This is today’s cyber news for October 23rd, 2025. Attackers are raiding Magento stores, China-linked actors are revisiting SharePoint, and a Rust TAR parser flaw raises fresh supply-chain worries. We also cover why common AI agents can be tricked into running commands and how an MCP registry issue exposed thousands of servers and keys. The middle of the brief turns to policy and nation-state pressure, plus quick-hit updates on TP-Link gateways, GitLab patches, NuGet supply chain abuse, and a doxxing-driven slump in the Lumma stealer market.
Listeners will hear who’s most at risk in plain English and exactly what to watch—signals, not hand-waving. Leaders get priorities; defenders get one practical next step per story. We wrap with Pwn2Own takeaways, the ripple cost of JLR’s outage, OAuth persistence in cloud tenants, and a new EY datapoint that half of companies already feel AI security pain. The narrated version is available at DailyCyber.news.