THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Magento ‘SessionReaper’ flaw under active attack (CVE-2025-54236)

A critical Adobe Commerce/Magento bug dubbed SessionReaper is being mass-exploited to hijack customer accounts via the REST API, with researchers blocking 250+ attempts in a single day. Patched in September, the issue allows unauthenticated attackers to bypass a security control; merchants should urgently apply fixes, rotate API keys/sessions, and monitor for anomalous logins and order activity.

Source: SecurityWeek


LockBit returns with cross-platform 5.0 variant and fresh victims

Months after Operation Cronos, LockBit has resurfaced and is actively extorting organizations, including a dozen victims identified in September. The new “LockBit 5.0 (ChuongDong)” targets Windows, Linux, and ESXi across multiple regions—underscoring the need for rapid patching, segmentation, and tested offline backups.

Source: Check Point Blog


IR Trends Q3: ToolShell SharePoint exploits dominate initial access

Cisco Talos reports a surge in intrusions via public‑facing apps, with ToolShell exploitation of SharePoint leading initial access vectors this quarter. Post-exploitation phishing and evolving ransomware tactics persist, reinforcing the urgency of tight network segmentation, rapid containment playbooks, and hardening of internet‑exposed services.

Source: Cisco Talos


Lanscope Endpoint Manager zero-day exploited since April (CVE-2025-61932)

A flaw in Lanscope Endpoint Manager has been exploited in the wild for months, with JPCERT warning of active targeting and CISA adding the bug to its Known Exploited Vulnerabilities catalog. The issue stems from improper verification of a communication channel; organizations should apply vendor mitigations immediately, restrict management interfaces, and review logs for suspicious activity dating back to April.

Source: SecurityWeek


YouTube “Ghost Network” pushed infostealers via 3,000 malicious videos

Check Point uncovered a large-scale operation abusing fake and compromised YouTube accounts to seed Rhadamanthys and Lumma infostealers through cracked software and game-hack lures. Over 3,000 videos were taken down, highlighting how social platforms and comment spam can create false trust; defenders should block known stealer infrastructure and tighten user download policies.

Source: Check Point Blog


Serious F5 breach raises supply-chain concerns for BIG-IP updates

F5 disclosed a long‑term intrusion by a suspected nation‑state actor that reached systems used to build and distribute BIG‑IP updates, prompting federal warnings for emergency action. The incident spotlights software supply‑chain risk to critical network appliances—customers should follow F5 guidance, validate update provenance, and increase monitoring for anomalous device behavior.

Source: Schneier Blog


Microsoft disables downloaded file previews to stop NTLM hash leaks

To block credential exfiltration, Microsoft has disabled previews of downloaded files where HTML tags could trigger external path requests and leak NTLM hashes. The change closes a long‑standing data exposure vector; admins should ensure policy updates propagate and adjust workflows that rely on file previews.

Source: SecurityWeek


You May Also Be Be Interested In...

AI Sidebar Spoofing Puts ChatGPT Atlas, Perplexity Comet and Other Browsers at Risk

North Korean hacking group targeting European drone maker with ScoringMathTea malware

BIND Updates Address High-Severity Cache Poisoning Flaws

Cybersecurity — October 24, 2025 | Briefing24