THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
WinRAR zero-day exploited in targeted espionage — update now

ESET uncovered CVE-2025-8088, a path traversal zero-day in WinRAR actively exploited by the Russia‑aligned RomCom group and others via weaponized “job application” archives. Targets included financial, manufacturing, defense, and logistics firms in Europe and Canada. Users of WinRAR, its Windows CLI tools, and UnRAR components should update immediately to the latest release.

Source: ESET Blog


Citrix NetScaler flaw (CVE-2025-6543) abused to breach critical Dutch organizations

The Netherlands’ NCSC warned that threat actors are exploiting a critical NetScaler ADC vulnerability to compromise multiple “critical organizations.” The advisory urges rapid patching, compromise checks, and hardening of external ADCs, as active exploitation is confirmed in the wild.

Source: BleepingComputer


‘Win‑DDoS’: Public Windows domain controllers can be weaponized

SafeBreach detailed multiple flaws, including CVE-2025-32724, that allow attackers to crash Active Directory domain controllers and coerce exposed DCs into participating in DDoS attacks by redirecting them to attacker‑controlled LDAP servers. Organizations with internet‑facing DCs should patch immediately and restrict LDAP/LDAPS egress to untrusted hosts.

Source: Help Net Security


OT networks targeted via Erlang/OTP SSH auth bypass (CVE-2025-32433)

A critical, now‑patched Erlang/OTP vulnerability (CVSS 10.0) has been actively exploited since early May, with roughly 70% of detections observed on firewalls protecting operational technology environments. The flaw enables unauthenticated access via OTP SSH; defenders should patch promptly and review OT perimeter logs for anomalous SSH activity.

Source: SecurityWeek


ICE disrupts BlackSuit ransomware infrastructure

US Homeland Security Investigations (ICE) announced a takedown of BlackSuit ransomware infrastructure, a win that could blunt near‑term operations by a group linked to significant extortion activity. Experts caution that durable impact requires arrests and continued pressure, as ransomware crews often rebrand and retool.

Source: SC Media


Car dealer portal bug exposed personal data and allowed remote vehicle unlock

A researcher found a major automaker’s dealership portal flaw that exposed customer information and could let anyone remotely unlock cars. The issue underscores the growing risk at the intersection of cloud portals and connected vehicles, and the need for strict auth, segmentation, and least‑privilege access.

Source: Malwarebytes


BadCam: Linux webcams abused as persistent BadUSB threats

Eclypsium researchers demonstrated “BadCam,” turning certain Linux‑based webcams (shown on Lenovo models, with others potentially affected) into persistent, host‑level threats via BadUSB techniques. Because the compromise lives on the device, it can survive OS reinstalls, emphasizing the importance of device provenance, firmware updates, and USB trust controls.

Source: SecurityWeek


You May Also Be Interested In...
EntraGoat: Vulnerable Microsoft Entra ID to simulate identity misconfigurations
New ‘Charon’ ransomware borrows APT tradecraft to target enterprises
Rusty Pearl: Remote Code Execution paths in PostgreSQL via PL/Perl and PL/Rust
Cybersecurity — August 12, 2025 | Briefing24