THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Akira Ransomware Surge Targets SonicWall Firewall Devices in Likely Zero-Day Attack

Security researchers have observed a sharp increase in Akira ransomware attacks this week, specifically targeting SonicWall firewall and SSL VPN devices. Evidence suggests attackers may be exploiting a previously unknown vulnerability to gain VPN access, even on fully patched appliances, and execute ransomware payloads. Organizations using SonicWall products are urged to review VPN access logs and ensure robust segmentation and multi-factor authentication to minimize risks.

Source: The Hacker News


AI-Generated Malicious npm Package Drains Solana Wallets from 1,500+ Victims

Researchers discovered an AI-generated malicious npm package, @kodane/patch-manager, that surreptitiously drained Solana cryptocurrency wallets. The package, disguised as a utility for license validation and registry optimization, was downloaded over 1,500 times before being removed from the npm registry. This incident demonstrates the increasing role of AI in automating malicious code distribution and highlights the supply chain risks in open-source ecosystems, especially for Web3 projects.

Source: The Hacker News


New Microsoft OAuth App Phishing Campaigns Bypass MFA to Steal 365 Credentials

A new wave of phishing attacks leverages fake Microsoft OAuth applications to gain access to Microsoft 365 accounts, bypassing multi-factor authentication (MFA). Threat actors impersonate well-known brands via rogue OAuth consent screens, tricking users into granting permissions and redirecting them to credential-harvesting pages. This highlights the urgent need for organizations to scrutinize OAuth integrations, enhance user training, and deploy conditional access policies beyond typical MFA protections.

Source: The Hacker News


Critical Flaw in AI-Powered Cursor Code Editor Allows Remote Code Execution via Prompt Injection

A high-severity vulnerability, dubbed "CurXecute" (CVE-2025-54135), has been patched in the AI-driven Cursor code editor. The flaw allowed remote code execution through prompt injection, enabling attackers to execute arbitrary commands with developer privileges. This incident underscores the growing attack surface associated with AI-assisted development environments and the necessity of diligent security reviews for AI-powered tools.

Source: The Hacker News


1 in 5 New Vulnerabilities Exploited Within a Week, Report Finds

According to new research, one in five recently disclosed IT and industrial control system vulnerabilities are actively exploited within the first week of disclosure. Notable highlights include critical flaws in Node-SAML, Pandora FMS, SonicWall, Apple devices, and Honeywell Experion PKS. Security teams are encouraged to prioritize rapid mitigation strategies and adopt risk-based vulnerability management programs as exploitation timelines continue to shrink.

Source: Cyble


OpenAI Revokes ChatGPT Chat Indexing and Faces Prompt Injection Data Exfiltration Risks

OpenAI has removed the feature that allowed users to make ChatGPT conversations indexable by search engines after reports revealed some chats appeared in Google search results. Meanwhile, researchers have demonstrated prompt injection techniques that let malicious documents or websites exfiltrate users’ private chat histories. Both issues highlight the persistent privacy and supply chain risks as generative AI tools integrate deeper into business and personal workflows.

Source: ArsTechnica


Proofpoint Warns of Link Wrapping Exploitation in Novel Phishing Campaigns

Threat actors are abusing link wrapping and URL scanning services to covertly deliver malware and steal credentials via phishing emails. Recipients often perceive these wrapped links as security-vetted, making them more likely to click and expose themselves to credential theft or malware infections. Enterprises should review URL rewriting practices across email security solutions to better detect and block these increasingly sophisticated phishing techniques.

Source: CISO2CISO (via CSO Online)


You May Also Be Interested In…

Cybersecurity — August 2, 2025 | Briefing24