THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Critical Magento/Adobe Commerce flaw exploited at scale

Attackers are actively exploiting CVE-2025-54236, a critical improper input validation bug in Adobe Commerce and Magento Open Source, to hijack customer accounts via the REST API. Researchers observed more than 250 attack attempts against multiple stores in 24 hours, underscoring the urgency to patch now, restrict API access, and monitor for anomalous account behavior.

Source: The Hacker News


BIND updates fix cache poisoning flaws that threaten core DNS

ISC released patches for high‑severity vulnerabilities that let attackers predict BIND’s source ports and query IDs, enabling cache poisoning. The bugs risk reviving Kaminsky‑style DNS attacks; admins should update immediately and reinforce defenses with DNSSEC, 0x20 name randomization, and response policy tuning.

Source: SecurityWeek


CISA flags Lanscope Endpoint Manager zero‑day exploited in the wild

A critical Lanscope Endpoint Manager vulnerability (CVE-2025-61932) has been added to CISA’s Known Exploited Vulnerabilities catalog after confirmed in‑the‑wild abuse. On‑prem deployments are affected; organizations should apply vendor fixes, isolate exposed management consoles, and hunt for post‑exploitation activity.

Source: SecurityWeek


Zero‑click Dolby audio bug allows RCE on Android and Windows

A newly disclosed vulnerability in Dolby audio processing (CVE-2025-54957) could enable remote code execution via malicious audio files on Android and Windows devices. Until patches are broadly available, limit playback from untrusted sources, scan email/media attachments, and prioritize vendor updates as they land.

Source: Malwarebytes


TP‑Link Omada gateways patched for critical remote command execution

TP‑Link has issued updates for four severe flaws affecting Omada gateway devices across ER, G, and FR models, including a bug allowing unauthenticated remote command execution. Branch networks and SMBs should upgrade firmware immediately and review WAN exposure and admin access controls.

Source: SecurityWeek


Chinese actors weaponize SharePoint “ToolShell” bug to breach governments

Threat actors linked to China rapidly exploited a recently patched Microsoft SharePoint vulnerability tied to ToolShell, compromising a Middle East telecom and government agencies in Africa and South America. The campaign highlights fast patch-to-exploit cycles—apply July SharePoint fixes, audit for suspicious ToolShell activity, and segment on‑prem collaboration servers.

Source: The Hacker News


Lazarus “DreamJob” resurfaces, targets Europe’s drone and defense sector

ESET uncovered a fresh Operation DreamJob wave by North Korea’s Lazarus Group targeting European defense contractors—particularly firms involved in UAV development—via polished fake job lures. Organizations should harden recruiting workflows, train staff to spot social engineering, and enforce application whitelisting and macro restrictions for candidate documents.

Source: Help Net Security


You May Also Be Interested In...

Canada fines cybercrime-friendly Cryptomus $176M
Verizon: Mobile attacks soar as AI-powered threats rise
100+ Chrome extensions abused WhatsApp Web for mass spam
Cybersecurity — October 23, 2025 | Briefing24