Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (13 November 2025)
Published: Loading…
At a Glance
- Microsoft’s November Patch Tuesday fixed 63 vulnerabilities, including an actively exploited Windows zero-day.
- The UK introduced its Cyber Security and Resilience Bill to strengthen national defences.
- Google filed lawsuits against China-based operators of the Lighthouse phishing-as-a-service platform.
- CISA warned federal agencies of ongoing exploitation of unpatched Cisco and Citrix zero-days.
- Amazon and researchers confirmed advanced attackers deploying custom malware through these flaws.
Summary
Microsoft released 63 security fixes in its November Patch Tuesday update, addressing several critical vulnerabilities, including a Windows Kernel zero-day currently under active exploitation. Intel, AMD, and Nvidia also issued advisories resolving over 60 flaws across chipsets, graphics, and driver components.
The UK government introduced its long-awaited Cyber Security and Resilience Bill, seeking to overhaul outdated laws and impose stronger requirements on essential sectors such as healthcare, energy, and transport. The bill threatens substantial penalties for organisations failing to meet the updated resilience standards.
Google launched a legal offensive against 25 China-based individuals behind the Lighthouse phishing-as-a-service network responsible for large-scale SMS scams impersonating major brands. The company also announced its new Emerging Threats Center to improve response speed to emerging vulnerabilities.
The Cybersecurity and Infrastructure Security Agency (CISA) warned that federal agencies have not fully patched vulnerable Cisco devices amid active exploitation campaigns. Related investigations by Amazon’s threat intelligence team revealed attackers abusing both Cisco Identity Services Engine and Citrix NetScaler zero-days to deploy tailored malware.
Separately, DanaBot malware re-emerged after a six-month hiatus following Operation Endgame, and the Rhadamanthys infostealer network was disrupted after operators lost access to servers. Ivanti and Zoom issued patches addressing high-severity flaws capable of privilege escalation and arbitrary file writing.
Highlights of the day:
- Rhadamanthys infostealer operation disrupted: control servers and Tor sites for the malware-as-a-service network were disabled, likely through a German-led action linked to Operation Endgame.
- UK unveils Cyber Security and Resilience Bill: new legislation expands NIS regulations to data centres and managed service providers, increasing reporting duties and regulator powers.
- Intel, AMD and Nvidia issue major patch updates: over 80 vulnerabilities fixed across chips and AI software, including high-severity flaws in Intel Xeon, AMD StoreMi, and Nvidia NeMo.
- Google sues phishing network “Lighthouse”: lawsuit targets a global SMS phishing operation stealing millions of credit card details, while supporting new US anti-scam legislation.
- DanaBot malware returns after takedown: version 669 of the banking trojan emerges with Tor-based C2 servers and crypto wallets, signalling persistent cybercriminal activity.
- CISA warns US agencies over unpatched Cisco devices: ongoing exploitation of CVE-2025-30333 and CVE-2025-20362 found despite previous directives, with attacks linked to China-based actors.
Highlights of the Day
Rhadamanthys Infostealer Operation Disrupted Amid Server Lockout
The Rhadamanthys malware-as-a-service network has been disrupted after cybercriminals reported losing access to their control servers. Researchers suggest German law enforcement may be behind the action, which disabled the web panels and Tor sites linked to the infostealer operation. The disruption appears connected to Operation Endgame, a wider campaign targeting malware infrastructure across Europe.
UK Introduces Cyber Security and Resilience Bill
The UK government has introduced the Cyber Security and Resilience Bill, aimed at strengthening national defences against cyber attacks and updating the 2018 NIS Regulations. The Bill expands regulatory coverage to include data centres and managed service providers, increases incident reporting obligations, and grants greater enforcement powers to regulators. It seeks to modernise the UK’s cybersecurity framework to address rising threats from state-sponsored and criminal actors.
Intel, AMD and Nvidia Patch Dozens of Chip Vulnerabilities
Intel, AMD and Nvidia have released security updates addressing more than 80 vulnerabilities across a range of hardware and software products. Intel issued fixes for over 60 flaws, including high-severity issues in Xeon processors and QuickAssist Technology, while AMD patched 14 vulnerabilities in devices such as Kria, Zynq and StoreMi. Nvidia resolved six security flaws in its AI software stack, including the NeMo and Megatron frameworks, affecting code execution and data integrity.
Google Sues Phishing Service and Backs US Anti-Scam Bills
Google has filed a lawsuit to dismantle “Lighthouse,” a global Phishing-as-a-Service network accused of running large-scale SMS phishing campaigns that stole millions of credit card details. The company alleges over one million victims were targeted using fake websites impersonating major brands, including Google. Alongside the legal action, Google has endorsed several bipartisan bills in the US Congress aimed at strengthening protections against fraud and cyber-enabled scams.
DanaBot Malware Resurfaces with New Infrastructure After Takedown
DanaBot, a banking trojan previously disrupted by Operation Endgame in May, has returned with a new version and rebuilt command-and-control infrastructure. Researchers at Zscaler identified the latest variant, version 669, using Tor-based domains and multiple cryptocurrency wallets to receive stolen funds. The malware’s resurgence highlights the persistence of financially motivated threat actors even after law enforcement interventions.
CISA Warns Federal Agencies Over Unpatched Cisco Devices
The Cybersecurity and Infrastructure Security Agency (CISA) has cautioned that several US federal agencies failed to fully patch vulnerable Cisco firewall devices, leaving them exposed to ongoing exploitation. The flaws, CVE-2025-30333 and CVE-2025-20362, have been actively targeted since September by a suspected China-based group linked to the ArcaneDoor campaign. CISA found that some devices marked as patched were still running insecure software versions and has ordered immediate corrective updates.
Daily Coverage