THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
FBI warns of Salesforce-targeted data theft by UNC6040 and UNC6395

The FBI issued a flash alert with IOCs for two cybercriminal groups increasingly targeting organizations’ Salesforce environments for data theft and extortion. The campaigns use different initial access paths, emphasizing the need to lock down third‑party integrations, enforce phishing-resistant MFA, monitor unusual API usage, and restrict data exports from SaaS platforms.

Source: TheHackerNews


HybridPetya bootkit bypasses UEFI Secure Boot, echoing Petya/NotPetya tactics

ESET researchers analyzed “HybridPetya,” a ransomware strain capable of infecting EFI partitions and bypassing UEFI Secure Boot on out-of-date systems via CVE‑2024‑7344. The malware revives destructive Petya/NotPetya-style techniques at the firmware level, underscoring the urgency of firmware updates, Secure Boot DBX revocations, and rigorous device hardening.

Source: Security Affairs


New “VoidProxy” PhaaS bypasses MFA for Microsoft and Google via AiTM

Okta Threat Intelligence exposed “VoidProxy,” a phishing-as-a-service platform that uses Adversary‑in‑the‑Middle reverse proxies to steal session tokens and sidestep MFA. Defenders should prioritize phishing-resistant authentication (FIDO2/WebAuthn), token binding/device trust, conditional access, and rigorous domain controls to blunt AiTM campaigns.

Source: HackRead


Record L7 DDoS attack from 5.76M-device botnet mitigated by Qrator Labs

Qrator Labs reports blocking a massive application-layer DDoS targeting government infrastructure, sourced from a botnet that surged globally since March to 5.76 million devices. The scale and speed highlight the need for adaptive L7 protections, anycast architectures, bot management, and anomaly-driven rate controls.

Source: HackRead


Samsung patches Android 0‑day (CVE‑2025‑21043) exploited in the wild

Samsung fixed a critical out‑of‑bounds vulnerability affecting Android 13–16 on its devices that may allow remote code execution and was reportedly exploited, potentially to spy on encrypted messaging content. Users and enterprises should apply the latest Samsung security updates immediately and review device telemetry for signs of compromise.

Source: CISO2CISO


CISA signals intent to keep federal control over the CVE program

After nearly allowing the CVE program to lapse earlier this year, CISA published a new “vision” that points to maintaining government stewardship of the global vulnerability ID system. The move reopens debate about governance, funding stability, and community participation in vulnerability disclosure and coordination.

Source: CISO2CISO


ShinyHunters breach Vietnam’s National Credit Information Center

Vietnam’s VNCERT confirmed signs of unauthorized access at the National Credit Information Center (CIC) aimed at stealing personal data, with ShinyHunters claiming responsibility. The incident puts sensitive credit and identity data at risk and underscores the need for robust segmentation, data loss monitoring, and rapid breach notification processes.

Source: Security Affairs


You May Also Be Interested In...

Cybersecurity — September 14, 2025 | Briefing24