THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Oracle patches EBS flaw allowing unauthenticated access to sensitive data (CVE-2025-61884)

Oracle has released a fix for a new Oracle E‑Business Suite vulnerability that can be exploited remotely without authentication to access sensitive data. It’s not yet clear if the flaw is being exploited in the wild, but the exposure of business-critical ERP data makes rapid patching and internet-exposure reviews urgent for EBS customers.

Source: Security Week


Google, Mandiant tie Oracle EBS extortion to malware, patched bugs, and likely zero‑day (CVE‑2025‑61882)

Google Threat Intelligence and Mandiant analyzed an Oracle E‑Business Suite extortion campaign that used malware, July‑patched vulnerabilities, and a likely zero‑day (CVE‑2025‑61882) to pressure executives. Their findings underscore a shift from opportunistic scanning to targeted ERP exploitation, with attackers chaining flaws and extortion tactics against high‑value apps.

Source: Security Affairs


Extortion group leaks millions of records from Salesforce-related breaches

An extortion group has posted data allegedly tied to major organizations using Salesforce, including Albertsons, Engie Resources, Fujifilm, GAP, Qantas, and Vietnam Airlines. The incident highlights the growing risk of third‑party SaaS ecosystems and the need to harden integrations, tokens, and access scopes tied to cloud CRM platforms.

Source: Security Week


Microsoft locks down Edge’s IE mode after threat actors abused it as a backdoor

Microsoft revamped Internet Explorer mode in Edge following credible reports that attackers combined social engineering with unpatched IE JavaScript exploits to gain unauthorized device access. Organizations should reassess any dependency on IE mode, apply the latest browser updates, and tighten policies for legacy compatibility features.

Source: TheHackerNews


RondoDox botnet now exploits 50+ vulnerabilities across 30+ vendors

Researchers warn the RondoDox botnet has broadened its “exploit shotgun” approach to target more than 50 flaws in routers, DVRs/NVRs, CCTV systems, web servers, and other internet‑exposed infrastructure. The campaign underscores the need to minimize external attack surface, promptly patch embedded/IoT devices, and segment networks to contain compromises.

Source: TheHackerNews


New Rust-based ChaosBot uses Discord channels for command-and-control

eSentire detailed “ChaosBot,” a Rust backdoor capable of reconnaissance and arbitrary command execution, controlled via Discord channels. The intrusion leveraged compromised credentials tied to both a Cisco VPN and an over‑privileged Active Directory “serviceaccount,” highlighting the compound risks of credential theft and excessive privileges.

Source: TheHackerNews


Spain dismantles ‘GXC Team’ crime‑as‑a‑service ring behind phishing kits and Android malware

Spanish authorities arrested “GoogleXcoder,” the alleged admin of the GXC Team service that supplied phishing kits and Android malware to cybercriminals. The takedown could disrupt multiple phishing and mobile malware campaigns in the near term, though defenders should anticipate copycats and reconstituted operations.

Source: Security Week


You May Also Be Interested In...

Wireshark 4.4.10 and 4.6.0 Released

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

Attackers don’t linger, they strike and move on

Cybersecurity — October 13, 2025 | Briefing24