THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA: Windows SMB flaw (CVE-2025-33073) under active exploitation—patch now

CISA added a Windows SMB Client privilege escalation bug to its Known Exploited Vulnerabilities catalog, confirming in-the-wild attacks. The flaw can grant SYSTEM privileges and is being targeted months after Microsoft issued a fix in June. Organizations should patch immediately, restrict outbound SMB, and monitor for suspicious NTLM/SMB authentication attempts.

Source: Help Net Security


Envoy Air confirms breach tied to Oracle E‑Business Suite 0‑day exploited by Cl0p

Envoy Air, a subsidiary of American Airlines, confirmed a cyberattack linked to Cl0p’s exploitation of an Oracle EBS zero‑day (CVE‑2025‑61882). The incident underscores active targeting of enterprise ERP stacks and the urgency of rapidly applying Oracle’s emergency patches and limiting external exposure of EBS components.

Source: HackRead


VS Code supply-chain hit: ‘GlassWorm’ malware hides with invisible Unicode, blockchain infra

A supply-chain attack targeted Visual Studio Code extensions with malware dubbed GlassWorm, which uses invisible Unicode characters to obfuscate code and blockchain-based infrastructure to resist takedowns. Developer environments are in scope—review extension provenance, pin trusted versions, and enforce code signing and allowlisting for IDE plugins.

Source: SecurityWeek


Official Xubuntu site compromised to serve Windows malware instead of Linux distro

The Xubuntu website briefly delivered a “Safe-Download” ZIP containing a suspicious Windows executable in place of legitimate torrent links. This website compromise highlights the risk of hijacked download flows; users should verify checksums and only obtain ISOs from authenticated mirrors.

Source: Help Net Security


‘TARmageddon’: RCE flaw in async‑tar Rust library threatens downstream projects

Researchers disclosed a high-severity remote code execution vulnerability in the popular async‑tar Rust library and multiple forks, impacting a widely used archive component embedded in other projects. Teams should inventory Rust dependencies, update to patched versions, and review any tar handling paths exposed to untrusted input.

Source: CyberScoop


TP‑Link patches critical Omada gateway bugs enabling remote code execution

TP‑Link released fixes for four Omada gateway vulnerabilities, including two critical issues that could allow arbitrary code execution. Network edge devices remain high-value targets—apply firmware updates quickly, restrict management plane access, and monitor for anomalous device behavior.

Source: The Hacker News


Google: Russia‑linked COLDRIVER rapidly retools with three new malware families

Google’s threat intel team says COLDRIVER (aka Callisto) accelerated malware development after its LOSTKEYS toolset was exposed, rolling out three new families within months. The pace of iteration complicates detections—keep threat intel feeds current, tune behavioral controls, and hunt for evolving TTPs rather than static IOCs.

Source: The Hacker News


You May Also Be Interested In...

Reducing abuse of Microsoft 365 Exchange Online’s Direct Send (Cisco Talos)

Hackers earn $520,000 on Day 1 of Pwn2Own Ireland (SecurityWeek)

Dataminr to acquire ThreatConnect for $290M (SecurityWeek)

Cybersecurity — October 22, 2025 | Briefing24