THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Millions of Dell Laptops Exposed to Persistent 'ReVault' Attacks via Firmware Flaws

Researchers from Cisco Talos have disclosed five critical vulnerabilities dubbed “ReVault,” impacting Broadcom and Dell ControlVault3 firmware used on over 100 Dell laptop models, including those frequently found in government and cybersecurity environments. These flaws could be exploited to gain persistent access, survive Windows reinstalls, and steal credentials, biometric templates, or security codes. Dell and Broadcom have released patches, but due to the scope, organizations are urged to assess and update affected systems immediately to prevent backdoor attacks on trusted endpoints.

Source: HelpNet Security


SonicWall Firewalls Hit by Active Zero-Day Exploitation in Ransomware Surge

SonicWall Gen 7 firewalls with SSLVPN enabled are currently under mass exploitation by ransomware groups, with at least 20 organizations believed affected. Security researchers and SonicWall are urgently investigating if an unpatched zero-day vulnerability is being abused, as fully patched systems have been breached. SonicWall is advising all customers to disable SSLVPN services immediately while the root cause is determined, underscoring the critical need for rapid operational response when vendor vulnerabilities surface.

Source: CyberScoop


Android Patches Two Actively Exploited Qualcomm Zero-Days—Update Urgently

Google and OEMs have released August security updates for Android devices, addressing six vulnerabilities, including two critical Qualcomm flaws (CVE-2025-21479 and CVE-2025-27038) that are actively exploited in the wild. One vulnerability allows device compromise with no user interaction. Android users should apply updates as soon as possible to avoid targeted attacks, especially those leveraging these exploit chains on unpatched devices.

Source: Bleeping Computer


Critical Zero-Days Patched in Adobe Experience Manager Forms After Exploit Chain Goes Public

Adobe has issued urgent out-of-band patches for two zero-day flaws in its AEM Forms platform after proof-of-concept exploit code surfaced, allowing unauthenticated remote code execution. With attacks now possible by simply targeting exposed AEM Forms instances, organizations running this software should prioritize updating to prevent compromise, especially given the widespread use of AEM in public and enterprise portals.

Source: Bleeping Computer


Malicious AI Coding Tool Vulnerability Allows Persistent Backdoors in Developer Environments

Check Point has disclosed a high-severity vulnerability (CVE-2025-54136) in the fast-growing AI-powered code editor Cursor, dubbed “MCPoison.” The flaw allows an attacker to weaponize previously approved Model Context Protocol (MCP) configurations, resulting in persistent remote code execution each time a project is opened—silently infiltrating developer environments and exposing the AI-powered software supply chain. All users of Cursor IDE should update immediately and review all previously approved MCPs.

Source: Check Point Blog


Cisco Data Breach via Vishing Attack Highlights CRM Third-Party Risk

Cisco has confirmed a data breach resulted from a voice phishing (vishing) attack targeting a company representative and led to unauthorized access to a third-party CRM platform. The attacker exposed basic profile details of Cisco.com users—names, emails, and phone numbers—but no sensitive company systems were reported compromised. Still, the incident underscores the increased social engineering risk and the challenge of securing cloud supply chains, especially when sensitive customer data is involved.

Source: Bleeping Computer


Pandora Becomes Latest Victim in Salesforce Third-Party Data Breach Wave

Jewelry giant Pandora has disclosed a data breach after customer information was stolen, reportedly in connection to the ongoing wave of attacks targeting organizations using Salesforce for cloud-based data management. Although no passwords or payment information were exposed, customer names and email addresses were affected—raising phishing and social engineering risks. The case highlights the growing threat posed by attacks on popular SaaS platforms and their ecosystem vendors.

Source: Bleeping Computer


You May Also Be Interested In... 15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign
Ransomware is up, zero-days are booming, and your IP camera might be next
Microsoft’s Project Ire: Autonomous Malware Detection with AI
Cybersecurity — August 6, 2025 | Briefing24