Zero Days, Breaches, and LockBit Fallout
News
Mozilla Foundation Confirms Breach, Source Code and Data Stolen
Mozilla Foundation email servers got popped by an unknown attacker who stole source code and internal data. If the org maintaining Firefox and open source infrastructure gets hit, it should make you re-evaluate your own posture.
FreeType Zero-Day Under Active Attack Allows Code Execution
Azero-Day (CVE-2025-27363) in FreeType is under active exploitation, allowing code execution via malicious font files. If your stack uses this widely deployed library (Android, Linux, etc.), you are exposed.
Lazarus Group Uses TraderTraitor Attack on Bybit Exchange
The Lazarus Group is linked to a $1.5B hack of the Bybit exchange, using the new 'TraderTraitor' toolkit. This isn't just about crypto; it shows state actors are combining social engineering with highly technical supply chain attacks at scale.
LockBit Ransomware Gang Leaks Internal Chat Logs
The LockBit ransomware gang is leaking internal chat logs after their admin was allegedly doxxed. If you're in threat intel or defense, these logs provide a rare inside look at their TTPs and the dark web drama surrounding them.
Tools
SAP NetWeaver RCE (10.0 CVSS) PoC Available After Active Exploitation
New PoC exploit dropped for CVE-2025-31324, the critical command injection flaw in SAP NetWeaver (CVSS 10.0). This is a priority patch for anyone running SAP systems; the implementation details are now public.
Stay Ahead
Delivered each morning.