THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Microsoft patches critical Entra ID flaw enabling cross-tenant admin impersonation

Microsoft fixed CVE-2025-55241, a CVSS 10.0 token validation failure in Entra ID that could have allowed attackers to impersonate any user — including Global Administrators — across any tenant. Classified as a privilege escalation issue, the bug underscores identity infrastructure risk concentration and the need for rapid patching and audit of privileged access and tokens.

Source: The Hacker News


Fortra patches critical GoAnywhere MFT deserialization bug (CVSS 10)

Fortra released fixes for CVE-2025-10035, a critical deserialization vulnerability in GoAnywhere MFT that can be abused for command injection. Organizations relying on managed file transfer should prioritize remediation and review external exposure and automation workflows tied to MFT endpoints.

Source: SecurityWeek


Cyberattack cripples European airport check-in systems

A cyber incident affecting Collins Aerospace software forced manual check-in and baggage processing at major European airports, causing widespread delays and cancellations. The disruption highlights systemic third-party and supply chain dependencies in aviation operations and the need for resilient, offline-capable contingency procedures.

Source: SecurityWeek


Widespread macOS infostealer campaign abuses fake GitHub repos

Threat actors are targeting macOS users via malicious GitHub repositories that masquerade as legitimate tools, redirecting victims to download the Atomic infostealer. LastPass reported the campaign focusing on its macOS user base; teams should tighten repository trust policies and monitor for suspicious developer tool downloads.

Source: SecurityWeek


ESET: Russia-linked Gamaredon and Turla collaborated in Ukraine attacks

ESET found evidence that the Gamaredon and Turla groups coordinated cyber operations against Ukrainian entities between February and April 2025. The rare APT collaboration suggests evolving tradecraft sharing and layered intrusion chains, elevating the threat to regional government and defense networks.

Source: Security Affairs


OpenID Foundation finalizes global standards for real-time security event sharing

The OpenID Foundation approved three Final Specifications—Shared Signals Framework 1.0, CAEP 1.0, and RISC 1.0—to enable secure, real-time exchange of security events across identity systems. The standards aim to improve continuous access evaluation, session change signaling, and coordinated risk response across providers and relying parties.

Source: Help Net Security


Researchers uncover “MalTerminal,” early LLM-enabled malware

SentinelOne researchers detailed MalTerminal, the earliest known malware embedding LLM capabilities to generate malicious logic at runtime, complicating static detection. Identified via API key and prompt patterns and presented at LABScon 2025, the finding underscores growing convergence of AI agents and offensive tooling.

Source: Security Affairs


You May Also Be Interested In...

BlockBlasters: Infected Steam game downloads malware disguised as patch
FBI warns of spoofed IC3 website
Europe’s cookie law messed up the internet. Brussels wants to fix it.
Cybersecurity — September 22, 2025 | Briefing24