THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Red Hat confirms GitLab breach amid claims of 28,000 private repos stolen

Red Hat has confirmed a compromise of a self-managed GitLab instance used for its consulting business, following hacker claims of stealing data from 28,000 private repositories. The incident raises supply-chain exposure concerns because consulting artifacts can contain customer environment details. Organizations working with Red Hat consulting should review shared assets, rotate tokens/keys, and monitor for misuse.

Source: SecurityWeek


Oracle execs hit by extortion wave tied to E‑Business Suite; known bugs may be involved

Attackers claiming affiliation with the Cl0p group are emailing executives to extort payment, alleging theft of data from Oracle E‑Business Suite. Oracle says its investigation indicates vulnerabilities patched in July 2025 may have been exploited. Enterprises should urgently apply all Oracle EBS updates from July onward, rotate credentials, and scrutinize access logs for suspicious activity.

Source: SecurityWeek


Chrome 141 and Firefox 143 fix high-severity flaws—patch now

Google and Mozilla shipped security updates addressing high-severity vulnerabilities, including issues in Chrome’s WebGPU and Video components and Firefox’s Graphics and JavaScript Engine. Rapid enterprise rollout is recommended, as browser bugs are frequently chained in drive-by attacks and malvertising campaigns.

Source: SecurityWeek


Actively exploited Meteobridge flaw allows unauthenticated root command execution

A command injection vulnerability in Smartbedded Meteobridge, patched in mid-May, is being exploited in the wild. The bug enables remote, unauthenticated attackers to execute arbitrary commands with root privileges, making immediate patching and network isolation essential for exposed devices.

Source: SecurityWeek


WireTap attack undermines Intel SGX attestation

New research details “WireTap,” an attack that uses a passive interposer to manipulate SGX enclaves and extract the DCAP attestation key, breaking SGX’s attestation mechanism. The findings pose serious implications for trusted execution environments that rely on SGX for remote trust guarantees.

Source: SecurityWeek


Android spyware campaigns impersonate Signal and ToTok

ESET uncovered two spyware families—ProSpy and ToSpy—spread via fake websites and social engineering, masquerading as Signal add‑ons and the discontinued ToTok app. Researchers say ToSpy’s campaign remains active, with live C2 infrastructure. Users should only install apps from official stores and verify publishers.

Source: Help Net Security


ENISA: Attacks in the EU increasingly target OT systems

ENISA’s 2025 Threat Landscape report highlights notable activity against operational technology across the EU. The trend underscores the need for tighter IT/OT segmentation, asset visibility, and incident response preparedness in industrial environments.

Source: SecurityWeek


You May Also Be Interested In...

Self‑propagating malware spreads via WhatsApp, targets Brazilian users

Chinese-speaking cybercrime group targets high-value IIS for SEO fraud

Malicious PyPI package “soopsocks” infects systems before takedown

Cybersecurity — October 3, 2025 | Briefing24