THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft Patch Tuesday fixes 111 flaws, including a Kerberos zero-day

Microsoft shipped fixes for 111 vulnerabilities, with 16 rated critical and one Windows Kerberos flaw publicly disclosed at release. Notable risks include “browse-and-own” RCEs in GDI+ (CVE-2025-53766) and the Windows Graphics component (CVE-2025-50165), plus Office Preview Pane issues and SharePoint bugs. Prioritize patching internet-exposed services and high-impact client-side components.

Source: The Hacker News


Citrix NetScaler zero-day (CVE-2025-6543) actively exploited against critical orgs

The Dutch NCSC confirmed active exploitation of CVE-2025-6543 to breach several critical organizations, urging immediate mitigation. The flaw can enable remote code execution on NetScaler ADC/Gateway devices; investigations are ongoing. Organizations should patch now, review for indicators of compromise, and restrict management access.

Source: The Hacker News


WinRAR zero-day (CVE-2025-8088) used by multiple threat actors

RomCom and a group tracked as Paper Werewolf both exploited a now-patched WinRAR zero-day, with evidence suggesting the exploit circulated on cybercrime forums before disclosure. The attacks leveraged malicious archives delivered via phishing. Update WinRAR immediately and tighten mail filtering for archive attachments.

Source: Help Net Security


Fortinet SSL VPNs hit by global brute-force wave; attackers pivot to FortiManager

GreyNoise observed a coordinated spike in brute-force attempts against Fortinet SSL VPN devices from over 780 IPs in a single day, with activity continuing and some actors shifting attention to FortiManager. Enforce MFA, rate-limit and geo-restrict access, enable lockouts, and monitor authentication logs for anomalies.

Source: The Hacker News


ShinyHunters and Scattered Spider appear to join forces in Salesforce extortion campaign

Researchers warn that ShinyHunters, working alongside Scattered Spider, is expanding beyond database theft to targeted extortion of Salesforce customers—and may soon eye financial services and IT providers. Tactics include social engineering, vishing, and session hijacking for data theft and leverage. Lock down SSO/MFA flows, audit Salesforce integrations, and monitor for unusual data exports.

Source: The Hacker News


Interlock ransomware dumps 43GB from Saint Paul after city refuses to pay

Following a disruptive late-July attack, the Interlock gang published a 43GB trove allegedly stolen from the City of Saint Paul, underscoring the rising pressure on municipalities. The city declared an emergency and engaged state and federal partners. Segment critical systems, maintain offline backups, and practice ransomware playbooks to reduce impact.

Source: The Register


OT networks targeted via Erlang/OTP vulnerability exploitation

Attackers have been exploiting CVE-2025-32433 in Erlang/OTP since early May, with observed activity against operational technology environments. The bug enables abuse of Erlang-based components that underpin some industrial systems. Patch affected runtimes, isolate OTP nodes, and increase monitoring for anomalous traffic between Erlang nodes and dependent services.

Source: SecurityWeek


You May Also Be Interested In...

SAP Patches Critical S/4HANA Vulnerability

Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images

Charon Ransomware Hits Middle East Sectors Using APT-Level Evasion Tactics

Cybersecurity — August 13, 2025 | Briefing24