THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Microsoft SharePoint Zero-Day Under Active Exploitation

Chinese-linked threat actors are actively exploiting a critical vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, with a severity rating of 9.8. This zero-day enables unauthenticated remote access to exposed on-premises SharePoint servers—leading to mass data theft, espionage, and ransomware deployment worldwide. While Microsoft 365 and SharePoint Online remain unaffected, organizations running on-prem setups are strongly urged to patch immediately and review for compromise.

Source: Schneier Blog


Scattered Spider Ransomware Targets VMware vSphere with Social Engineering

The notorious Scattered Spider cybercrime group, also known as 0ktapus and UNC3944, is shifting tactics to target VMware ESXi and vSphere hypervisors in sectors such as retail, airlines, and transportation. Leveraging social engineering—such as fake IT help desk calls—rather than software exploits, attackers obtain Active Directory credentials before deploying ransomware directly from compromised hypervisors, bypassing traditional endpoint defenses. Google’s Threat Intelligence team and others urge organizations to harden identity access controls and monitor for lateral movement into virtualization environments.

Source: Security Affairs


Massive Allianz Life Data Breach Exposes Information of Majority of 1.4 Million Customers

Allianz Life, a major US insurance provider, disclosed that a threat actor breached a third-party CRM system, compromising sensitive data of most of its 1.4 million customers and staff. The incident highlights ongoing risks from supply chain and social engineering attacks, with exposed information potentially including personal identifiers, employee details, and financial data. Security teams are encouraged to assess vendor risk and review CRM/third-party integrations for potential vulnerabilities.

Source: RecordedFuture


Widespread WordPress Site Takeovers Likely with Popular Post SMTP Plugin Flaw

A critical vulnerability (CVE-2025-24000, CVSS 8.8) in the Post SMTP WordPress plugin—used by over 400,000 sites—lets attackers gain administrator access and fully compromise vulnerable websites. Nearly half the installations remain unpatched, putting hundreds of thousands of sites at risk for defacement, data theft, and malware injection. Website administrators should urgently apply the latest plugin update and monitor for suspicious account activity.

Source: Security Week


macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Apple Intelligence-Cached Data

Microsoft Threat Intelligence discovered a critical macOS vulnerability (CVE-2025-31199) that allowed attackers to bypass the TCC (Transparency, Consent, and Control) privacy system, gaining access to sensitive user files and cached data from Apple Intelligence features. The flaw leveraged Spotlight plugins and was patched in March, but recent public disclosures bring heightened awareness to post-patch risk and the need for continual review of data access permissions, especially with AI integrations.

Source: Microsoft MMPC


RedHook: Sophisticated Android Banking Trojan Hits Vietnamese Users

Researchers have uncovered “RedHook,” an advanced Android banking trojan targeting users in Vietnam through phishing sites impersonating government and financial entities. RedHook abuses accessibility permissions, deploys keylogging, executes 34 remote commands via WebSocket, and has a low antivirus detection rate. Its Chinese-language artifacts and infrastructure suggest development by a Chinese-speaking threat group, indicating potential for rapid expansion in Southeast Asia.

Source: Cyble


Maritime Sector Faces Surge in State-Backed and Hacktivist Cyber Threats

The global maritime industry, responsible for nearly 90% of world trade, is experiencing an escalation in cyberattacks from APTs, ransomware, and hacktivists amid geopolitical tensions. Notable campaigns include GPS jamming, isolation of vessels, and dark web trade in sensitive ship data and control system vulnerabilities. Experts urge operators to prioritize vulnerability patching, implement network segmentation, restrict USB/device use, and expand incident response plans for OT and IT systems alike.

Source: Cyble


You May Also Be Interested In…

Cybersecurity — July 29, 2025 | Briefing24