THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Apple ships iOS 26 and macOS Tahoe 26 with 50+ security fixes

Apple released major platform updates across iPhone, iPad, Mac, watch, and TV that patch more than 50 vulnerabilities, including an exploited bug on older platforms. With Apple now aligning version numbers to “26,” enterprises should prioritize rapid testing and deployment, especially for WebKit and kernel fixes. Notably, VisionOS was not updated this cycle.

Source: SecurityWeek


FBI releases IoCs as criminals target Salesforce to steal data and extort victims

The FBI published indicators of compromise tied to campaigns by UNC6040 and UNC6395, warning that threat actors are breaching Salesforce instances to exfiltrate data and pressure organizations for payment. The advisory urges reviews of connected apps and OAuth scopes, tighter API and SSO configurations, and active monitoring of audit logs for suspicious access.

Source: SecurityWeek


‘Phoenix’ RowHammer bypasses DDR5 defenses in 109 seconds, enabling privilege escalation

Researchers from ETH Zürich and Google disclosed Phoenix (CVE-2025-6202), a new RowHammer technique that defeats enhanced Target Row Refresh (TRR) and in-DRAM protections on SK Hynix DDR5. The team demonstrated the first RowHammer-based privilege escalation on a production DDR5 system, highlighting gaps in current TRR/ECC mitigations and underscoring the need for stronger standards like PRAC.

Source: The Hacker News


Malicious VS Code, Cursor, and Windsurf extensions found abusing developer ecosystems

Researchers identified roughly two dozen nefarious extensions uploaded by “WhiteCobra” to the VS Code Marketplace and Open VSX, targeting users of VSCode, Cursor, and Windsurf. The add-ons can run arbitrary code and exfiltrate data, reinforcing the urgency for extension allowlists, publisher verification, and routine audits of IDE environments.

Source: SC Media


Phishing wave impersonates Rust Foundation to hijack crates.io maintainer accounts

Rust crate publishers are receiving convincing “breach notification” emails minutes after posting new packages, urging them to revalidate via credential-harvesting pages. The campaign mirrors recent npm phishing and aims to compromise maintainer accounts, enabling supply-chain tampering of popular crates.

Source: Help Net Security


Mustang Panda deploys ‘SnakeDisk’ USB worm to drop Yokai backdoor on Thailand IPs

China-linked APT Mustang Panda is using an updated TONESHELL backdoor alongside a previously undocumented USB worm, SnakeDisk, that only executes on devices with Thailand-based IP addresses. The campaign illustrates continued APT focus on region-specific targeting and removable-media tradecraft to establish persistence and exfiltrate data.

Source: The Hacker News


China mandates 1-hour reporting window for serious cyber incidents

Beijing’s new rule compels Chinese network operators to report major cyber incidents within one hour of detection or face penalties. The accelerated timeline will reshape incident response for firms operating in China, raising compliance pressure around detection, triage, and rapid regulatory disclosure.

Source: The Register


You May Also Be Interested In...

689,000 Affected by Insider Breach at FinWise Bank

Company that owns Gucci and Balenciaga confirms customer data breach

Uvalde, Texas school district closes for days after ransomware attack

Cybersecurity — September 16, 2025 | Briefing24