THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Cl0p exploits Oracle E-Business Suite zero-day (CVE-2025-61882) in mass data-theft, extortion campaign

Oracle rushed an emergency patch for a critical EBS flaw after Cl0p operators began exploiting it in August to steal sensitive data and send extortion emails to victims. Security agencies and researchers urge immediate patching and threat hunting around EBS internet exposure, API logs, and anomalous data egress.

Source: SecurityWeek


Medusa ransomware leverages GoAnywhere MFT zero-day (CVE-2025-10035) for pre-auth command execution

Microsoft and incident responders report Medusa affiliates exploited a critical deserialization bug in Fortra’s GoAnywhere MFT about a week before patches were released. Organizations should upgrade immediately, rotate credentials/keys integrated with MFT, and review for suspicious job executions or unusual outbound transfer activity.

Source: SecurityWeek


Critical Redis RCE (CVE-2025-49844) threatens 60,000 internet-exposed servers

A maximum-severity flaw enables authenticated attackers to abuse crafted Lua scripts to trigger a use-after-free and potentially execute code on hosts. Patch urgently, restrict Redis network exposure, disable or constrain Lua where possible, and enforce strong auth and TLS to reduce exploitation risk.

Source: SecurityWeek


Unity engine vulnerability puts games at risk across Windows, Android, and more

A widely used Unity flaw can enable local code execution via affected apps, prompting Microsoft and Steam to enforce mitigations and developer patches. Game publishers should ship fixes fast and players should update titles promptly, as the attack surface spans desktops and mobile devices running Unity-built apps.

Source: SecurityWeek


New leak site targets 39 organizations tied to Salesforce data theft

A collective dubbed Scattered Lapsus$ Hunters launched a data leak portal to pressure victims—purportedly via compromised Salesforce environments—into paying ransoms. The campaign underscores SaaS supply-chain risk; defenders should audit Salesforce integrations, access tokens, third-party apps, and data export activity.

Source: Help Net Security


Discord discloses third-party breach exposing user support data, including some ID images

Discord confirmed a compromise at a customer support vendor that exposed names, contact details, IPs, limited billing info, and a subset of government ID images for users interacting with support. Users should be alert to targeted phishing, and enterprises should reassess vendor data minimization and breach response SLAs.

Source: SecurityWeek


CSS “hidden text salting” helps phishing bypass AI-powered email defenses

Cisco Talos warns of a surge in attackers abusing CSS to “salt” hidden text in emails, degrading the accuracy of ML and LLM-based filters without changing human-visible content. Security teams should harden pipelines against style-based obfuscations and supplement content inspection with robust sender, URL, and behavior signals.

Source: Cisco Talos


You May Also Be Interested In...
FBI, UK Gov’t urge immediate patching of Oracle EBS after Cl0p campaign
Microsoft links Storm-1175 to GoAnywhere exploit deploying Medusa ransomware
Phishers target 1Password users with convincing fake breach alerts
Cybersecurity — October 7, 2025 | Briefing24