Multiple hackers on laptops attacking central server with warning signs, shields, locks, and threat labels

Daily Dose of Cybersecurity News - October 5, 2025

Massive Surge in Scans Targeting Palo Alto Networks Login Portals

High

What happened

A significant increase in scanning activity targeting Palo Alto Networks login portals was observed, with a 500% rise in unique IP addresses conducting these scans on October 3, 2025. This surge suggests a coordinated effort to identify vulnerable systems.

Who is affected

Organizations utilizing Palo Alto Networks' GlobalProtect and PAN-OS platforms are the primary targets of these scanning activities.

Why it matters

The targeted scanning indicates potential reconnaissance efforts that could precede exploitation attempts, posing a risk of unauthorized access and data breaches for affected organizations.

How it could have been prevented

Regularly updating and patching systems to address known vulnerabilities, implementing robust access controls, and monitoring network traffic for unusual activities can help prevent such reconnaissance efforts.

Relevant professional terms

Reconnaissance
The preliminary phase of a cyber attack where attackers gather information about a target system to identify potential vulnerabilities.
GlobalProtect
A VPN solution by Palo Alto Networks that enables secure remote access to an organization's network.

Recommended reading: Cybersecurity Dive

Discord Data Breach Exposes User Information via Third-Party Support Provider

High

What happened

An unauthorized party compromised a third-party customer service provider used by Discord, gaining access to support tickets containing user data. The attacker attempted to extort a financial ransom from Discord.

Who is affected

A limited number of Discord users who interacted with the platform's Customer Support or Trust & Safety teams were affected.

Why it matters

The breach exposed sensitive user information, including names, email addresses, partial payment details, and government-issued IDs, increasing the risk of identity theft and phishing attacks.

How it could have been prevented

Implementing stricter access controls and regular security audits for third-party service providers could have mitigated the risk of unauthorized access.

Relevant professional terms

Personally Identifiable Information (PII)
Information that can be used to identify an individual, such as name, email address, or government-issued ID.
Phishing
A cyber attack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.

Recommended reading: Discord's Official Statement on the Security Incident

CometJacking Vulnerability in Perplexity's Comet AI Browser

High

What happened

A new attack method named CometJacking has been identified, targeting Perplexity's Comet AI browser. By embedding malicious prompts within seemingly harmless links, attackers can extract sensitive data from connected services such as email and calendar.

Who is affected

Users of Perplexity's Comet AI browser who have integrated it with services like Gmail and Calendar are at risk.

Why it matters

This vulnerability allows attackers to exploit the AI browser's authorized access to personal data, leading to potential data breaches without the need for credential theft. It underscores the emerging security challenges associated with AI-native tools.

How it could have been prevented

Implementing strict validation and sanitization of input parameters within the AI browser to prevent prompt injection attacks. Enhancing security measures to detect and block obfuscated data exfiltration techniques.

Relevant professional terms

Prompt Injection
A technique where malicious inputs are crafted to manipulate an AI system's behavior, leading it to perform unintended actions.
Base64 Encoding
A method of encoding binary data into an ASCII string format, often used to obfuscate data.

Recommended reading: Experts Find AI Browsers Can Be Tricked by PromptFix Exploit to Run Malicious Hidden Prompts