THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Record-shattering Aisuru DDoS botnet draws firepower from US ISPs

The world’s most disruptive botnet is now sourcing a majority of its traffic from compromised IoT devices on major U.S. providers, with a peak burst nearing 30 Tbps this week. The high concentration inside AT&T, Comcast, and Verizon networks complicates mitigation and raises the stakes for ISP filtering and enterprise DDoS resilience plans.

Source: KrebsOnSecurity


FBI seizes revived BreachForums as Scattered Spider extorts Salesforce customers

Authorities took down the cybercrime marketplace that Scattered Spider tried to resurrect to pressure Salesforce and its high-profile customers. While the forum now displays a seizure banner, experts warn the actors may still leak stolen data, and impacted organizations should prepare for follow-on extortion and exposure.

Source: Recorded Future News


Active zero-day: Gladinet CentreStack/Triofox LFI exploited, no patch yet (CVE-2025-11371)

Attackers are abusing an unauthenticated Local File Inclusion flaw in Gladinet CentreStack and Triofox, with in-the-wild exploitation confirmed. A vendor fix is pending; administrators should immediately disable the vulnerable handler in Web.config as a temporary mitigation and restrict external exposure.

Source: Help Net Security


Oracle E-Business Suite zero-day campaign hit dozens of orgs since July

Google researchers say a sophisticated malware operation exploiting an Oracle EBS zero-day likely began around July 10, compromising dozens of organizations. The campaign underscores the risk to ERP platforms and the need for tight access controls, vigilant logging, and rapid patch uptake when fixes land.

Source: SecurityWeek


‘Payroll Pirates’ hijack HR SaaS accounts to divert salaries

Microsoft tracked Storm-2657 targeting U.S. organizations—especially higher ed—to compromise accounts on platforms like Workday and reroute paychecks to attacker-controlled accounts. Defenders should enforce phishing-resistant MFA, conditional access, and out-of-band verification for payroll changes.

Source: The Hacker News


Apple doubles max bug bounty to $2M for zero-click chains, with bonuses up to $5M

Apple expanded its bounty categories and top payouts to $2 million for zero-click exploit chains, adding bonuses for Lockdown Mode bypasses and beta software issues that can push awards above $5 million. The move aims to incentivize disclosure amid intense competition from private exploit markets.

Source: SecurityWeek


Stealit malware abuses Node.js SEA and Electron via fake game/VPN installers

Fortinet reports a Stealit infostealer campaign leveraging Node.js Single Executable Application (SEA)—and in some variants Electron—to pack and obfuscate payloads that evade detection. Lures masquerade as game and VPN installers, highlighting the need for application allowlisting and strict software provenance checks.

Source: Fortinet


You May Also Be Interested In... - Juniper Networks Patches Critical Junos Space Vulnerabilities - 100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure - Private repository info exposed by GitHub Copilot Chat vulnerability
Cybersecurity — October 11, 2025 | Briefing24