THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Redis “RediShell” RCE puts tens of thousands of servers at risk (CVE-2025-49844)

Redis patched a maximum-severity flaw that allows authenticated attackers to use malicious Lua scripts to escape the sandbox and execute arbitrary code on the host. Researchers estimate roughly 60,000 internet-exposed Redis servers could be at risk; admins should patch immediately, restrict exposure, and monitor for suspicious Lua activity.

Source: SecurityWeek


Leaked Oracle EBS exploit scripts fuel active RCE attacks (CVE-2025-61882)

Exploit scripts for a critical Oracle E-Business Suite vulnerability have leaked on Telegram, and attackers reportedly began exploiting the flaw months before patches landed. Researchers warn the issue chains multiple weaknesses for unauthenticated RCE; organizations should patch now, audit internet-facing EBS, and hunt for signs of compromise.

Source: Help Net Security


Medusa ransomware exploiting GoAnywhere MFT zero-day (CVE-2025-10035)

The Medusa ransomware group leveraged a critical deserialization bug in Fortra’s GoAnywhere MFT to achieve unauthenticated command execution, with exploitation observed before patches were released. Enterprises should upgrade to fixed versions immediately, review MFT access logs for License Servlet abuse, and isolate file transfer infrastructure.

Source: SecurityWeek


ShinyHunters launch mass extortion site, claim Fortune 500 data and Red Hat theft

ShinyHunters resurfaced with an extortion portal threatening to leak data from dozens of major firms, after earlier vishing-led theft of Salesforce customer records. The crew also tied themselves to the Discord third‑party breach and alleged multi-terabyte theft from Red Hat, signaling a coordinated pressure campaign on corporate victims.

Source: KrebsOnSecurity


Zimbra stored XSS actively exploited; CISA adds to KEV (CVE-2025-27915)

A stored cross-site scripting flaw in Zimbra Collaboration Suite is being exploited in the wild, including via malicious iCalendar invites, prompting CISA to add it to the Known Exploited Vulnerabilities catalog. Mail admins should apply vendor fixes, sanitize calendar content, and harden webmail to limit script execution.

Source: Security Affairs


Microsoft: Threat actors abusing Teams across the entire attack chain

Microsoft warns adversaries are weaponizing Teams features for everything from reconnaissance and initial access to data exfiltration. Redmond recommends tightening external access, enforcing strong identity controls, hardening endpoints, and adding DLP and network policies to blunt Teams-enabled intrusion paths.

Source: Microsoft Security Blog


“Hidden text salting” via CSS helps phishing evade email AI detection

Cisco Talos highlights a rising evasion tactic where attackers hide “salted” text in messages using CSS, fooling ML- and LLM-based email filters while preserving human readability. Defenders should normalize/strip styling, flag hidden or off-screen text, and tune models to detect salting patterns in inbound mail.

Source: Cisco Talos


You May Also Be Interested In...

Polymorphic Python malware spotted with self-modifying code
OpenAI disrupts state-linked actors misusing ChatGPT for cyberattacks
Researchers: Y2K38 is an exploit vector today for ICS and devices
Cybersecurity — October 8, 2025 | Briefing24