THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗

Cl0p names nearly 30 alleged victims of Oracle E‑Business Suite hack

The Cl0p ransomware site has posted an alleged victim list tied to an Oracle EBS intrusion campaign, naming major organizations including Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ, and Copeland. The claims highlight the risk to ERP platforms and data exfiltration at scale. Oracle EBS users should urgently review internet exposure, apply the latest patches, and hunt for anomalous access and data movement.

Source: SecurityWeek


QNAP patches multiple vulnerabilities exploited at Pwn2Own Ireland

QNAP released fixes for multiple flaws across QTS, QuTS hero and several apps that could enable remote code execution, information disclosure, and DoS conditions. The issues were demonstrated in live exploits during Pwn2Own Ireland, underscoring the risk to widely deployed NAS gear. Admins should update firmware and affected apps immediately, minimize internet exposure, and review backup/sync and admin access policies.

Source: SecurityWeek


Microsoft details ‘Whisper Leak’ side‑channel exposing AI chat topics despite encryption

Microsoft researchers disclosed Whisper Leak, a side‑channel that allows network observers to infer what users discuss with remote LLMs even when traffic is encrypted. The finding highlights metadata leakage risks as organizations adopt AI assistants over the network. Mitigations include traffic shaping/padding, gateway proxies, and treating LLM egress like other sensitive SaaS with zero‑trust monitoring.

Source: Security Affairs


Malicious ‘GlassWorm’ resurfaces via three VS Code extensions with thousands of installs

Researchers identified three Visual Studio Code extensions tied to the GlassWorm campaign that remain available for download, collectively tallying thousands of installs. Malicious extensions can exfiltrate data or execute attacker code in developer environments, turning the dev toolchain into an intrusion vector. Teams should inventory and restrict extensions via allowlists, verify publishers, and monitor developer workstation egress.

Source: TheHackerNews


New ‘Landfall’ zero‑click spyware targets Samsung Galaxy devices

A commercial‑grade Android spyware dubbed Landfall has been discovered exploiting zero‑day vulnerabilities in Samsung Galaxy devices. The campaign appears tailored for targeted surveillance with no user interaction. Galaxy users and enterprise MDM teams should apply the latest security updates as soon as they land, enforce mobile threat defense, and minimize attack surface by disabling unneeded services/features.

Source: CyberNews


Time‑bombed NuGet packages aim to disrupt databases and industrial systems

Socket’s Threat Research Team uncovered nine malicious NuGet packages from “shanhai666” that include time‑delayed payloads set to trigger in 2027 and 2028, targeting databases and industrial control environments. The long‑dwell supply‑chain tactic seeks to evade detection and maximize operational impact. Developers should remove the affected packages, pin dependencies with lockfiles, use private registries with provenance checks, and scan builds for malicious code.

Source: Security Affairs


U.S. reportedly preparing TP‑Link sales ban amid supply‑chain and security concerns

KrebsOnSecurity reports the U.S. government is considering a ban on TP‑Link networking gear, a vendor with an estimated 50% market share among home and SMB users. While tied to China concerns rather than a specific CVE, the move spotlights persistent “insecure‑by‑default” issues across low‑cost routers. Organizations should review procurement dependencies, harden consumer‑grade gear where used, and plan lifecycle replacements with devices supporting strong default security and patch cadence.

Source: KrebsOnSecurity


You May Also Be Interested In...

Multi‑brand phishing campaign harvests credentials via Telegram Bot API

ClickFix phishing wave targets hotels, delivers PureRAT

Data breach at Chinese infosec firm reportedly exposes cyber‑weapons and targeting

Cybersecurity — November 10, 2025 | Briefing24