THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
New ‘MadeYouReset’ flaw in HTTP/2 fuels massive DDoS campaigns

Researchers disclosed a design issue across multiple HTTP/2 implementations that lets attackers bypass the usual 100-request-per-connection cap, enabling high-impact denial-of-service attacks reminiscent of 2023’s Rapid Reset. Hundreds of vendors were notified; some major providers say existing Rapid Reset mitigations help, but enterprises should still review edge protections, update stacks, and tighten rate-limiting and anomaly detection.

Source: SecurityWeek


Cisco fixes CVSS 10.0 RCE in Secure Firewall Management Center

Cisco patched a critical RADIUS subsystem flaw (CVE-2025-20265) in Secure Firewall Management Center that allows unauthenticated remote code execution. Admins should urgently update FMC and review RADIUS exposure, apply least-privilege on management planes, and monitor for abnormal authentication traffic; Cisco also shipped additional advisories for ASA and FTD in its August bundle.

Source: SecurityWeek


CISA: N‑able N‑central zero‑days exploited against MSPs

Two N‑central vulnerabilities (CVE-2025-8875, CVE-2025-8876) were added to CISA’s KEV catalog after in-the-wild exploitation was observed on patch day. Given RMM platforms’ central role, MSPs should patch immediately, rotate credentials and tokens, audit logs for post-exploitation activity, and assess downstream customer impact.

Source: SecurityWeek


Norway blames pro‑Russian hackers for dam takeover that opened floodgates

Norway’s security service says pro‑Russian actors breached a dam’s control systems in April, opening valves for hours and releasing large volumes of water before operators regained control. The incident underscores rising OT/ICS risk: segment control networks, lock down remote access, enforce MFA and strong passwords, and test incident response for physical-process scenarios.

Source: The Record


Researchers show passkey logins can be bypassed via WebAuthn flow manipulation

New research demonstrates that attackers can impersonate users by manipulating parts of the WebAuthn process, undermining passkey protections in certain scenarios. Organizations should ensure strict RP ID/origin checks, enforce phishing‑resistant MFA settings, and verify browser and IdP configurations to prevent downgrade or process‑tampering attacks.

Source: SecurityWeek


Chinese‑speaking APT ‘UAT‑7237’ targets Taiwanese web hosting infrastructure

Cisco Talos tracks UAT‑7237, active since at least 2022 with overlaps to UAT‑5918, focusing on compromising Taiwanese hosting providers as a springboard into tenant environments. Targeting shared infrastructure magnifies blast radius; hosting firms should harden management interfaces, audit cross‑tenant isolation, and instrument lateral‑movement detection.

Source: Cisco Talos


Malvertising campaign spreads PS1Bot framework to steal crypto and data

A widespread malvertising operation is pushing PS1Bot, a modular PowerShell‑based framework that steals credentials and crypto wallets, logs keystrokes, and captures screens. Defenders should clamp down on ad‑driven download flows, block PowerShell abuse via application control and constrained language mode, and monitor for suspicious script execution chains.

Source: HackRead


You May Also Be Interested In... - Canada’s House of Commons investigating data breach after cyberattack - For $40, you can buy stolen police and government email accounts - NIST concept paper outlines AI‑specific cybersecurity framework
Cybersecurity — August 15, 2025 | Briefing24