THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Palo Alto Networks to Acquire CyberArk in Landmark $25 Billion Deal

Palo Alto Networks has announced a definitive agreement to acquire identity security leader CyberArk in a cash-and-stock deal valued at approximately $25 billion. The acquisition—one of the largest in cybersecurity history—signals Palo Alto Networks' strategic push into the identity security and privileged access management domain, critical for securing both humans and AI-driven agents amid escalating threats.

Source: Help Net Security


Apple Patches Zero-Day Vulnerability Exploited Against Chrome, Urges Immediate Update

Apple has released urgent security updates for iOS and iPadOS addressing 29 vulnerabilities, including a high-severity zero-day flaw actively exploited to target Google Chrome users (CVE-2025-6558). This vulnerability allows attackers to escape browser sandboxes via GPU components, reinforcing the importance of prompt patching as sophisticated attacks increasingly exploit browser chains across platforms.

Source: MalwareBytes Blog


Critical SAP NetWeaver Flaw Exploited in Auto-Color Malware Attack

Threat actors exploited a critical vulnerability (CVE-2025-31324) in SAP NetWeaver to deliver an upgraded version of the Auto-Color Linux backdoor during a recent attack on a U.S. chemicals firm. The incident highlights the growing risks facing organizations that rely on ERP and critical infrastructure platforms, with attackers leveraging enterprise system flaws to access sensitive environments.

Source: TheHackerNews


SafePay Ransomware Gang Threatens to Leak 3.5TB of Ingram Micro Data

The SafePay ransomware group is threatening to publish 3.5TB of data allegedly stolen from IT distribution giant Ingram Micro, following an attack earlier this month. The incident underscores continued ransomware risks to supply chains, and the increasing trend of threat actors imposing strict deadlines for extortion while targeting massive repositories of business-critical information.

Source: Bleeping Computer


Hackers Plant 4G-Enabled Raspberry Pi in Physical ATM Attack, Bypass Security Controls

Hackers from group UNC2891 have demonstrated the feasibility of backdooring ATMs through physical implants, using a 4G-enabled Raspberry Pi to gain persistent network access and bypass security defenses. The attack, which involved anti-forensic techniques, highlights ongoing risks to ATM and banking infrastructure from advanced cybercriminal operations blending physical and digital methods.

Source: ArsTechnica


PyPI-Targeted Phishing Surge Entangles Python Developers

Pythons Package Index (PyPI) users have been hit with a targeted phishing wave, with attackers sending convincing verification emails that redirect developers to malicious fake PyPI websites aimed at credential theft. The ongoing campaign signals persistent threats to software supply chains and highlights the developer ecosystem’s growing attractiveness for credential harvesting attacks.

Source: Bleeping Computer


AI Drives Surge in vCISO Adoption, Cutting Workload and Redefining Security Operations

A new report indicates that adoption of virtual CISO (vCISO) services has tripled in the past year as AI-driven platforms reduce workloads for MSPs and MSSPs by up to 68%. This transformation is allowing security teams to scale their protection against threats more efficiently, marking a significant shift in how organizations—especially SMBs—manage and operationalize cybersecurity leadership.

Source: Help Net Security


You May Also Be Interested In...

Cybersecurity — July 31, 2025 | Briefing24