THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
SonicWall Zero-Day Suspected in Ransomware Surge

Multiple security vendors and incident response firms have warned that a likely zero-day vulnerability in SonicWall firewalls is enabling the Akira ransomware group to bypass protections and deliver attacks against enterprise networks. Since mid-July, there has been a marked spike in targeted intrusions, with threat actors reportedly gaining access via SSL VPNs even on fully patched devices, prompting SonicWall to advise taking certain appliances offline while the investigation continues.

Source: SecurityWeek


NVIDIA Triton AI Server Flaws Allow Remote Takeover

Researchers disclosed a critical series of vulnerabilities impacting NVIDIA’s Triton Inference Server, allowing unauthenticated remote attackers to fully compromise AI infrastructure on both Windows and Linux. If chained, these bugs could enable attackers to gain control of AI servers, achieving remote code execution and potentially exfiltrating sensitive data or sabotaging AI operations. NVIDIA has issued patches and urgent mitigations are advised for any exposed deployments.

Source: SecurityWeek


New “Plague” Linux Backdoor Evades Detection for Months

A highly persistent Linux backdoor dubbed “Plague” has compromised systems for over a year without triggering antivirus alerts, according to new research. The malware installs itself as a rogue authentication module, bypassing SSH authentication and allowing stealthy, persistent access, while scrubbing traces of attacker logins to avoid detection; IT teams are urged to review authentication modules and monitor for anomalous SSH behaviors.

Source: Bleeping Computer


Ransomware Campaigns Adopt Quadruple Extortion Tactics

Threat actors have escalated their cyber extortion methods, moving beyond double and triple extortion to include DDoS attacks and harassment of a victim's third-party associates. This new “quadruple extortion” tactic—aimed at maximizing pressure on organizations already struggling with ransomware encryption and data leaks—shows ransomware operations are evolving rapidly, according to new reports from Akamai and others.

Source: Help Net Security


Generative AI Data Leakage: Over a Gigabyte of Sensitive Files Uploaded by Employees

According to fresh analysis, corporate employees uploaded more than a gigabyte of files—including sensitive and regulated data—to GenAI tools and AI-powered SaaS platforms last quarter. Security leaders are increasingly challenged to monitor this shadow data flow as enterprises experiment with dozens of new AI tools per quarter, risking inadvertent data exposure or regulatory violations.

Source: Help Net Security


Open-Source Supply Chain Under Fire as Malicious Packages Proliferate

Fortinet’s Q2 2025 threat research highlights a relentless wave of malicious packages in open-source registries such as NPM and PyPI, which continue to be abused for credential theft, cryptomining, and malware distribution. Foreign adversaries and cybercriminals are increasingly embedding backdoors in trusted libraries, raising concerns about software supply chain risks that affect countless downstream applications globally.

Source: Fortinet


North Korean “Laptop Farms” Infiltrate US Companies with Deepfakes & Generative AI

US authorities sentenced an Arizona woman for helping North Korean IT workers pose as US employees and gain remote jobs at hundreds of firms—including defense contractors—by operating a “laptop farm” and facilitating deepfake interviews. The North Korean operatives leveraged generative AI to craft convincing resumes and video personas, highlighting the growing convergence of nation-state espionage, AI deception, and insider risk.

Source: Schneier Blog


You May Also Be Interested In...
Cybersecurity — August 5, 2025 | Briefing24