THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
State-Sponsored Hackers Breach U.S. Army National Guard in Major Espionage Operation

Chinese state-backed threat group Salt Typhoon successfully compromised a U.S. state's Army National Guard network, accessing configuration data, administrative credentials, and intercepting inter-unit communications between March and December 2024. The Department of Defense report highlights the growing threat of Chinese cyber-espionage campaigns targeting U.S. military and critical infrastructure, escalating concerns among defense and intelligence communities.

Source: SecurityWeek


SonicWall SMA Devices Hacked by OVERSTEP Backdoor and Rootkit—Widespread Attacks on End-of-Life Hardware

A persistent and stealthy attack campaign is targeting fully patched, end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances. Google's Threat Intelligence Group links this activity to threat actor UNC6148, who deploys a custom rootkit called OVERSTEP, facilitating deep system compromise, data theft, and potentially extortion or ransomware operations. Organizations relying on legacy SonicWall hardware are at urgent risk and should prioritize upgrades or mitigations.

Source: Help Net Security


Global Operation Eastwood Takes Down Pro-Russian NoName057(16) DDoS Cybercrime Group

An international law enforcement campaign, codenamed Operation Eastwood and led by Europol and Eurojust, has dismantled the infrastructure of the notorious pro-Russian hacktivist group NoName057(16). Over 100 servers were seized and multiple suspects arrested across Europe and the US, delivering a decisive blow to DDoS operations targeting Ukraine and its allies and demonstrating increased global cooperation in cybercrime enforcement.

Source: SecurityWeek


Google Patches Actively Exploited Chrome Zero-Day (CVE-2025-6558)—Update Now

Google has released an urgent security update for Chrome to address CVE-2025-6558, a high-severity vulnerability under active exploitation. The flaw, rooted in incorrect input validation in Chrome's ANGLE and GPU components, allows attackers to escape the browser sandbox and execute code, marking the fifth exploited Chrome zero-day in 2025. Immediate patching is strongly advised to prevent compromise.

Source: Help Net Security


Former U.S. Soldier Pleads Guilty to Massive Telecom Hacks and Extortion Schemes

Cameron John Wagenius, a 21-year-old former U.S. Army soldier, has pleaded guilty to charges involving hacking into major telecom operators such as AT&T and Verizon and orchestrating crippling data extortion campaigns. His actions included leaking sensitive databases and demanding ransoms, demonstrating the persistent insider and external threats facing telecommunications infrastructure.

Source: Bleeping Computer


Amazon Issues Phishing Warning to 200 Million Prime Customers Amid Surge in Credential Theft Scams

Amazon has warned 200 million Prime members against a sophisticated phishing campaign actively seeking customer login credentials. This latest wave of social engineering emphasizes the ongoing risks to large-scale e-commerce platforms and the need for heightened security awareness and user education.

Source: MalwareBytes Blog


Clandestine Attacks Leverage SVG Images to Deliver Hidden Malware

Security researchers are warning of a notable spike in attacks using Scalable Vector Graphics (SVG) files to conceal malicious JavaScript for redirect and phishing campaigns. Utilities, SaaS providers, and B2B services are increasingly targeted, as attackers exploit trusted image formats to slip past conventional defenses, underscoring the need for advanced payload detection and user vigilance.

Source: SCMagazine


You May Also Be Interested In...
Cybersecurity — July 17, 2025 | Briefing24