Multiple hackers around two laptops with central shield displaying lock surrounded by malware and envelopes

Daily Dose of Cybersecurity News - September 8, 2025

iCloud Calendar Exploited to Dispatch Phishing Emails

Medium

What happened

Attackers are exploiting iCloud Calendar invites to send phishing emails that appear to originate from Apple's servers, thereby increasing the likelihood of bypassing spam filters and reaching users' inboxes.

Who is affected

Apple users who receive unsolicited iCloud Calendar invites are the primary targets of this phishing campaign.

Why it matters

By leveraging Apple's legitimate email infrastructure, these phishing emails gain credibility, making it more challenging for users and security systems to identify them as malicious.

How it could have been prevented

Users should be cautious of unsolicited calendar invites and avoid interacting with unknown senders. Implementing stricter filtering rules for calendar invites can also help mitigate such attacks.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Spam Filters
Software tools designed to detect and block unsolicited and potentially harmful emails from reaching users' inboxes.

Recommended reading: BleepingComputer

Czech Cyber Agency Warns Against Chinese Tech in Critical Infrastructure

High

What happened

The Czech Republic's National Cyber and Information Security Agency (NUKIB) has issued a directive advising critical infrastructure organizations to avoid using Chinese technology and to refrain from transferring user data to servers located in China. This guidance stems from concerns over significant cybersecurity threats associated with such practices.

Who is affected

Critical infrastructure organizations within the Czech Republic are directly impacted by this advisory. Additionally, Chinese technology providers are implicated due to the concerns raised about their products and services.

Why it matters

The advisory underscores the heightened risk of cyber espionage and potential disruptions to essential services. By relying on technology from entities linked to foreign governments, critical infrastructure becomes vulnerable to unauthorized access and control, posing national security risks.

How it could have been prevented

Implementing stringent supply chain risk management practices and conducting thorough security assessments of technology providers can mitigate such risks. Additionally, diversifying technology sources and prioritizing vendors with transparent security protocols can enhance resilience.

Relevant professional terms

Critical Infrastructure
Systems and assets vital to national security, economic stability, public health, or safety, whose incapacitation would have a debilitating effect.
Cyber Espionage
The act of using cyber tools and techniques to obtain secret or sensitive information from individuals, competitors, or governments without permission.

Recommended reading: Czechia blames China for Ministry of Foreign Affairs cyberattack

Rapid AI Adoption Exposes Data Security Gaps

High

What happened

A recent survey of over 3,000 IT and security professionals revealed that while one-third of enterprises are integrating generative AI into their operations, nearly 70% express significant concerns about the security challenges posed by the rapidly evolving AI ecosystem.

Who is affected

Organizations across various sectors adopting generative AI technologies without adequate security measures are at risk.

Why it matters

The swift adoption of AI introduces complex security challenges, including data integrity attacks where malicious actors inject false information into AI models, potentially leading to compromised decision-making processes.

How it could have been prevented

Implementing comprehensive data security strategies tailored to AI environments, ensuring robust data integrity checks, and maintaining strict access controls could mitigate these risks.

Relevant professional terms

Generative AI
A type of artificial intelligence capable of generating new content, such as text, images, or code, based on training data.
Data Integrity Attack
A cyberattack aimed at compromising the accuracy and trustworthiness of data within a system.

Recommended reading: helpnetsecurity.com

Salesloft Drift Breach and Sitecore Zero-Day Vulnerability (CVE-2025-53690)

Critical

What happened

A significant supply chain attack targeted Salesloft's Drift integration, leading to unauthorized access to OAuth tokens and subsequent data breaches in multiple organizations. Simultaneously, a zero-day vulnerability (CVE-2025-53690) in Sitecore's content management system was exploited, allowing remote code execution on affected systems.

Who is affected

Organizations utilizing Salesloft's Drift integration, including Zscaler, Palo Alto Networks, and Cloudflare, were impacted. Additionally, entities using vulnerable versions of Sitecore's Experience Manager and related products are at risk.

Why it matters

These incidents highlight the critical vulnerabilities in third-party integrations and content management systems, emphasizing the need for robust security measures to protect sensitive data and maintain system integrity.

How it could have been prevented

Regularly auditing and securing third-party integrations, promptly applying security patches, and ensuring unique, secure configurations for all system components can mitigate such risks.

Relevant professional terms

OAuth tokens
Authorization credentials used to grant access to resources without sharing passwords.
Remote code execution (RCE)
A security vulnerability that allows an attacker to run arbitrary code on a target system.

Recommended reading: helpnetsecurity.com