THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
13-Nation Advisory: China’s ‘Salt Typhoon’ has quietly burrowed into global critical infrastructure for years

Security agencies say China-linked operators exploited known flaws in routers and edge devices at telecom, government, transportation, lodging, and military networks to maintain stealthy persistence and siphon data. The multi-year campaign underscores the risk of aging network gear and weak segmentation; defenders are urged to patch edge appliances, rotate credentials, harden logging on routers, and monitor for anomalous lateral movement from network infrastructure.

Source: SecurityWeek


Salesloft/Drift OAuth breach widens—Google warns all integrations and tokens may be compromised

What began as a Salesforce-focused incident is now confirmed to affect all third-party integrations tied to the Drift platform, with attackers using stolen OAuth tokens to access Google Workspace email and more. Organizations should revoke and rotate all tokens connected to Drift, review OAuth grants across SaaS estates, and hunt for suspicious API activity and inbox access.

Source: TheHackerNews


AI-weaponized supply chain attack hits Nx build system, steals developer and cloud credentials

Attackers pushed trojanized Nx packages and plugins to npm that scanned file systems and exfiltrated thousands of secrets, marking a first-of-its-kind supply chain breach that leveraged AI assistants for data theft. Teams should pin/verify package versions, require provenance (Sigstore/SLSA), rotate any exposed credentials, and watch for anomalous CI activity and token usage.

Source: SecurityWeek


TransUnion breach exposes data of 4.4M+ people, including Social Security numbers

The credit reporting giant disclosed a third-party application compromise first detected July 30, with filings indicating SSNs were among the leaked data. Given the sensitivity and longevity of credit data, consumers and enterprises should assume sustained identity fraud risk, enroll in monitoring, and enable stronger verification for account changes.

Source: The Record


28,000+ Citrix NetScaler instances still vulnerable to actively exploited RCE (CVE-2025-7775)

Despite patches, tens of thousands of ADC and Gateway appliances remain exposed to a critical memory overflow bug that can enable DoS or remote code execution. Organizations should patch immediately, check for signs of compromise and persistence, rotate credentials, and consider isolating or replacing unsupported edge devices.

Source: SC Media


Attacker used agentic AI assistant to breach and extort 17 organizations end-to-end

Anthropic’s report details how an adversary scripted Claude Code to plan and execute intrusions, including reconnaissance, exploitation, data handling, and extortion playbooks. This signals a shift toward automated, scalable intrusions; defenders should restrict AI tooling access, monitor for machine-driven attack cadence, and double down on identity, data governance, and egress controls.

Source: Help Net Security


Microsoft: Ransomware actor shifts to stealing cloud data and locking companies out—no encryption needed

New tactics focus on exfiltrating cloud data and disabling access to critical services instead of deploying encryptors on endpoints. To blunt impact, enforce least-privilege on cloud identities, require MFA with phishing-resistant factors, tighten token lifetimes, and monitor for mass downloads, policy changes, and suspicious admin actions.

Source: The Record


You May Also Be Interested In...

FreePBX zero‑day under active attack—emergency patch released

FBI and Dutch Police seize VerifTools fake‑ID marketplace infrastructure

Passwordstate password manager: high‑severity auth bypass—patch now

Cybersecurity — August 29, 2025 | Briefing24