THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical SharePoint Vulnerabilities Under Active Exploit by ToolShell Campaign

Security researchers warn that the ‘ToolShell’ exploit chain is enabling sustained global attacks on on-premises Microsoft SharePoint servers, with hundreds of organizations—including high-profile U.S. agencies—affected. The highly impactful vulnerability allows remote code execution and persistent unauthorized access, and the speed at which attackers are leveraging these flaws is increasing. Microsoft has released emergency patches, but some initial fixes were bypassed, fueling continued intrusions, especially by China-linked actors. Immediate patching and vigilance remain essential for all SharePoint customers.

Source: Cyble


Open-Source Repositories Face Growing Supply-Chain Attacks

Recent weeks saw a spike in supply-chain attacks targeting npm and other open-source software repositories, including the compromise of popular JavaScript type-testing utilities. Attackers are injecting backdoors and malware—posing risks to any organization or developer pulling these packages. This trend underscores the need for continuous dependency analysis and strict provenance controls in software development lifecycles.

Source: ArsTechnica


BlackSuit Ransomware Sites Seized—But New Chaos Group Emerges

International law enforcement dismantled the darknet infrastructure of the notorious BlackSuit ransomware gang as part of Operation Checkmate. However, researchers have already uncovered a new group called ‘Chaos’ exhibiting similar tactics, techniques, and procedures, filling the criminal void left by BlackSuit’s takedown. This rapid succession highlights the persistent nature of ransomware threats despite major enforcement actions.

Source: RecordedFuture


US Sanctions North Korean IT Scheme; American Accomplice Sentenced

The US Treasury sanctioned North Korean entities and individuals involved in global remote IT worker schemes that funneled millions to Pyongyang. Meanwhile, Christina Marie Chapman received an eight-year prison sentence for operating a ‘laptop farm’ in Arizona, aiding North Koreans in surreptitiously working for over 300 US companies. These events highlight continued nation-state abuse of legitimate work platforms for sanctions evasion and revenue generation.

Source: Bleeping Computer


Amazon’s AI Coding Agent Compromised to Wipe Cloud Data, Highlighting AI Risks

A hacker manipulated the Amazon Q Developer Extension for Visual Studio Code, injecting malicious code that could wipe files and AWS cloud resources. The incident, enabled by a supply-chain-style hijack via a public GitHub account, underscores the security challenges posed by AI-powered development tools and the need for independent code integrity verification.

Source: Bleeping Computer


Severe Cisco ISE Remote Code Execution Bug Can Yield Root Shell—Patch Immediately

A critical pre-authentication vulnerability (CVE-2025-20337) in Cisco Identity Services Engine allows unauthenticated attackers to achieve remote code execution as root, even escaping Docker isolation due to misconfigurations. Public details reveal that sophisticated chaining of Java deserialization and command injection makes exploitation dangerous and possible for determined adversaries. Organizations using Cisco ISE must apply the latest patches urgently to prevent full network compromise.

Source: ZeroDayInitiative


Emerging AI-Assisted Malware Targets Linux and Cloud Infrastructures

Security researchers warn of Koske, a new AI-assisted Linux malware, and Soco404, both exploiting cloud misconfigurations to deploy cryptominers and rootkits. These advanced malware strains use polyglot file formats and living-off-the-land techniques to evade detection, and are capable of targeting both Linux and Windows platforms. The AI element in their development signals a concerning trend towards more adaptive and evasive threats in cloud environments.

Source: TheHackerNews


You May Also Be Interested In...
After BlackSuit is taken down, new ransomware group Chaos emerges
Time to exploit new vulnerabilities continues to fall—get proactive
Inside The ToolShell Exploit Campaign: Exploits, Webshells, and Prevention
Cybersecurity — July 26, 2025 | Briefing24