THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
APT exploited Cisco ISE and Citrix NetScaler zero-days to breach identity and access infrastructure

Amazon’s threat intel team observed an advanced actor exploiting CVE-2025-20337 (Cisco ISE) and CVE-2025-5777 (“CitrixBleed 2”) as zero‑days to deploy custom malware and pivot through critical identity and network access control systems. Defenders should urgently inventory exposed devices, restrict management interfaces, review logs for anomalous authentications and web requests, and apply vendor mitigations and patches as they are released.

Source: SecurityWeek


Microsoft patches actively exploited Windows Kernel zero-day (CVE-2025-62215)

November Patch Tuesday fixed 60+ flaws, including a Windows Kernel race condition (CVE-2025-62215) used in the wild to elevate privileges to SYSTEM. Prioritize deployment to servers and endpoints, and review EoP telemetry for suspicious token manipulation and kernel instability around exploitation windows.

Source: Help Net Security


CISA flags critical WatchGuard Fireware flaw exposing 54,000 Fireboxes to pre-auth compromise

CVE-2025-9242, an out‑of‑bounds write in WatchGuard Fireware, is under active exploitation and enables “no‑login” attacks on affected devices. Patch immediately, disable remote management from the public Internet, enforce IP allow‑listing and MFA for admin access, and monitor for unusual device reboots or configuration changes.

Source: The Hacker News


Google sues ‘Lighthouse’ smishing network operating at massive scale

Google filed suit against the China‑based Smishing Triad behind the Lighthouse phishing‑as‑a‑service kit, which fueled SMS phishing and credit‑card theft via more than 194,000 malicious domains. The action seeks to disrupt infrastructure and deter copycats; enterprises should harden mobile anti‑phishing controls, block known Lighthouse domains, and educate users to avoid links in unsolicited texts.

Source: SecurityWeek


UK unveils Cyber Security and Resilience Bill to toughen protections for critical services

After years of delay, the government introduced legislation to update NIS regulations, bring more organizations (including managed service providers) into scope, mandate incident reporting, and impose steep fines for non‑compliance. Operators of essential services should begin readiness assessments now—mapping dependencies, third‑party exposure, and resilience plans against expected obligations.

Source: Recorded Future News


NHS pathology supplier Synnovis confirms stolen patient data; notifications begin 17 months on

Synnovis concluded its forensic review of the 2024 ransomware attack and confirmed patient information was exfiltrated, with notifications now going out to affected individuals—including those whose sensitive test results may have been posted online. The prolonged impact underscores the need for segmented lab systems, immutable backups, and tested crisis communications in healthcare.

Source: SecurityWeek


‘Payroll Pirates’ malvertising network hijacks pay and finance logins at scale

Check Point tracked a financially motivated operation using sponsored ads to impersonate payroll systems, credit unions, and trading platforms, targeting more than 200 interfaces and luring over 500,000 users since mid‑2023. Lock down ad‑driven brand abuse by monitoring for look‑alike domains, enforcing FIDO/SSO for payroll access, and educating staff to navigate directly rather than via search ads.

Source: Check Point Blog


You May Also Be Interested In...
Unleashing the Kraken ransomware group
Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack
Increase in Lumma Stealer Activity Coincides with Use of Adaptive Browser Fingerprinting Tactics
Cybersecurity — November 13, 2025 | Briefing24