THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Citrix NetScaler zero-day exploited in the wild (CVE-2025-7775)

Citrix released fixes for three NetScaler ADC/Gateway flaws, confirming active exploitation of CVE-2025-7775, a memory overflow enabling pre-auth remote code execution or denial of service. This marks the third actively exploited NetScaler zero-day since June, underscoring persistent targeting of edge appliances—admins should patch immediately and audit for suspicious activity.

Source: CyberScoop


Widespread Salesforce data theft via compromised Salesloft Drift OAuth tokens

Google Threat Intelligence warns a threat actor (UNC6395) abused stolen OAuth and refresh tokens from Salesloft’s Drift integration to exfiltrate large volumes of data from numerous Salesforce instances. Tokens have been revoked, but impacted orgs should treat Salesforce data as compromised, scan for exposed secrets (e.g., AWS keys), rotate credentials, and review logs for IOCs and Drift-connected app activity.

Source: Google Threat Intelligence


Git arbitrary file write flaw actively exploited for RCE (CVE-2025-48384)

CISA added a newly patched Git vulnerability to its KEV catalog, confirming active exploitation of CVE-2025-48384. The bug stems from control-character handling mismatches that can enable arbitrary file writes leading to remote code execution—teams should update Git across developer systems and CI/CD runners without delay.

Source: SecurityWeek


‘ZipLine’ social engineering flips the script to breach U.S. manufacturing

Attackers initiate contact via public “Contact Us” forms, progressing into multi-week professional email exchanges (with NDAs) before delivering a malicious ZIP that drops MixShell in-memory malware. The campaign, now also using an “AI transformation” pretext, targets supply chain–critical manufacturers and uses DNS tunneling with HTTP fallback for C2—highlighting the need to vet inbound business requests and enforce strict attachment controls.

Source: Check Point Blog


Silk Typhoon hijacks captive portals to target diplomats

A Mustang Panda–linked cluster (Silk Typhoon) hijacked network captive portals to redirect victims to malware sites, focusing on diplomats in Asia. The technique bypasses user caution by abusing a trusted browsing moment—organizations should lock down captive portal infrastructure and monitor for unexpected redirect chains.

Source: BleepingComputer


Critical Docker Desktop flaw lets attackers escalate to Windows host admin

A critical vulnerability in Docker Desktop allows modification of the Windows host filesystem, enabling privilege escalation to administrator. Given Docker Desktop’s ubiquity in developer environments, rapid patching is essential, along with reviewing endpoint hardening and developer workstation EDR coverage.

Source: SecurityWeek


Researchers spot “PromptLock,” an early AI-powered ransomware concept

ESET researchers detailed PromptLock, described as the first known AI-assisted ransomware prototype that leverages an AI model to generate malicious logic. While not observed in active attacks yet, it signals an emerging trend toward AI-augmented malware development and faster iteration cycles for threat actors.

Source: The Register


You May Also Be Interested In...

Google to verify all Android developers to block malware on Google Play
Malware-ridden Android apps hit 19M downloads on Google Play
FTC urges tech firms to resist foreign anti-encryption demands
Cybersecurity — August 27, 2025 | Briefing24