THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Sitecore zero-day exploited via exposed sample machine key (CVE-2025-53690)

Attackers are abusing a ViewState deserialization flaw in Sitecore deployments where a sample ASP.NET machine key from older guides was left in place, enabling remote code execution and malware delivery. Organizations running Sitecore XM, XP, XC, or Managed Cloud with the sample key are at risk and should immediately replace keys, harden configurations, and hunt for post-exploitation activity.

Source: SecurityWeek


Google patches two Android flaws already under targeted exploitation

Google shipped fixes for CVE-2025-48543 (Android Runtime) and CVE-2025-38352 (Linux kernel) that have been exploited in the wild in limited, targeted attacks. Admins should prioritize deploying September 2025 Android updates across fleets and verify OEM patch levels, especially for high-risk users.

Source: SecurityWeek


Critical SAP S/4HANA code injection bug (CVE-2025-42957) exploited in the wild

A recently disclosed SAP S/4HANA vulnerability allowing full system takeover is being actively exploited. Organizations should apply SAP’s patches without delay and review systems for signs of compromise, given the potential for deep business process impact.

Source: SecurityWeek


Salesforce-Salesloft Drift supply chain attack widens, hits more cybersecurity vendors

Proofpoint, SpyCloud, Tanium, and Tenable joined a growing list of companies disclosing exposure via stolen OAuth tokens tied to Salesloft Drift, with attackers accessing data stored in Salesforce instances. The campaign’s blast radius remains under assessment; rotate tokens, review app integrations, and enforce least privilege on connected SaaS platforms.

Source: SecurityWeek


GhostRedirector: New group hijacks search results with custom IIS module and C++ backdoor

ESET uncovered “GhostRedirector,” a likely China-linked actor compromising at least 65 Windows servers and deploying a passive C++ backdoor (Rungan) plus a malicious IIS module (Gamshen) to manipulate Google search results. Targeted servers were primarily in Brazil, Thailand, Vietnam, and the U.S., highlighting a blend of SEO fraud and stealthy persistence.

Source: ESET Blog


New TP-Link router zero-day emerges as CISA flags active exploitation of other TP-Link flaws

TP-Link confirmed an unpatched zero-day impacting multiple router models, while CISA warned that other TP-Link vulnerabilities have been exploited in attacks. Until patches are available, defenders should disable remote management, segment or replace EoL hardware, and monitor for suspicious outbound traffic from SOHO gear.

Source: BleepingComputer


AI supply chain risk: “Model Namespace Reuse” enables malicious model swaps

Researchers demonstrated an AI supply chain weakness dubbed Model Namespace Reuse that allows attackers to publish malicious models under trusted names and achieve code execution in products from major vendors. The finding underscores the need for model signing, strict provenance checks, and runtime isolation in AI pipelines.

Source: SecurityWeek


You May Also Be Interested In...
Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1 (Cloudflare)
Russian APT28 Deploys “NotDoor” Outlook Backdoor (The Hacker News)
Czech cyber agency warns against services that send data to China (The Record)
Cybersecurity — September 5, 2025 | Briefing24