THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Fortinet FortiWeb SQL Injection Flaw: PoC Exploits Published, Patch Immediately (CVE-2025-25257)

A critical SQL injection vulnerability (CVE-2025-25257) affecting Fortinet’s FortiWeb web application firewall is now under active threat as proof-of-concept exploits have been released. This pre-auth bug enables attackers to execute remote code, potentially granting complete system compromise; organizations are urged to patch FortiWeb immediately to prevent exploitation. Security researchers warn that the flaw affects the Fabric Connector component, and public exploitation is anticipated given its severity (CVSS 9.8).

Source: Help Net Security


GPUHammer Attack Targets NVIDIA GPUs, Threatens AI Model Security

Security researchers have demonstrated a novel Rowhammer attack known as GPUHammer that targets NVIDIA GPUs powering AI models, including the popular RTX A6000 series, reducing AI accuracy from over 80% to nearly zero. The attack marks the first instance of direct memory bit flipping in GPUs via Rowhammer, allowing adversaries to corrupt AI workloads or potentially plant invisible backdoors; NVIDIA has issued an advisory urging users to stay alert for mitigations.

Source: ArsTechnica


Google Gemini AI Bug Enables Stealthy Phishing Attacks via Summarization Feature

Researchers have discovered that Google Gemini for Workspace can be manipulated to generate misleading or phishing-laden summaries, turning the trusted AI-powered feature into a vector for invisible cyberattacks. By hiding malicious prompts within emails, threat actors can trick Gemini into displaying phishing messages as legitimate summaries, exposing organizations to new risks as AI is increasingly embedded into everyday workflows.

Source: SecurityWeek


MITRE Unveils AADAPT: The First Cybersecurity Framework for Cryptocurrency Threats

MITRE has launched its AADAPT framework (Adversarial Actions in Digital Asset Payment Technologies), the first of its kind dedicated to mapping cyber threats facing digital currencies and payment platforms. Modeled after the ATT&CK framework, AADAPT offers a taxonomy of adversarial tactics, techniques, and procedures across the crypto ecosystem, supporting developers and security teams as digital payments become an ever-larger cyber risk focus.

Source: Help Net Security


Interlock Ransomware Launches Widespread Attacks with New PHP-based RAT

The Interlock ransomware group is leveraging a new PHP-based remote access trojan (RAT) distributed via the FileFix technique, intensifying the threat to organizations worldwide. Researchers say the campaign, active since June, uses manipulated file delivery methods to establish persistent, stealthy access and foreshadows a broader adoption of web-based RATs in ransomware operations.

Source: TheHackerNews


17,000+ Fake News Sites Impersonate CNN, BBC, CNBC in Global Investment Scam Blitz

Security analysts have uncovered an enormous network of 17,000 phishing websites cleverly disguised as trustworthy media outlets like CNN, BBC, and CNBC, duping users into high-stakes investment scams. These sites—often promoted via ads on Google and Meta—demonstrate a significant escalation in social engineering, blending brand impersonation with sophisticated ad abuse to defraud users at scale.

Source: CyberNews


Kigen eSIM Vulnerability Exposes Billions of Mobile and IoT Devices to Cloning Attacks

Critical flaws in Kigen’s eSIM firmware have been revealed, allowing attackers to clone eSIM profiles, hijack subscriber identities, and spy on smartphone and IoT users across billions of affected devices. Researchers demonstrated practical attacks exploiting test profile vulnerabilities, raising alarm about the security of remote SIM provisioning and the rapid shift toward eSIMs in both consumer and industrial devices.

Source: CyberNews


You May Also Be Interested In...

Cybersecurity — July 15, 2025 | Briefing24