THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Critical SAP S/4HANA Flaw (CVE-2025-42957) Under Active Exploitation—Patch Immediately

A critical command injection vulnerability in SAP S/4HANA (CVE-2025-42957, CVSS 9.9) is being actively exploited, allowing attackers to take full control of affected systems. Organizations should urgently apply available patches, review access logs for suspicious activity, and isolate exposed instances to reduce blast radius.

Source: HackRead


GhostAction Supply-Chain Attack Exfiltrates 3,325 Secrets from GitHub Projects

A widespread supply-chain campaign dubbed “GhostAction” compromised 817 GitHub repositories and siphoned 3,325 secrets, including npm, PyPI, and DockerHub tokens. The attack abused malicious GitHub Actions workflows to harvest CI/CD credentials—teams should audit workflows, revoke exposed tokens, and enforce least-privilege for automation.

Source: HackRead


Salesloft Breach Hits Multiple Security Vendors; Sitecore Zero‑Day (CVE-2025-53690) Exploited

Fallout from a breach at Salesloft—attributed by Google to UNC6395—continues as Zscaler, Palo Alto Networks, PagerDuty, Tanium, and SpyCloud confirmed unauthorized access to their Salesforce instances. Separately, attackers are exploiting a Sitecore zero‑day (CVE-2025-53690), underscoring the need to review SaaS integrations, OAuth scopes, and web CMS patch posture.

Source: Help Net Security


‘Noisy Bear’ Targets Kazakhstan’s Energy Sector in Operation BarrelFire

A new threat group tracked as Noisy Bear, possibly of Russian origin, is conducting phishing campaigns against Kazakhstan’s energy sector, including employees of KazMunaiGas (KMG). Active since at least April 2025, the operation blends social engineering and tailored lures to gain footholds in critical energy infrastructure.

Source: The Hacker News


MeetC2: Serverless C2 Over Google Calendar Shows How Attackers Blend in with Cloud Traffic

Researchers released MeetC2, a proof‑of‑concept command‑and‑control framework that uses Google Calendar APIs as its communications channel. The tool is designed to help red and blue teams emulate modern adversaries who hide C2 inside ubiquitous cloud services, and to validate detection, logging, and response coverage for SaaS APIs.

Source: Security Affairs


Scammers Abuse Grok on X to Slip Malicious Links Past Ad Policies

Attackers are “grokking” on X—leveraging Grok to embed malicious links and circumvent the platform’s ban on URLs in promoted posts. The tactic boosts reach for scam content, signaling that adversaries are adapting quickly to AI‑driven content tools and ad policy guardrails.

Source: Dark Reading


Report: ICE Has Spyware Now

Wired reports that US Immigration and Customs Enforcement (ICE) now has spyware capabilities, highlighting a growing expansion of government surveillance tooling. The development raises oversight and privacy concerns for civil society and underscores the need for transparent governance around powerful monitoring technologies.

Source: Wired


You May Also Be Interested In...

Google Confirms Android Attacks—No Fix For 1 Billion Phones

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

WTF is going on with age verification laws?

Cybersecurity — September 7, 2025 | Briefing24