THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA warns of actively exploited WSUS flaw, orders agencies to patch

The US government issued an emergency directive for federal agencies to remediate a Windows Server Update Services (WSUS) remote code execution bug after researchers found the prior fix “did not fully mitigate” the issue. The flaw is under active exploitation, raising the risk of attackers hijacking enterprise patch infrastructure to push malicious updates. Organizations should apply Microsoft’s out-of-band update immediately and audit WSUS servers for signs of compromise.

Source: Recorded Future News


Chrome zero-day tied to Italian spyware vendor Memento Labs

Investigators linked exploitation of a Chrome sandbox escape zero-day (CVE-2025-2783) to delivery of LeetAgent, an espionage tool associated with Memento Labs (formerly Hacking Team). The campaign highlights the continued use of commercial surveillanceware and supply chains to target high-value users across platforms. Update Chrome to the latest version and consider EDR protections that detect post-exploitation behaviors.

Source: The Hacker News


Swedish power grid operator hit by data breach; operations unaffected

Sweden’s national grid operator confirmed data theft via a file transfer solution after a ransomware group claimed responsibility, but emphasized the power supply was not impacted. The incident underscores third-party and data-movement risks in critical infrastructure, where exfiltration and extortion are increasingly favored over encryption. Energy-sector defenders should harden file-transfer tools, enforce least-privilege access, and monitor for anomalous data egress.

Source: SecurityWeek


Ransomware payments fall to historic lows as victims resist

Only 23% of ransomware victims paid in Q3 2025, and for data-theft-only incidents the rate fell to 19%, according to Coveware’s latest analysis. As enterprises invest in resilience and legal guidance, threat actors are adapting with higher-pressure tactics and multi-stage extortion. Bolstering backup integrity, incident playbooks, and legal/PR coordination continues to pay dividends for victim organizations.

Source: SecurityWeek


US declines to sign UN cybercrime treaty as 70+ countries join

More than 70 nations signed the first global UN Convention against Cybercrime, but the United States opted out at this stage. The pact aims to improve cross-border cooperation and enforcement, while critics warn about potential overreach and civil liberties concerns. The decision has implications for how evidence-sharing and international investigations will proceed over the next several years.

Source: Recorded Future News


Mass exploitation resumes against year-old WordPress plugin flaws

Attackers reignited large-scale exploitation of critical vulnerabilities in the GutenKit and Hunk Companion WordPress plugins, with roughly 9 million exploit attempts observed this month. The bugs enable unauthenticated arbitrary plugin installation leading to remote code execution. Site admins should update or disable affected plugins, scan for rogue plugins/backdoors, and rotate credentials.

Source: SecurityWeek


New Atlas browser exploit plants persistent hidden commands

Researchers disclosed a flaw in OpenAI’s ChatGPT Atlas browser that allows attackers to inject instructions into the agent’s memory, persist across sessions, and run arbitrary code. Coming on the heels of other prompt-injection vectors, the finding spotlights the risks of “agentic” browsing that intermixes user commands, navigation, and automation. Organizations trialing Atlas should restrict its use, apply strict tenant controls, and monitor agent actions until fixes are available.

Source: The Hacker News


You May Also Be Interested In...

Massive China-Linked Smishing Campaign Leveraged 194,000 Domains

Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs

Phishing scam uses fake death notices to trick LastPass users

Cybersecurity — October 28, 2025 | Briefing24