THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Attackers are exploiting critical SAP S/4HANA flaw (CVE-2025-42957)

A 9.9 CVSS code injection vulnerability in SAP S/4HANA is under active exploitation, allowing attackers to achieve full system takeover. Successful compromise can enable database manipulation, creation of superuser accounts, and credential theft; organizations should urgently apply SAP’s August security updates and increase monitoring for suspicious activity.

Source: SecurityWeek


CISA orders agencies to patch Sitecore zero-day after hacking reports

Following advisories from Sitecore and Mandiant, CISA added CVE-2025-53690 to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies three weeks to patch. The configuration flaw enables remote code execution via a sample machine key in older deployments, with observed post-compromise activity including privilege escalation and lateral movement.

Source: The Record


‘SEO fraud-as-a-service’ hijacks Windows servers to juice gambling sites

ESET researchers uncovered “GhostRedirector,” a scheme that compromises Windows servers and manipulates search traffic to promote gambling websites. The campaign abuses SEO and server-side malware to redirect users at scale, highlighting the importance of hardening web servers, auditing scheduled tasks, and monitoring for unauthorized web shell activity.

Source: The Record


Salesforce–Salesloft–Drift breach impacts more cybersecurity firms

Proofpoint, SpyCloud, Tanium, and Tenable confirmed threat actors accessed data stored in their Salesforce instances via the Salesforce–Salesloft–Drift supply-chain incident. The campaign, linked to UNC6395, underscores third-party SaaS risk; organizations should review connected app permissions, rotate tokens/API keys, and tighten data access policies in CRM platforms.

Source: SecurityWeek


Stealthy attack serves poisoned web pages only to AI agents

JFrog detailed a novel prompt-injection technique that displays hidden, malicious content solely to autonomous AI agents—while keeping pages benign to human users. The approach can covertly hijack agent behavior, enabling data exfiltration or unsafe actions; defenses include agent-side origin allowlists, content sanitization, and robust output validation.

Source: Help Net Security


Nexar dashcam video database hacked

A hacker breached a database containing video recordings from Nexar-branded in-vehicle cameras, raising serious privacy and safety concerns. The exposure of road footage can reveal sensitive locations and routines; companies handling telematics and video data should enforce strict access controls, token hygiene, and retention minimization.

Source: Malwarebytes Blog


‘GPUGate’: Fake GitHub Desktop installers use GPU-gated decryption and Google Ads lures

Arctic Wolf Labs uncovered a malvertising chain abusing Google Ads and GitHub’s repository structure to deliver trojanized GitHub Desktop installers. The payload remains encrypted unless a GPU is present, hindering analysis and sandboxes; verify installer hashes, restrict ad-based software downloads, and deploy EDR to detect post-execution anomalies.

Source: Arctic Wolf Labs


You May Also Be Interested In...

Cybersecurity — September 6, 2025 | Briefing24