THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical 'ForcedLeak' flaw in Salesforce Agentforce enables indirect prompt injection and CRM data exfiltration

Researchers at Noma Labs disclosed “ForcedLeak” (CVSS 9.4), a vulnerability in Salesforce Agentforce that allows indirect prompt injection to siphon sensitive CRM records. The flaw shows how embedded AI agents can be coerced via untrusted content, turning trusted systems into data-leaking conduits. Organizations using Agentforce should review agent permissions, tighten data scopes, and monitor for anomalous AI-driven queries and exports.

Source: Security Affairs


Beijing-linked ‘RedNovember’ campaign hit government and critical networks via internet-facing appliances

The Register reports that the RedNovember cyberspy group ran a year-long operation (June 2024–July 2025) against government and critical private-sector networks worldwide. Intruders exploited buggy edge appliances to plant a Go-based backdoor dubbed Pantegana and leveraged Cobalt Strike and SparkRAT, underscoring persistent abuse of perimeter devices. Rapid patching of internet-facing gear and hunting for unusual Go binaries and RAT beacons are essential.

Source: The Register


Actively exploited Cisco ASA zero-days and Fortra GoAnywhere risks headline the week’s top vulnerabilities

Help Net Security’s roundup flags active exploitation of Cisco ASA zero-day flaws and renewed risk to Fortra GoAnywhere MFT instances. Both highlight the continuing exposure of widely deployed network and file-transfer appliances, where a single weak point can offer broad access. Teams should prioritize isolation and rapid remediation of perimeter systems and restrict external access paths.

Source: Help Net Security


China-linked PlugX and ‘Bookworm’ malware variants target Asian telecom and ASEAN networks

Telecom and manufacturing organizations across Central and South Asia face an ongoing espionage campaign using a new PlugX variant. The malware overlaps with RainyDay and Turian backdoors and abuses legitimate applications for DLL side-loading, complicating detection in enterprise environments. Defenders should audit for suspicious side-loading chains and outbound C2 activity characteristic of PlugX-family implants.

Source: TheHackerNews


Fake invoice lures are dropping XWorm RAT via malicious Office files

Attackers are distributing invoice-themed phishing emails carrying Office attachments that deploy XWorm RAT on Windows systems. The infection uses shellcode and process injection to gain persistent remote access and steal data, highlighting the continued efficacy of business-themed lures. Block risky document macros by default, scrutinize invoice senders, and ensure EDR can detect process injection patterns.

Source: HackRead


Airport cyber incidents surge across Europe—why 2025 attacks look different

GovTech examines a growing wave of cyber incidents affecting European airports and why this year’s attacks stand apart. The analysis cites aviation’s tightly connected systems, third-party dependencies, and cross-border impacts as drivers of heightened operational risk, reinforcing the need for sector-specific resilience and incident playbooks.

Source: GovTech


‘Retired’ Sattered Spider, LAPSUS$, and ShinyHunters are likely regrouping for new waves of attacks

A short-lived alliance of high-profile cybercrime crews has “retired,” but researchers say the announcement is likely a smokescreen. CyberNews reports signs the groups are reorganizing and planning fresh campaigns, meaning data theft, extortion, and intrusion activity could ramp up again. Maintain elevated monitoring for their TTPs and harden identity and third-party access pathways.

Source: CyberNews


You May Also Be Interested In...

Ohio’s Union County suffers ransomware attack impacting 45,000 people

Ransomware’s favorite targets in 2025 and how to protect your business

Google Starts Tracking Your Phone As Chrome And Gemini Change

Cybersecurity — September 28, 2025 | Briefing24