THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CrushFTP Zero‑Day Under Active Exploitation Enables Admin Takeover (CVE-2025-54309)

watchTowr Labs disclosed an actively exploited zero‑day in CrushFTP that allows attackers to gain administrative access via the web interface. Organizations are urged to patch immediately to v10.8.5 or v11.3.4, review management access exposure, and rotate credentials/tokens that may have been accessed. This is a widely used file transfer platform, so downstream data exposure should be assessed.

Source: HackRead


FreePBX Zero‑Day Exploited in the Wild Against Internet‑Exposed Admin Panels (CVE-2025-57819)

Sangoma warned of an actively exploited, critical FreePBX flaw (CVSS 10.0) impacting systems with an internet‑facing Admin Control Panel. Defenders should immediately restrict ACP exposure, apply vendor fixes/workarounds, and monitor for suspicious admin actions and outbound connections from PBX hosts.

Source: CISO2CISO (via Security Affairs)


WhatsApp Pushes Emergency Fix for Zero‑Click Exploit Hitting iOS and macOS (CVE-2025-55177)

WhatsApp released an update to address a zero‑click vulnerability that may have been exploited in targeted attacks, reportedly in conjunction with a recently disclosed Apple flaw. Users on iOS and macOS should update immediately, and high‑risk users should enable automatic updates and review device indicators for compromise.

Source: CISO2CISO (via The Hacker News)


Salesloft Drift OAuth Breach Impacts All Integrations—Treat Tokens as Compromised

Google and incident responders warn the Salesloft Drift OAuth incident is broader than initially believed, affecting all integrations, not just Salesforce. Organizations should revoke and rotate all tokens connected to the Drift platform, audit integration activity for suspicious access, and tighten OAuth scopes and monitoring.

Source: CISO2CISO (via Security Affairs)


Living-Off-the-Land: Velociraptor Abused to Run VS Code for C2 Tunneling

Researchers detailed an intrusion where attackers deployed the legitimate Velociraptor forensic tool to download and execute Visual Studio Code, likely to establish command‑and‑control tunneling. The case underscores persistent abuse of trusted admin and developer tools; defenders should baseline and alert on unauthorized EDR/DFIR utilities and anomalous VS Code use on servers.

Source: The Hacker News


TamperedChef Infostealer Pushed via Fraudulent “PDF Editor” in Google Ads

Threat actors are distributing the TamperedChef infostealer through convincing PDF editing apps promoted by Google ads and multiple look‑alike websites. The campaign targets users seeking free productivity tools—block suspicious ads, enforce application allow‑listing, and monitor for credential theft and browser data exfiltration.

Source: BleepingComputer


Salt Typhoon Campaign Declared a National Defense Crisis by U.S. and Allies

Authorities characterized the China‑linked Salt Typhoon telecom intrusions as a national defense crisis, citing extensive infiltration across 80 countries. The escalation signals more aggressive defensive and policy responses; telecoms and critical infrastructure operators should accelerate hardening of network management systems, identity controls, and supply‑chain vetting.

Source: Forbes


You May Also Be Interested In...

Cisco Identity Services Engine Authenticated RCE and Authorization Bypass Vulnerabilities

Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability

Lab Dookhtegan Hacking Group Disrupts Comms on Dozens of Iranian Ships

Cybersecurity — August 31, 2025 | Briefing24