THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
WinRAR 0‑day exploited by multiple threat actors; Microsoft patches critical Kerberos flaw

Two distinct groups, including Paper Werewolf and RomCom, are actively exploiting a newly disclosed WinRAR vulnerability (CVE-2025-8088) in zero‑day attacks. Microsoft also addressed a critical Kerberos issue dubbed “BadSuccessor” (CVE-2025-53779) in August Patch Tuesday—organizations should urgently patch Windows, update WinRAR, and review email/file scanning policies for archive files.

Source: Help Net Security


Critical Cisco FMC RADIUS RCE allows unauthenticated command injection (CVE-2025-20265)

Cisco disclosed a critical remote code execution flaw in Secure Firewall Management Center’s RADIUS subsystem that lets unauthenticated attackers inject shell commands. Environments using RADIUS for FMC authentication should patch immediately, restrict management-plane access, and monitor for anomalous RADIUS activity until remediation is verified.

Source: CISO2CISO


FortiWeb WAF: Researcher to release exploit for full authentication bypass

A security researcher published a partial PoC for a FortiWeb vulnerability enabling remote authentication bypass, with plans to release a full exploit. Organizations should apply Fortinet’s fixes where available, restrict management interfaces, and enforce network segmentation to prevent WAF takeover.

Source: BleepingComputer


ERMAC 3.0 Android banking trojan source leak exposes ops and expanded targeting

Researchers analyzed a full source code leak of ERMAC 3.0, revealing major upgrades that expand form-injection and data theft against 700+ banking, shopping, and crypto apps. The leak also exposes operational weaknesses defenders can leverage for detection and takedown; enterprises should harden Android fleets and scrutinize overlay/Accessibility abuse.

Source: The Hacker News


“Man‑in‑the‑Prompt” attack hijacks AI assistants via simple browser extensions

A new attack class dubbed Man‑in‑the‑Prompt can silently intercept and modify prompts and responses for tools like ChatGPT, Gemini, Copilot, and Claude via low‑friction browser extensions. The technique highlights emerging supply‑chain risk in AI workflows—lock down extension policies, audit browser add‑ons, and route AI tool access through secured, monitored environments.

Source: Security Affairs


EncryptHub exploits “MSC EvilTwin” (CVE-2025-26633) with rogue .msc files to drop malware

Threat actor EncryptHub is abusing a now‑patched Windows MMC flaw to deliver malware via malicious .msc files, pairing the technique with social engineering (including fake Brave Support). Patch CVE‑2025‑26633, block or scrutinize .msc attachments, and harden file association policies to blunt this vector.

Source: Security Affairs


Norway dam sabotage likely linked to pro‑Russian hackers, police say

Norwegian authorities assess that pro‑Russian hackers were likely behind a suspected cyber sabotage incident at a dam in April that disrupted water flows. The case underscores increasing cyber‑enabled operations against Western critical infrastructure—operators should review ICS segmentation, remote access controls, and anomalous OT network monitoring.

Source: CISO2CISO


You May Also Be Interested In...
CISA warns of active exploitation of N‑able N‑central vulnerabilities
Chinese‑speaking APT UAT‑7237 targets Taiwan’s web infrastructure with custom toolset
Free decryptor released for Phobos and 8Base ransomware victims
Cybersecurity — August 17, 2025 | Briefing24