THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Popular NPM Packages Poisoned in Supply Chain Attack, Aimed at Crypto Theft

A maintainer’s account was hijacked and at least 18 widely used npm packages were briefly trojanized with code that intercepts Web3 activity and rewrites wallet destinations. Researchers say the malware reached roughly 10% of cloud environments during a two-hour window, underscoring how fast dependency compromises can propagate. Teams should lock dependencies, audit build pipelines for suspicious token use, and rotate credentials.

Source: SecurityWeek


Microsoft Patch Tuesday: HPC Pack RCE and NTLM EoP Top a Busy Month

Microsoft’s September updates address ~80+ CVEs, including eight Critical issues; none are known to be actively exploited. Standouts include a wormable Remote Code Execution in High Performance Compute Pack (CVE-2025-55232), a GDI+ RCE reachable via web content, and an NTLM Elevation of Privilege bug. Prioritize patching HPC Pack clusters, harden/segment management interfaces, and consider temporarily disabling Office Preview Pane features.

Source: Zero Day Initiative


SAP Ships Critical Fixes: NetWeaver CVSS 10 and Previously Exploited S/4HANA Flaws

SAP released multiple critical patches, including CVE-2025-42944 (CVSS 10.0) in NetWeaver that can enable unauthenticated code execution, plus other high-severity issues and fixes for previously exploited S/4HANA bugs. SAP customers should apply updates immediately, restrict access to RMI and management interfaces, and monitor for suspicious deserialization or file-upload activity.

Source: The Hacker News


DoD Finalizes CMMC Rule: New Cyber Requirements for Defense Contractors

The US Department of Defense has finalized its Cybersecurity Maturity Model Certification (CMMC) rule, making third-party-validated security controls a prerequisite for many Pentagon contracts. The move tightens oversight of contractor cyber hygiene and supply-chain risk, aligning more closely with NIST 800-171 and elevating consequences for noncompliance.

Source: The Register


Mitsubishi Electric to Acquire Nozomi Networks in Major OT Security Deal

Mitsubishi Electric will acquire Nozomi Networks for nearly $1 billion, folding the OT/IoT security leader into its portfolio while keeping Nozomi’s San Francisco HQ. The deal signals continued consolidation in industrial cybersecurity and could accelerate integration of threat detection and asset visibility across automation ecosystems.

Source: SecurityWeek


Exposed Docker APIs Exploited to Build Botnet and Deploy Miners

Attackers are abusing internet-exposed Docker APIs to spin up containers, mount host file systems, pull payloads over Tor, and even block further API access. Activity points to cryptomining and botnet formation. Defenders should disable public Docker APIs, enforce TLS and authentication, restrict daemon access by firewall, and continuously audit container sprawl.

Source: SecurityWeek


Plex Breach Prompts Password Resets; Company Urges 2FA

Plex disclosed unauthorized access to a database containing emails, usernames, password hashes, and authentication data for a subset of users. The streaming platform is forcing password resets and recommending two-factor authentication to reduce the risk of account takeover and credential stuffing.

Source: SecurityWeek


You May Also Be Interested In...

Cisco puts agentic AI at the core of Splunk Enterprise Security
Nearly 500 researchers urge EU to rethink controversial CSAM scanning proposal
Signal adds secure backup option for chat history
Cybersecurity — September 10, 2025 | Briefing24