THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
FSB-linked ‘Static Tundra’ is hijacking end‑of‑life Cisco gear via a 2018 bug

Cisco Talos warns that Russia’s state-sponsored group “Static Tundra” is actively exploiting CVE-2018-0171 in Cisco IOS/IOS XE Smart Install to compromise unpatched, end‑of‑life network devices worldwide. Victims span strategic sectors, with attackers exfiltrating configs and establishing persistence. Defenders should disable Smart Install, migrate to supported images, lock down management/SNMP, rotate creds, and monitor for SMI/TFTP activity.

Source: Cisco Talos


Apple rushes fix for zero‑day exploited in highly targeted attacks (CVE‑2025‑43300)

Apple patched an Image I/O out‑of‑bounds write that can be triggered by malicious image files to corrupt memory and execute code. The flaw was used in “extremely sophisticated” targeted attacks; users should update iOS, iPadOS and macOS immediately and review image‑handling exposure in high‑risk workflows.

Source: SecurityWeek


Public exploit chain for critical SAP NetWeaver bugs raises takeover risk

A working exploit chaining CVE‑2025‑31324 (authorization bypass) and CVE‑2025‑42999 (insecure deserialization) in SAP NetWeaver is now public after prior in‑the‑wild use. Onapsis warns the chain can enable total system compromise; SAP admins should apply patches, restrict external exposure, and hunt for exploitation artifacts.

Source: Help Net Security


Unauthenticated RCE chains in Commvault backup suite — patch now

Commvault fixed four vulnerabilities that watchTowr Labs showed can be chained for pre‑auth remote code execution on on‑prem deployments. While PoCs weren’t released, the technical detail lowers the bar; given backups’ privileged reach, organizations should prioritize patching and tighten exposure of Commvault services.

Source: Help Net Security


Browser password managers exposed to clickjacking data theft

Research reveals “DOM‑based extension clickjacking” flaws in several popular password manager extensions, enabling theft of credentials, 2FA codes, and payment data under specific UI‑redress conditions. Until patches land, disable automatic autofill, require explicit user action to fill, and limit extension permissions on untrusted sites.

Source: The Hacker News


‘RapperBot’ DDoS botnet disrupted; alleged admin indicted

U.S. authorities dismantled the RapperBot (aka CowBot/Eleven Eleven) botnet and charged its alleged operator, accused of renting out the service for hundreds of thousands of DDoS attacks. The botnet relied on compromised IoT devices (DVRs/routers), underscoring the need to secure edge gear and block default creds.

Source: SecurityWeek


SharePoint on‑prem zero‑day campaign hits UK organizations

At least three British organizations reported to the ICO that attackers exploited bugs in on‑prem Microsoft SharePoint servers, indicating active zero‑day targeting. Enterprises running on‑prem SharePoint should accelerate patching, reduce public exposure, enforce strict auth, and monitor for web shell and anomalous process activity.

Source: The Record by Recorded Future News


You May Also Be Interested In...

Scattered Spider SIM-swapper gets 10 years, $13M restitution (KrebsOnSecurity)
Orange Belgium breach affects 850,000 customer accounts (SecurityWeek)
Proofpoint: URL-based threats now dominate phishing campaigns (Help Net Security)
Cybersecurity — August 21, 2025 | Briefing24