THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Docker Desktop patches critical container escape (CVE-2025-9074)

A critical flaw in Docker Desktop for Windows and macOS (CVSS 9.3) allows a malicious container to break out and compromise the host, even when Enhanced Container Isolation is enabled. Admins should upgrade immediately to version 4.44.3 and avoid running untrusted images in developer environments where host credentials and secrets are often accessible.

Source: BleepingComputer


CISA adds exploited Git and Citrix bugs to KEV—patch now

US CISA added an exploited arbitrary file write in Git and a Citrix Session Recording vulnerability to its Known Exploited Vulnerabilities catalog, signaling active in-the-wild attacks. Federal agencies (and everyone else) should prioritize patching, inventory Git client/server usage across developer endpoints and CI systems, and mitigate Citrix exposure per vendor guidance.

Source: Security Affairs


PRC-nexus UNC6384 hijacks captive portals to deliver PlugX to diplomats

Google’s Threat Intelligence Group detailed a sophisticated espionage chain that hijacks captive-portal checks to redirect targets to a fake plugin page signed with a valid cert, then side-loads a DLL to deploy the SOGU.SEC (PlugX) backdoor. The campaign, aimed at diplomats in Southeast Asia, blends AitM tactics, code signing abuse, and memory-only payloads—defenders should monitor for captive-portal redirects, DLL sideloading, and associated IOCs.

Source: Google Cloud Threat Intelligence


77 malicious Android apps (19M installs) removed from Google Play

Researchers found 77 apps on Google Play with over 19 million installs distributing various malware families, including the Anatsa (TeaBot) banking trojan. Enterprises should audit managed Android fleets for the listed packages, enforce MDM policies to block risky categories, and enable Play Protect; consumers should remove unknown utilities and check app permissions.

Source: BleepingComputer


Global phishing wave uses UpCrypter to drop RATs via fake voicemail emails

FortiGuard Labs uncovered a campaign abusing convincing voicemail and purchase order lures to deliver UpCrypter, which then installs RATs like PureHVNC and DCRat across multiple industries. Block JavaScript attachments and HTA downloads at the email gateway, apply URL rewriting/sandboxing, and hunt for UpCrypter and RAT beacons in your EDR/NGFW telemetry.

Source: Fortinet


AI prompt injection via image scaling can exfiltrate data

New research shows attackers can hide malicious instructions inside images that trigger during downscaling, causing popular AI systems to follow injected prompts and leak sensitive data. Organizations deploying LLMs or AI assistants should treat all media as untrusted input, add image pre-processing/sanitization, and implement strict output filtering and allow-listing for tool use.

Source: SecurityWeek


Farmers Insurance breach hits 1.1M via third‑party Salesforce attacks

Farmers Insurance disclosed a data breach affecting 1.1 million customers after a third-party vendor tied to the recent wave of Salesforce compromises was attacked. The incident underscores SaaS and supply-chain risk; review partner access, rotate API keys/tokens, enforce SSO and scoped permissions for CRM integrations, and enable anomaly monitoring.

Source: BleepingComputer


You May Also Be Interested In...

Surge in coordinated scans targets Microsoft RDP auth servers

ScreenConnect admins targeted with spoofed login alerts

Arch Linux Project responding to week-long DDoS attack

Cybersecurity — August 26, 2025 | Briefing24