THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Widespread Salesforce–Salesloft Drift OAuth breach hits major security firms

Attackers abused compromised OAuth tokens from Salesloft’s Drift chatbot integration to access connected Salesforce tenants at Cloudflare, Palo Alto Networks, and Zscaler. Exfiltrated data includes customer contact information and support case metadata, raising the risk of highly convincing phishing and social engineering. The incident underscores how third‑party SaaS integrations and OAuth trust chains can become stealthy supply‑chain entry points.

Source: SecurityWeek


Cloudflare blocks record‑breaking 11.5 Tbps DDoS attack

Cloudflare mitigated the largest volumetric DDoS attack on record, peaking at 11.5 Tbps amid weeks of hyper‑volumetric assaults. The UDP flood, largely originating from cloud infrastructure, highlights adversaries’ ability to weaponize cloud bandwidth and the need for always‑on, automated DDoS defenses and upstream controls.

Source: SecurityWeek


Zero‑days chained: WhatsApp flaw exploited with Apple OS vulnerability in targeted spyware attacks

Meta patched CVE‑2025‑55177 impacting WhatsApp on iOS/macOS, which investigators say was chained with Apple’s CVE‑2025‑43300 to deliver zero‑click spyware against select high‑value targets. Users should urgently update WhatsApp and Apple devices; enterprises should review mobile threat detection and harden device exploit mitigations.

Source: SecurityWeek


Amazon disrupts APT29 watering‑hole campaign targeting Microsoft 365 users

Amazon dismantled a Russia‑linked APT29 operation that used compromised websites to trick users into authorizing attacker‑controlled devices in Microsoft 365. The campaign abused device authorization flows, reinforcing the need for conditional access, phishing‑resistant MFA, and tight governance over device trust and OAuth grants.

Source: SecurityWeek


Jaguar Land Rover operations ‘severely disrupted’ by cyberattack

JLR disconnected systems after a cyber incident that significantly impacted retail and manufacturing operations, leading to production stoppages. The company says there’s no evidence of customer data theft; the event spotlights the fragility of manufacturing IT/OT and the value of segmentation, incident response drills, and resilient run‑books.

Source: SecurityWeek


Critical FreePBX zero‑day actively exploited; Sangoma issues patches

A CVSS 10 flaw (CVE‑2025‑57819) in Sangoma FreePBX—caused by insufficient sanitization—was exploited in the wild to compromise servers. Admins should apply available updates immediately, review systems for indicators of compromise, and restrict internet exposure of management interfaces.

Source: SecurityWeek


Hexstrike‑AI shows how LLMs can accelerate zero‑day exploitation

Check Point warns a new framework, Hexstrike‑AI, can orchestrate over 150 specialized AI agents to autonomously scan, exploit, and persist in targets—potentially compressing exploitation cycles from days to minutes. Early dark‑web chatter claims use against recent zero‑days, signaling a rapid shift in attacker tradecraft and a need for AI‑aware detection and response.

Source: Check Point Blog


You May Also Be Interested In...

Salesloft takes Drift offline after OAuth token theft hits hundreds of organizations

BruteForceAI: Free AI‑powered login brute force tool

Frostbyte10 flaws put supermarket refrigeration at risk

Cybersecurity — September 3, 2025 | Briefing24