THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Oracle E-Business Suite zero-day exploited by Cl0p; emergency patch released (CVE-2025-61882)

Oracle pushed an out-of-band fix for a critical remote code execution flaw in E‑Business Suite that has already been exploited by the Cl0p group in data theft attacks. Admins should apply the patch immediately and review Oracle’s indicators of compromise, web access logs, and outbound data flows for signs of exploitation.

Source: SecurityWeek


Zimbra zero-day used to target Brazilian military via malicious ICS calendar files (CVE-2025-27915)

A stored XSS vulnerability in Zimbra’s Classic Web Client—triggered by crafted ICS calendar content—was exploited as a zero-day earlier this year against Brazil’s military. Zimbra has shipped a fix; organizations should patch promptly, audit mail/calendar gateways for suspicious ICS attachments, and review user sessions for anomalous script execution.

Source: The Hacker News


Abusing AWS X‑Ray for covert cloud C2

Researchers detail how attackers can weaponize AWS X‑Ray’s legitimate tracing infrastructure as a bidirectional command-and-control channel. Cloud defenders should restrict X‑Ray permissions, baseline and alert on unusual trace generation and service integrations, and use CloudTrail/CloudWatch to detect anomalous X‑Ray API activity.

Source: Security Affairs


New LOLBin: ntprint.exe can sideload arbitrary DLLs

A fresh “living-off-the-land” technique shows ntprint.exe can be invoked to load a DLL from the working directory, enabling DLL search-order hijacking and stealthy execution. Block or closely monitor ntprint.exe outside System32, enforce application control, and hunt for suspicious invocations with non-standard load paths.

Source: Hexacorn


Ransomware hits Beer Giant Asahi; operations disrupted, data stolen

Asahi reports a ransomware incident that forced manual order processing and shipment at Japanese subsidiaries, with data confirmed stolen. The case underscores ransomware groups’ persistent focus on operational technology–adjacent businesses and the need for tested continuity plans and segmented backups.

Source: SecurityWeek


$4.5M Zeroday.Cloud competition launches with AWS, Google, and Microsoft

Wiz, alongside the major hyperscalers, is funding a new cloud hacking contest to uncover impactful vulnerabilities across modern cloud stacks. The initiative could accelerate coordinated disclosure and drive hardening in multi-cloud services—researchers should review scope and eligibility for high-value targets.

Source: SecurityWeek


ENISA Threat Landscape 2025: Ransomware up, AI‑powered phishing grows, espionage persists

ENISA’s annual review cataloged nearly 4,900 verified incidents (Jul 2024–Jun 2025), highlighting the convergence of ransomware, AI-enabled social engineering, and state-backed espionage in Europe. The report calls for resilience measures that address both scale (automation) and sophistication (targeted tradecraft) across critical sectors.

Source: Security Affairs


You May Also Be Interested In...

Phishing is old, but AI just gave it new life (Comcast threat report)

SANS: Quick analysis and IoCs for Oracle E‑Business Suite exploit (CVE-2025-61882)

Signal urges Germany to block EU client-side scanning law

Cybersecurity — October 6, 2025 | Briefing24