THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
China-Linked UNC6384 Exploits Windows Zero‑Day Against European Diplomats

Arctic Wolf Labs reports that China‑nexus group UNC6384 is actively exploiting a Windows zero‑day to conduct espionage against diplomatic targets in Hungary, Belgium, and other EU nations. The campaign expands the group’s operations beyond earlier Southeast Asia targeting and underscores the urgency of applying temporary mitigations, tightening endpoint telemetry, and monitoring for suspicious lateral movement until a patch is available.

Source: Security Affairs


ASD Warns of BADCANDY Webshell on Unpatched Cisco IOS XE (CVE‑2023‑20198)

Australia’s Signals Directorate says attackers are exploiting the critical CVE‑2023‑20198 flaw on Cisco IOS XE, dropping a previously undocumented BADCANDY implant. Successful compromise can yield admin control of edge devices; defenders should patch immediately, audit for rogue users and unexpected web UI changes, and review device configs and logs for persistent implants.

Source: TheHackerNews


Active Windows Attacks With No Fix Available: CVE‑2025‑9491

Microsoft has confirmed in‑the‑wild exploitation of CVE‑2025‑9491 with no patch currently available. Organizations should apply Microsoft’s recommended mitigations, increase monitoring for related exploit indicators, and ensure rapid patch deployment once an update ships.

Source: Forbes Security


CISA: Ongoing Ransomware Attacks Target a Linux Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency warns that ransomware operators are actively exploiting a Linux vulnerability, dispelling myths that Linux is off attackers’ radar. Teams should prioritize patching, harden exposed services, deploy behavioral EDR on Linux workloads, and verify tested, offline backups.

Source: Forbes Security


Proton Confirms 300 Million Stolen Credentials Circulating on Dark Web

Proton has identified a massive trove of 300 million stolen credentials being traded on criminal marketplaces. Security teams should force password resets where appropriate, enable MFA across accounts, and advise users to monitor for reuse and enable breach alerts in their password managers.

Source: Forbes Security


Conti Case: Ukrainian Extradited to U.S. Over Ransomware Involvement

Irish authorities extradited Ukrainian national Oleksii Lytvynenko to the U.S. to face charges tied to the Conti ransomware enterprise. The action highlights sustained international cooperation against major ransomware operations and may yield further intelligence on Conti affiliates and infrastructure.

Source: Security Affairs


After Qantas Breach, Court Orders Raise Questions About Consumer Protection

Following a breach exposing frequent flyer data for 5 million Qantas customers, legal moves to restrict access to leaked data are drawing criticism. Experts argue such orders can shield brands more than consumers by limiting public verification and remediation, potentially benefiting scammers who already have the data.

Source: The Guardian


You May Also Be Interested In...

PayPal Attack Update: Another ‘Do Not Pay’ Warning Issued

New Kurdish Hacktivists Hezi Rash Behind 350 DDoS Attacks in 2 Months

‘Update And Shut Down’—Microsoft Confirms Windows Update Mistake

Cybersecurity — November 2, 2025 | Briefing24