THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Chrome zero-day under active exploitation patched — update now (CVE-2025-10585)

Google shipped an emergency Chrome update to fix CVE-2025-10585, a high‑severity type confusion flaw in the V8 engine that is already being exploited. It’s the latest in a string of Chrome zero-days this year, underscoring the value of rapid browser patching. Security teams should push the stable update immediately and consider hunting for suspicious V8 crashes or anomalous renderer activity.

Source: Help Net Security


SonicWall breach exposes firewall configuration backups; password resets urged

SonicWall says attackers brute-forced its cloud backup service and accessed firewall configuration preference files for fewer than 5% of devices. The vendor has pushed updated preference files and is urging impacted customers to reset credentials and re-secure appliances. Exposed configs can accelerate follow-on attacks, so organizations should rotate all related credentials, audit management access, and review rule and VPN changes.

Source: SecurityWeek


Zero-click ‘ShadowLeak’ bug in ChatGPT Deep Research agent fixed by OpenAI

Researchers disclosed “ShadowLeak,” a server-side data theft technique that let attackers exfiltrate data from the ChatGPT Deep Research agent by simply sending a crafted email when the agent was connected to Gmail and browsing tools. OpenAI has patched the issue, but the case highlights growing TOCTOU- and agent-integrations risk in LLM workflows. Teams should limit agent tool scopes, monitor agent activity logs, and review where corporate mailboxes or APIs are connected to autonomous agents.

Source: Recorded Future News (The Record)


CISA warns of malware exploiting Ivanti EPMM flaws (CVE-2025-4427, -4428)

CISA detailed two malware sets observed after exploitation of Ivanti Endpoint Manager Mobile vulnerabilities, with loaders deploying malicious listeners to run arbitrary code. Defenders should patch affected EPMM versions immediately, scan for post-exploitation payloads and persistence, and review management interface exposure. The advisory reinforces that mobile device management platforms are high-value targets for initial access.

Source: The Hacker News


ESET: Russia-linked Gamaredon and Turla collaborating in Ukraine operations

ESET researchers found evidence that Gamaredon gained initial access and deployed tools across endpoints, while Turla later leveraged the access to execute its Kazuar backdoor. Both groups are linked to Russia’s FSB, and the teaming suggests more modular, multi-actor campaigns. Defenders should correlate TTPs across clusters, watch for Gamaredon implants (e.g., PteroGraphin/PteroOdd) alongside Turla tooling, and adjust detections for pivot behavior.

Source: Help Net Security


Critical WatchGuard Firebox flaw patched; update Fireware OS now (CVE-2025-9242)

WatchGuard issued fixes for a 9.3-severity out-of-bounds write in Firebox devices that could enable remote compromise under certain conditions. Customers should upgrade to the patched Fireware OS releases without delay and restrict management interfaces from the internet. As with other edge devices, review configs, rotate admin credentials, and verify logs for suspicious management events.

Source: HackRead


Microsoft and Cloudflare disrupt fast-growing RaccoonO365 phishing-as-a-service

A joint effort by Microsoft and Cloudflare dealt a significant blow to “RaccoonO365,” a booming phishing-as-a-service targeting Microsoft 365 credentials at scale. The takedown should reduce near-term volume, but copycats and rebrands are likely. Organizations should enforce phishing-resistant MFA, conditional access, and continuous detection for adversary-in-the-middle kits and legacy auth attempts.

Source: Malwarebytes


You May Also Be Interested In...

Two Scattered Spider Suspects Arrested in UK; One Charged in US

Threat landscape for industrial automation systems in Q2 2025 (Kaspersky ICS)

LinkedIn now uses your data for AI by default — how to opt out

Cybersecurity — September 19, 2025 | Briefing24