THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA warns of actively exploited Sudo flaw granting root on Linux/Unix

A critical Sudo vulnerability (CVE-2025-32463) is being actively exploited, allowing local, low‑privileged users to execute commands with root privileges and potentially fully compromise systems. CISA added the bug to its Known Exploited Vulnerabilities catalog, urging organizations to patch affected Sudo versions immediately and review systems for abuse. Prioritize updates on Linux and Unix-like hosts and tighten controls on local access.

Source: SecurityWeek


Akira ransomware: From SonicWall VPN login to encryption in under four hours

Arctic Wolf reports Akira affiliates are using stolen SonicWall SSL VPN credentials—and appear able to bypass MFA—to break into networks and deploy ransomware in as little as four hours. After initial access, actors scan the environment, use Impacket for SMB sessions, and rely on RDP for rapid lateral movement. Audit SSL VPNs, rotate credentials, enforce phishing‑resistant MFA, and hunt for Impacket/RDP artifacts.

Source: Help Net Security


Apple rushes updates to block malicious font attacks across iOS and macOS

Apple shipped emergency updates to mitigate a flaw triggered by processing malicious fonts that can cause denial-of-service or memory corruption. The patches span current and older iOS and macOS releases, and admins should prioritize rapid fleet updates given the low-friction exploit vector. Validate that managed devices receive the latest builds before allowing external font rendering.

Source: SecurityWeek


‘Widespread’ breach hits FEMA and CBP via Citrix vulnerability

A Citrix vulnerability enabled a breach that allowed hackers to steal employee data from FEMA and CBP, with compromised FEMA servers connected to state systems along the southern border. The incident reportedly led to staff shake-ups and highlights how edge service exposures can cascade across interlinked networks. Agencies and partners should urgently verify Citrix patch levels and credential hygiene.

Source: NextGov


Cybersecurity Information Sharing Act set to expire, raising legal and risk concerns

The Cybersecurity Information Sharing Act is scheduled to lapse on September 30, 2025, creating uncertainty for public‑private threat intelligence exchanges. Security leaders warn that expiration could chill sharing due to legal risk and hinder collective defense during elevated threat activity. Congress faces pressure to renew or reform the framework to preserve vital information flows.

Source: SecurityWeek


Typosquatted MCP package siphoned emails via a single line of code

A fake npm package posing as Postmark’s MCP server quietly exfiltrated potentially thousands of messages per day by adding one line of code to copy outgoing emails to an attacker’s address. The episode underscores growing supply‑chain risk around Model Context Protocol integrations and AI agent ecosystems. Developers should verify package provenance, pin dependencies, and monitor egress for anomalies.

Source: The Register


Microsoft flags AI‑crafted SVG phishing that evades email defenses

Microsoft observed a campaign using LLM‑generated code to obfuscate payloads within SVG files masquerading as business dashboards, helping the lures bypass filters and reach U.S. organizations. The synthetic structure and business terminology masked malicious behavior until execution. Consider blocking or sanitizing SVG attachments, applying content disarm/inspection, and tightening heuristics for vector graphics.

Source: The Hacker News


You May Also Be Interested In...

Cybersecurity — September 30, 2025 | Briefing24