detection strategies to account for repurposed security tools now being weaponized by attackers.

Source: The Hacker News


Over 2.3 Million Chrome and Edge Users Compromised by Trojanized Browser Extensions

A massive browser hijacking campaign has silently transformed 18 Chrome and Edge extensions—initially appearing legitimate—into Trojans via covert updates, impacting over 2.3 million users. The malicious extensions hijack browser sessions, steal data, redirect to phishing sites, and enable persistent monitoring, showing the risk of supply chain attacks through browser add-ons. Security teams should review extension policies and banlists before further damage accrues.

Source: CyberNews


Chinese State-Sponsored Hacker Arrested for HAFNIUM Attacks and COVID-19 Espionage

Xu Zewei, alleged member of the Silk Typhoon (HAFNIUM) group, was arrested in Italy following a U.S. warrant. Xu faces nine federal charges for leading high-profile cyberattacks from 2020 to 2021, including the exploitation of Exchange and mass theft of COVID-19 research worldwide—spotlighting continued cross-border cyberespionage and law enforcement collaboration.

Source: SecurityWeek


Ransomware Operator Shuts Down, Plans Full Data Leak—67 Organizations Impacted

The SatanLock ransomware gang announced its exit from cybercrime, promising to leak all stolen data from 67 recently compromised organizations. The rapid rise and fall of the group, coupled with imminent mass data exposure, highlights the persistent risk of sudden data leaks even after ransomware operations cease—a forceful reminder to revisit disaster recovery, breach notification, and brand protection protocols.

Source: CyberNews


You May Also Be Interested In...
Cybersecurity — July 9, 2025 | Briefing24