THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
OAuth token mega-campaign widens: Google says Salesloft Drift breach hit Workspace and all integrations

Google confirmed that the OAuth token theft campaign tied to Salesloft’s Drift AI chat integration extended beyond Salesforce, enabling access to a small number of Google Workspace accounts as well. Organizations are urged to assume all tokens stored in or connected to Drift were compromised, revoke/rotate them, audit logs for abuse, and temporarily disable affected integrations until vendors complete remediation.

Source: SecurityWeek


WhatsApp issues emergency patches after zero-click spyware attacks on iOS and macOS

WhatsApp fixed CVE-2025-55177, a vulnerability exploited in targeted zero-day attacks that abused insufficient authorization in linked device sync messages—reportedly chained with a recent Apple flaw. Apple users should update WhatsApp on iOS and macOS immediately, review linked devices, and consider hardening high-risk targets with additional protections.

Source: The Hacker News


Actively exploited CVSS 10 FreePBX zero-day: patch now and lock down admin panels

Sangoma disclosed an actively exploited FreePBX zero-day (CVE-2025-57819, CVSS 10) impacting systems with an internet-exposed Administrator Control Panel. Apply the emergency fix, restrict the ACP to internal networks/VPN, and monitor for suspicious PowerShell or web shell activity linked to PBX hosts.

Source: The Hacker News


AWS disrupts APT29 watering‑hole abusing Microsoft device code to hijack accounts

Amazon’s threat intel team disrupted a Russia-linked APT29 campaign that used compromised sites to redirect victims to malicious infrastructure and trick them into approving attacker-controlled devices via Microsoft’s device code flow. Enterprises should review device code grant usage, enforce Conditional Access, and hunt for anomalous OAuth/device authorization events in sign-in logs.

Source: AWS Security Blog


Passwordstate patches authentication bypass granting Emergency Access admin — update immediately

Click Studios released Passwordstate 9.9 (Build 9972) to fix an authentication bypass that could grant access to an emergency admin account via a crafted URL, potentially affecting tens of thousands of orgs. Update right away, rotate sensitive credentials stored in Passwordstate, and review access logs for suspicious Emergency Access usage.

Source: The Register


Microsoft to enforce MFA for all Azure resource management in October

Starting in October, Microsoft will require multi-factor authentication for all Azure resource management actions to reduce unauthorized access. Admins should ensure accounts are enrolled in MFA, validate Conditional Access baselines, and test automation paths (e.g., service principals) to avoid disruption.

Source: BleepingComputer


Ransomware takedowns spawn wave of smaller crews and rebrands

Law enforcement actions are splintering the ransomware ecosystem, scattering affiliates and triggering a proliferation of smaller, fast-moving groups. Defenders should prioritize detecting shared TTPs and infrastructure reuse across “new” brands, rather than relying on operator-name threat models alone.

Source: The Record


You May Also Be Interested In...

TransUnion Data Breach Impacts 4.4 Million

Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution

Almost all Americans likely compromised by Salt Typhoon, FBI official says

Cybersecurity — August 30, 2025 | Briefing24