THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Ransomware on airport check‑in provider snarls European travel; third‑party risk in focus

A ransomware attack on Collins Aerospace, a U.S. provider of airport check‑in and boarding systems, disrupted operations across major European hubs including London, Brussels, and Berlin. Airports reverted to manual processes, causing delays and cancellations while recovery efforts and law enforcement investigations continue. The incident underscores critical dependencies on single vendors and the need for robust third‑party risk management, contingency plans, and segmentation between OT/IT systems.

Source: SecurityWeek


Critical GoAnywhere MFT flaw (CVE‑2025‑10035) allows command injection and full takeover

Fortra patched a CVSS 10.0 deserialization vulnerability in the GoAnywhere MFT License servlet that can be exploited for command injection, putting unpatched instances at risk of complete compromise. Organizations should update immediately, restrict external exposure, rotate credentials, and hunt for suspicious admin activity and new users on MFT hosts.

Source: SecurityWeek


Mac users hit by widespread Atomic infostealer via fake GitHub repos and SEO poisoning

Threat actors are luring Mac users searching for popular apps (e.g., LastPass, 1Password, Adobe After Effects) to fraudulent GitHub repositories that deliver the Atomic (AMOS) infostealer. The malware harvests passwords, crypto wallets, and browser data; defenders should enforce download provenance, verify code signatures, and deploy macOS EDR with behavioral detections.

Source: SecurityWeek


FBI warns: spoofed IC3 websites stealing victims’ personal data

The FBI says cybercriminals have cloned its Internet Crime Complaint Center (IC3) site to phish for sensitive information and enable follow‑on fraud. Users should only report crimes at ic3.gov, avoid links in unsolicited emails, and verify domains and TLS details before submitting any data.

Source: SecurityWeek


GitHub tightens npm security with 2FA mandates, short‑lived tokens, and trusted publishing

Responding to a surge in package registry attacks, GitHub will require stronger authentication and granular, short‑lived tokens for npm publishing, and expand trusted publishing to curb token abuse and self‑replicating malware. Publishers should enable 2FA now, audit automation workflows, and prepare to migrate to the new authentication flows to reduce supply chain risk.

Source: The GitHub Blog


Iran‑linked Nimbus Manticore expands into Europe with job‑lure phishing and advanced malware

Check Point reports the Iranian threat actor Nimbus Manticore is targeting European defense, telecom, and aerospace firms with fake recruitment portals and tailored spear‑phishing. The group deploys evolving malware families (MiniJunk, MiniBrowse) to evade detection and maintain persistence, aligning with IRGC intelligence collection priorities.

Source: Check Point Blog


Auto giant Stellantis discloses breach via third‑party provider; customer contact data exposed

Stellantis said a provider supporting its North American customer service platform was accessed without authorization, exposing customer contact information. The case highlights persistent supply chain exposure; impacted users should watch for targeted phishing and account takeover attempts, and enterprises should reassess vendor access controls and data minimization.

Source: SecurityWeek


You May Also Be Interested In...

Researchers Earn $150,000 for L1TF Exploit Leaking Data From Public Cloud

Gartner: Preemptive cybersecurity to dominate 50% of security spend by 2030

Scattered Spider Suspect Arrested in US

Cybersecurity — September 23, 2025 | Briefing24