THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Salesforce data theft hits hundreds of orgs via stolen OAuth tokens

Google’s Threat Intelligence Group says threat actor UNC6395 siphoned corporate data from Salesforce instances by abusing OAuth/refresh tokens stolen from the Salesloft Drift integration. Attackers hunted for high‑value secrets, including AWS access keys and Snowflake tokens, raising the risk of follow‑on compromise across cloud environments. Organizations should revoke affected tokens, review Salesforce connected apps, and rotate any exposed credentials.

Source: Help Net Security


Citrix rushes patch for actively exploited NetScaler zero‑day

Citrix released fixes for a NetScaler ADC/Gateway zero‑day exploited in the wild, prompting CISA to set emergency patch deadlines for federal agencies. The flaw enables remote code execution and has already been used in attacks, underscoring the urgency to update, audit for indicators of compromise, and check for possible persistence.

Source: SecurityWeek


AI‑powered ransomware “PromptLock” emerges with cross‑platform capabilities

ESET researchers uncovered PromptLock, an experimental ransomware that uses a locally run OpenAI gpt‑oss:20b model (via Ollama) to generate malicious Lua scripts in real time. The proof‑of‑concept targets Windows, Linux, and macOS, signaling how generative AI can automate payload creation and adaptation, lowering barriers for threat actors.

Source: SecurityWeek


NPM supply chain attack poisons Nx packages to steal developer secrets

Wiz detailed “s1ngularity,” a software supply chain compromise that pushed malicious Nx NPM packages designed to exfiltrate secrets from developers and CI environments. Organizations using impacted versions should immediately audit dependencies, pin trusted releases, rotate tokens and keys, and scan repos for leaked credentials.

Source: Wiz


Storm‑0501 pivots to cloud ransomware tactics targeting Azure

Microsoft warns that financially motivated group Storm‑0501 has evolved from on‑prem encryption to cloud‑centric extortion, abusing Entra ID access to exfiltrate and encrypt data in Azure. The actor has also leveraged compromised Microsoft Teams accounts for ransom communications, highlighting the need for strong identity controls, conditional access, and tenant‑wide monitoring.

Source: Microsoft Security Blog


FreePBX zero‑day exploited in the wild; emergency fix available

Sangoma’s FreePBX team disclosed active exploitation of a zero‑day affecting systems with the Administrator Control Panel exposed to the internet. An emergency patch is available; admins should apply it immediately, restrict ACP exposure, and review logs for suspicious access.

Source: BleepingComputer


Allied advisory ties China’s Salt Typhoon to tech firms as global targeting expands

Security agencies from over a dozen countries linked the long‑running Salt Typhoon campaigns to three China‑based tech companies, warning of operations spanning more than 80 countries. The activity extends beyond telecom to transportation and military infrastructure, emphasizing the need for rigorous patching, segmentation, and credential hygiene in critical networks.

Source: BleepingComputer


You May Also Be Interested In...

300k+ Plex Media Server instances still vulnerable to CVE-2025-34158

77 malicious apps removed from Google Play Store

Docker Desktop vulnerability allowed host takeover on Windows and macOS

Cybersecurity — August 28, 2025 | Briefing24