tactical

Tactical

Live incidents, exploited CVEs, IOCs, and breaches

PRIVSEC·Vulnerabilities & CVEs·highCONF 61
USmedium · 45CISA

Cybersecurity and Infrastructure Security Agency confirms exploitation of Oracle E-Business Suite CVE-2025-61884

Bottom line: the flaw was added to the Known Exploited Vulnerabilities catalog after confirmed in-the-wild abuse following the earlier zero-day campaign. Treat catalog additions as a patch deadline, not a notification.

Automated analysis from cited open sources.

Private SectorOct 21, 2025BleepingComputer (opens in new tab) Details
#Known Exploited Vulnerabilities#CVE-2025-61884#Oracle
PRIVSEC·Industry & Vendors·highCONF 57

SecurityWeek: Oracle E-Business Suite flaw exploited across dozens of customer environments

Bottom line: a cluster associated with FIN11 conducted mass data theft from Oracle E-Business Suite instances before extorting victims. Inventory internet-reachable enterprise resource planning endpoints and log their outbound data volume.

Automated analysis from cited open sources.

Private SectorOct 21, 2025SecurityWeek (opens in new tab) Details
#FIN11#Data theft#Enterprise resource planning
US-FED·Cyber Policy & Strategy·criticalCONF 57
USmedium · 43CISAUS (general)

Cybersecurity and Infrastructure Security Agency directs agencies to act on F5 vulnerabilities

Bottom line: agencies were told to identify F5 BIG-IP assets, restrict management interfaces and apply the vendor's releases on a compressed timeline. Verify exposure of every appliance management plane, not only the patch level.

Automated analysis from cited open sources.

Federal Civilian GovernmentOct 15, 2025CISA alert (opens in new tab) Details
#F5 BIG-IP#Federal Civilian Executive Branch#Patch deadline
CI-ENERGY·Critical Infrastructure·highCONF 57

Joint advisory on the People's Republic of China espionage system names transportation and military infrastructure

Bottom line: the advisory's technical annex covers router configuration abuse, tunneling and long-dwell access on provider infrastructure serving energy and transport customers. Compare running configurations against known-good baselines on every internet-facing router.

Automated analysis from cited open sources.

#Router configuration#Tunneling#Persistence
ADV-CN·Threat Intelligence·mediumCONF 78

CyberScoop: twelve Chinese nationals indicted over a hacker-for-hire espionage spree

Bottom line: the unsealed cases describe a contracting ecosystem selling stolen data to Chinese security services. Expect commercial intermediaries, not uniformed units alone, in future attribution.

Automated analysis from cited open sources.

Adversary: China (PRC)Mar 5, 2025CyberScoop (opens in new tab) Details
#Hacker for hire#Attribution#Ministry of Public Security

AI Daily Briefing

ICD 203 · Briefing for today

Automated analysis, generated from cited open sources using a methodology designed by a United States Intelligence Community veteran.

CI-COMMS·Incidents & Breaches·highCONF 61
USlow · 11US (general)

Chinese operators breach additional United States telecom networks through unpatched Cisco routers

Bottom line: reporting on the Insikt Group findings identified further carrier compromises through Cisco devices left unpatched for over a year. Asset inventory gaps on network gear, not novel exploits, are carrying this campaign.

Automated analysis from cited open sources.

Critical Infra: CommunicationsFeb 14, 2025BleepingComputer (opens in new tab) Details
#Salt Typhoon#Cisco#Carriers
ADV-CN·Threat Intelligence·mediumCONF 57
USmedium · 40Treasury / OFAC

WIRED: Salt Typhoon keeps hacking telecoms despite sanctions

Bottom line: public reporting confirmed the group continued operations through the sanctions and indictment cycle. Assume designation has deterrence value for financiers, not for the operators themselves.

Automated analysis from cited open sources.

Adversary: China (PRC)Feb 13, 2025WIRED (opens in new tab) Details
#Salt Typhoon#Deterrence#Open source reporting
ADV-CN·Cyber Diplomacy & Norms·highCONF 57
USmedium · 48Treasury / OFACUS (general)

Associated Press: Treasury sanctions follow the telecom hack and the breach of its own network

Bottom line: the designations covered both the carrier campaign and an intrusion into Treasury systems through a third-party support provider. Third-party remote support tooling remains an unresolved federal exposure.

Automated analysis from cited open sources.

Adversary: China (PRC)Jan 17, 2025Associated Press (opens in new tab) Details
#Treasury#Third party access#Sanctions
ALLIES·Defensive Operations·mediumCONF 57
USlow · 8US (general)

Canadian Centre for Cyber Security bulletin on People's Republic of China targeting of telecom operators

Bottom line: an allied agency independently confirmed the same telecommunications espionage pattern against its own carriers. Coordinated allied bulletins raise the confidence level attached to the United States assessment.

Automated analysis from cited open sources.

Allied & Partner NationsOct 21, 2024Canadian Centre for Cyber Security (opens in new tab) Details
#Five Eyes#Telecommunications#Allied reporting
CRIME·Incidents & Breaches·highCONF 57
USlow · 8US (general)

Operation Cronos seizes LockBit infrastructure and publishes affiliate detail

Bottom line: international law enforcement took the leak site, recovered decryption keys and exposed the affiliate structure of the most active ransomware brand. Infrastructure seizure combined with public exposure now precedes arrests in United States practice.

Automated analysis from cited open sources.

Cybercrime / RansomwareFeb 20, 2024US Department of Justice (opens in new tab) Details
#LockBit#Operation Cronos#Ransomware