THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Wormable npm supply-chain attack self-replicates across 180+ packages

A self-replicating worm dubbed “Shai-Hulud” has compromised at least 187 npm packages, stealing developer credentials and automatically publishing those secrets to GitHub to fuel further spread. The incident briefly infected multiple code packages from a major security vendor, underscoring how quickly trust in software dependencies can be subverted and the risks to CI/CD pipelines and private repos.

Source: KrebsOnSecurity


Apple backports fix for actively exploited zero-day used in spyware attacks

Apple has shipped patches for CVE-2025-43300 to older devices—including models as old as iPhone 8—after confirming the bug was exploited in “extremely sophisticated” targeted attacks. The ImageIO out-of-bounds write flaw can be triggered with a malicious image, making rapid fleet updates critical for organizations with high‑risk users.

Source: The Register


Microsoft and Cloudflare disrupt RaccoonO365 phishing service, identify ringleader

Authorities seized 338 domains tied to the RaccoonO365 phishing-as-a-service, which Microsoft says stole over 5,000 Microsoft 365 credentials across 94 countries since mid‑2024. The operation identified an alleged leader and highlights the industrialization of credential theft, reinforcing the need for phishing-resistant MFA and conditional access.

Source: SecurityWeek


New “Phoenix” Rowhammer exploit cracks DDR5 protections in under 2 minutes

Researchers demonstrated a new Rowhammer variant (CVE-2025-6202) that bypasses advanced DDR5 defenses on certain AMD/SK Hynix configurations, achieving root in 109 seconds under lab conditions. While real-world constraints apply, the work shows hardware-level fault attacks remain viable, pressing vendors and operators to revisit memory protection assumptions.

Source: SecurityWeek


Criminals created fake account in Google’s law enforcement data portal

Google confirmed threat actors enrolled a fraudulent account in its Law Enforcement Request System (LERS), which agencies use to request user data, before the company disabled it. The incident raises concerns about verification processes for sensitive portals and the potential for forged legal requests or data exposure.

Source: The Register


GitHub adds post-quantum protection for SSH with hybrid keys

GitHub introduced hybrid SSH keys that combine classical and post‑quantum algorithms to mitigate harvest‑now‑decrypt‑later threats while maintaining compatibility. It’s a significant step in mainstreaming PQC for developer workflows, offering a practical migration path before quantum-capable adversaries emerge.

Source: Help Net Security


EFF releases Rayhunter, an open-source tool to detect Stingray-style cellular spying

The Electronic Frontier Foundation launched Rayhunter, which uses a low‑cost mobile hotspot to flag suspicious cell site simulator (IMSI catcher) activity. The project aims to equip researchers, journalists, and civil society with better visibility into mobile surveillance that often evades public scrutiny.

Source: Help Net Security


You May Also Be Interested In...

Cybersecurity — September 17, 2025 | Briefing24