THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Supply chain fallout: Cloudflare confirms Drift-linked breach; OAuth tokens targeted across SaaS

Cloudflare said it was impacted by the Salesloft Drift supply chain incident, with attackers accessing 104 Cloudflare API tokens that have since been rotated. The Drift exploitation campaign has hit numerous Salesforce instances by abusing OAuth tokens and third‑party integrations, underscoring the need to inventory and restrict SaaS-to-SaaS access and monitor CRM app tokens.

Source: Help Net Security


Android patches two exploited flaws amid massive monthly update

Google fixed 120 Android vulnerabilities this month, including two exploited elevation-of-privilege bugs in Android Runtime (CVE-2025-48543) and the Linux kernel (CVE-2025-38352). Enterprises should fast‑track OTA updates and plan mitigations for devices stuck on older builds due to OEM fragmentation.

Source: SecurityWeek


Sitecore zero‑day: ViewState deserialization RCE traced to old sample keys

Attackers are exploiting CVE-2025-53690 to achieve RCE on Sitecore deployments by leveraging sample machine keys published in older deployment guides. Google/Mandiant observed post‑exploitation tool staging (EARTHWORM tunneling, DWAgent, SharpHound) and advise immediate key rotation, enabling ViewState MAC, and following Sitecore remediation guidance.

Source: SecurityWeek


Cloudflare mitigates record 11.5 Tbps DDoS as hyper‑volumetric attacks surge

Cloudflare neutralized the largest recorded volumetric DDoS attack, peaking at 11.5 Tbps in a short burst, part of a broader wave of “hyper‑volumetric” events in recent weeks. The incident highlights attackers’ growing capacity to briefly overwhelm targets and the importance of auto‑mitigation and anycast architectures.

Source: BleepingComputer


Mis‑issued TLS certificates for 1.1.1.1 raise Internet trust concerns

Three mistakenly issued certificates covering Cloudflare’s 1.1.1.1 DNS service came to light, posing potential risks if abused to impersonate services and intercept traffic. The episode spotlights persistent challenges in the public CA ecosystem and the need for vigilant issuance monitoring and rapid revocation.

Source: Ars Technica


US and allies push SBOM adoption to harden software supply chains

US and partner nations urged broader, standardized use of software bills of materials (SBOMs) to improve transparency, reduce risk, and lower lifecycle costs. The guidance emphasizes interoperable formats and automated exchange so buyers can map dependencies and respond faster to newly discovered component flaws.

Source: SecurityWeek


Report: Attackers weaponize Salesforce trust; detections up 20× in 2025

WithSecure research shows a sharp rise in malicious activity inside Salesforce environments, with adversaries abusing trusted CRM channels and ordinary documents/QR codes to deliver payloads. The findings reinforce the need for stricter access controls, app allow‑listing, and continuous monitoring within SaaS platforms.

Source: Help Net Security


You May Also Be Interested In...
With less than a month to go, House panel votes to extend popular cyber programs
European Court rejects challenge to EU-US data transfer agreement
Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086
Cybersecurity — September 4, 2025 | Briefing24