THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Hacking Team returns: New ‘Dante’ spyware tied to ForumTroll APT

Kaspersky researchers uncovered a previously unidentified commercial spyware dubbed Dante, developed by Memento Labs (formerly Hacking Team), and linked it to ongoing ForumTroll APT operations. The findings spotlight a mature mercenary spyware ecosystem and renewed offensive activity from a historically controversial vendor. Organizations in high-value sectors should review high-risk endpoint telemetry and harden browser/app update channels.

Source: SecureList


Chrome zero-day exploitation linked to Hacking Team spyware operator

SecurityWeek reports that the actor behind Operation ForumTroll leveraged a Chrome zero-day and the same toolset typically associated with Dante spyware campaigns. The link further validates active, in-the-wild exploitation paired with commercial-grade surveillance tooling. Teams should ensure Chrome is up to date and expand monitoring for post-exploitation beacons or anomalous browser child processes.

Source: SecurityWeek


Cisco Talos dissects Qilin ransomware’s living-off-the-land playbook

Cisco Talos analyzed the Qilin ransomware group, noting frequent targeting of manufacturing, extensive use of legitimate tools for credential theft and data exfiltration, and advanced methods for lateral movement, evasion, and persistence. The group’s living-off-the-land approach complicates detection and accelerates time-to-impact. Defenders should baseline admin tool usage, enforce least privilege, and tighten EDR detections on credential dumping and data staging behaviors.

Source: Cisco Talos


Mass exploitation of year-old WordPress plugin flaws resumes

Attackers have reignited large-scale exploitation of critical vulnerabilities in the GutenKit and Hunk Companion WordPress plugins, with roughly 9 million attempts observed this month. The bugs enable unauthenticated arbitrary plugin installation leading to remote code execution. Site admins should immediately patch or remove affected plugins, audit for rogue additions, and rotate credentials if compromise is suspected.

Source: SecurityWeek


Hackers weaponize Windows update infrastructure flaw—patch WSUS now

Active exploitation of a critical Windows Server/WSUS-related vulnerability could let attackers turn trusted updates into malware delivery, according to new reporting. Microsoft urges rapid installation of the latest security patches to protect software distribution chains. Enterprises should also review WSUS configurations, code-signing policies, and endpoint update logs for anomalies.

Source: CyberNews


UN Cybercrime Treaty signed by 72 nations, privacy concerns persist

The UN’s new Convention against Cybercrime drew dozens of signatories and enables broader surveillance and cross-border evidence sharing. Critics warn the framework could weaken civil liberties and be misused by authoritarian regimes. Security and legal teams should prepare for shifting international cooperation requests and ensure data-handling practices align with evolving obligations.

Source: The Register


US House Democrats’ site exposed applicants with ‘Top Secret’ clearances

A database containing information on applicants—including those with ‘Top Secret’ clearances—was left accessible on the open web. The exposure underscores ongoing risks in public-facing assets and third-party recruiting workflows. Organizations should enforce strict access controls, perform continuous external surface scans, and apply data minimization for candidate pipelines.

Source: Wired


You May Also Be Interested In...

Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack (The Hacker News)
Active Water Saci Campaign in WhatsApp Features Multi-Vector Persistence (Trend Micro Research)
AI writes code like a junior dev, and security is feeling it (Help Net Security)
Cybersecurity — October 27, 2025 | Briefing24