THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Chinese APTs keep exploiting unpatched Windows flaw (CVE-2025-9491)

A long-running Windows shortcut vulnerability (CVE-2025-9491, aka ZDI-CAN-25373) continues to be leveraged by state-backed and criminal groups, with recent activity attributed to UNC6384. Active since at least 2017, the bug enables execution via malicious .LNK chains against diplomatic and government targets. With no vendor patch available, defenders should harden against shortcut-borne payloads, restrict script execution, and intensify detection around PowerShell/LNK abuse.

Source: HelpNet Security


Chinese hackers are scanning and exploiting Cisco ASA firewalls worldwide

Unit 42 observed Storm-1849, a China-based threat group, actively targeting Cisco ASA devices used by governments and sensitive organizations around the world. Compromise of perimeter firewalls can provide durable footholds and enable stealthy lateral movement. Patch to fixed ASA releases, limit and monitor management exposure, enforce MFA for VPNs, and scrutinize configs/logs for persistence and traffic manipulation.

Source: RecordedFuture


CISA and partners warn: Exchange on‑prem risks mount after final updates

CISA and the NSA, with international partners, released best practices for securing on‑prem Microsoft Exchange as Microsoft shipped the final security updates for Exchange 2016/2019. Many servers will remain exposed unless organizations restrict admin access, enforce MFA and strict transport security, minimize internet exposure, and accelerate migration or compensating controls.

Source: HelpNet Security


VMware and XWiki bugs added to CISA KEV amid active exploitation

CISA added exploited vulnerabilities in XWiki and Broadcom VMware Tools/VMware Aria Operations (CVE-2025-41244) to its Known Exploited Vulnerabilities catalog, noting in-the-wild attacks. With exploitation tied to sophisticated actors, enterprises should patch immediately, restrict management interfaces, and hunt for suspicious guest/automation activity and anomalous service behavior.

Source: SecurityWeek


Nation-state hackers hid in Ribbon Communications’ network for months

Telecom tech supplier Ribbon said government-backed attackers maintained access to its systems since at least December 2024 before discovery. Given Ribbon’s role across global carrier networks, the incident elevates supply-chain risk for downstream telco and ISP customers. Carriers should review vendor access, rotate credentials and keys, and proactively hunt for shared TTPs.

Source: TechCrunch Security


FCC moves to scrap telecom cyber rules, favoring voluntary commitments

The FCC signaled plans to rescind Biden-era telecom security rulemakings, arguing they were an ineffective response to intrusions like Salt Typhoon. A vote is slated for next month, shifting emphasis toward ISP self-regulation—raising questions about baseline protections for critical communications infrastructure.

Source: ArsTechnica


Ransomware gangs exploit old Linux kernel bug (CVE-2024-1086)

CISA warned that ransomware operators are actively abusing a high-severity Linux netfilter (nf_tables) vulnerability introduced in 2014 and patched in January 2024. Successful exploitation can enable privilege escalation and takeover. Admins should update kernels, consider disabling unprivileged user namespaces, and monitor for anomalous nftables activity and post-exploitation behaviors.

Source: Security Affairs


You May Also Be Interested In...

Cloud Abuse at Scale: TruffleNet BEC campaign abuses AWS SES — Fortinet

Update Chrome now: 20 security fixes just landed — Malwarebytes

Nation-state hackers deploy new Airstalk malware in suspected supply chain attack — The Hacker News

Cybersecurity — November 1, 2025 | Briefing24