THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Salesloft token heist ripples across the SaaS ecosystem

Mass theft of OAuth and session tokens from Salesloft has triggered an urgent scramble among enterprises to revoke access across integrated apps. Google warned the impact extends far beyond Salesforce, with valid tokens for Slack, Google Workspace, AWS, Azure, OpenAI and more, while downstream victims like Zscaler disclosed data exposure via the compromised integration—an object lesson in supply-chain blast radius and token hygiene.

Source: KrebsOnSecurity


WhatsApp patches zero‑click exploit used alongside Apple bug

WhatsApp fixed CVE-2025-55177, a flaw in linked-device sync message authorization that was abused in sophisticated, zero-click attacks. The exploit was reportedly chained with an Apple vulnerability, underscoring the need for rapid app updates and enabling phishing‑resistant protections like device locks and two-step verification.

Source: Malwarebytes


Amazon disrupts Russian APT29 watering-hole targeting Microsoft 365 auth

Amazon’s security team dismantled an APT29/Midnight Blizzard campaign that used compromised sites and malicious redirects to intercept Microsoft authentication flows and access M365 data. The operation highlights the continued targeting of identity providers and cloud SSO paths—defenders should review conditional access policies, token lifetimes, and sign-in anomalies.

Source: BleepingComputer


Signed driver abuse lets Silver Fox deploy ValleyRAT via BYOVD

Researchers attribute a Bring Your Own Vulnerable Driver (BYOVD) technique to Silver Fox, which abused a validly signed but vulnerable WatchDog Anti‑malware driver (amsdk.sys) to disable security products and drop ValleyRAT. The case reiterates the importance of kernel‑mode driver controls (e.g., Microsoft’s blocklist, HVCI/Memory Integrity) and vigilant EDR tamper protection.

Source: The Hacker News


Lazarus subgroup expands RAT arsenal against finance and crypto

Fox‑IT and NCC Group detail a Lazarus subgroup overlapping AppleJeus/Citrine Sleet/UNC4736/Gleaming Pisces using multiple RATs to compromise financial and cryptocurrency targets. The campaigns blend social engineering, supply-chain touchpoints, and bespoke implants—organizations should harden macOS/Windows developer workflows and enforce strict code‑signing and wallet segregation.

Source: Fox‑IT Blog


Frostbyte10 flaws threaten cold-chain: patch Copeland controllers now

Ten vulnerabilities in Copeland refrigeration controllers deployed across major grocers and cold storage sites could allow attackers to alter temperatures, risking mass spoilage of food and medicine. Operators should prioritize vendor updates, segment OT networks, and monitor for anomalous setpoint changes to protect critical supply chains.

Source: The Register


Sextortion at scale: 1,900 emails, 205 BTC addresses over four years

SANS ISC analyzed nearly 2,000 sextortion messages tied to 205 Bitcoin addresses, mapping operational patterns over multiple years. Findings can help defenders auto‑triage extortion spam, block recurrent wallet clusters, and educate users to reduce payment rates that keep these low‑effort scams profitable.

Source: SANS Internet Storm Center


You May Also Be Interested In...

Malicious npm package mimics Nodemailer to backdoor Atomic/Exodus wallet apps

Cisco finds 1,100+ Ollama AI servers exposed to the internet

NCSC UK: Adapting vulnerability disclosure models for AI safeguard bypasses

Cybersecurity — September 2, 2025 | Briefing24