THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical SAP Vulnerability Exploited to Deploy Auto-Color Linux Malware in Targeted Attack

Threat actors have exploited a critical SAP NetWeaver vulnerability (CVE-2025-31324) to deploy the Auto-Color Linux malware in a targeted attack against a U.S.-based chemicals company. The sophisticated campaign highlights the growing risk of attackers chaining recently patched flaws with stealthy malware, underlining the need for rapid patch cycles and advanced detection capabilities across enterprise Linux environments.

Source: The Hacker News


French Telecom Giant Orange Suffers Major Cyberattack, Disrupting Services Across Europe and Africa

Orange, France’s largest telecommunications provider, has confirmed a significant cyberattack impacting its internal systems and disrupting services in multiple regions. While details about the threat actor and initial access vector remain undisclosed, the breach demonstrates the vulnerability of critical telecom infrastructure and the potential cascading effects of such incidents across national and international networks.

Source: TechCrunch Security


Tea App Data Breach Grows: Over 1 Million Private Messages and Images Exposed

The women-focused dating safety app Tea continues to reel from a deepening data breach, with reports now confirming exposure of over a million user chat messages in addition to thousands of images. Researchers attribute the expanding impact to misconfigured cloud storage and inadequate access controls, raising urgent questions about security hygiene in rapidly growing consumer platforms.

Source: TechCrunch Security


Google Announces Device Bound Session Credentials (DBSC) to Combat Cookie Theft Attacks

Google has launched the open beta of Device Bound Session Credentials (DBSC) in Chrome, a new security feature designed to prevent session hijacking by binding authentication cookies to specific devices. This move follows a spike in session token stealing attacks and complements Google Project Zero’s new policy to enhance patch transparency and reduce the “upstream patch gap” across the software supply chain.

Source: The Hacker News


Scattered Spider: Updated Tactics Targeting Snowflake Data & Supply Chain Weaknesses

The notorious Scattered Spider cybercriminal group has evolved its techniques, now pivoting to target cloud data storage, specifically seeking Snowflake credentials for data exfiltration. Joint advisories from the FBI and international agencies underscore the group’s emerging ransomware variants, supply chain infiltration, and social engineering prowess, urging organizations to update detection and response playbooks for cloud-centric attacks.

Source: Recorded Future


Base44 “Vibe Coding” Platform Exposed by Simple, Yet Critical Access Bypass Flaw

Researchers have uncovered a severe authentication bypass vulnerability in Base44, an AI-powered application development platform, which allowed attackers to access private applications simply by providing a public “app_id” value. The incident highlights supply chain risks in next-generation AI/LLM coding tools and the importance of rigorous verification of authentication flows in emerging development platforms.

Source: The Hacker News


PyPI Users Targeted in New Phishing Campaign Leveraging Fake Verification Emails and Domains

Administrators of the Python Package Index (PyPI) have issued warnings about ongoing phishing campaigns using convincing lookalike domains and verification emails to steal developer credentials and push malicious packages. Ongoing compromise of developer supply chains via such phishing tactics threatens the broader Python and open source ecosystem, reinforcing the need for careful domain monitoring and security awareness.

Source: The Hacker News


You May Also Be Interested In...

Cybersecurity — July 30, 2025 | Briefing24