THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Samsung 0‑Day ‘LandFall’ Exploited via WhatsApp Images to Install Spyware

Attackers are abusing malicious WhatsApp images to exploit a critical Samsung zero-day vulnerability dubbed “LandFall,” enabling stealthy spyware installation on targeted devices. Mobile defenders should harden media handling, monitor high-risk devices, and push rapid patching once fixes land; end users should disable auto media downloads and stay current on security updates.

Source: Forbes Security


Microsoft Details ‘Whisper Leak’: Side-Channel Attack Reveals AI Chat Topics Despite Encryption

Microsoft disclosed a novel side-channel attack on streaming-mode language models that allows a passive network observer to infer conversation topics even over encrypted channels. The finding raises confidentiality concerns for enterprise AI deployments and underscores the need for traffic-shaping and other mitigations, as well as caution when sharing sensitive data with remote LLMs.

Source: TheHackerNews


China-Linked APT Maintained Weeks-Long Access at U.S. Policy Nonprofit

A China-linked group breached a U.S. policy-focused nonprofit in April 2025 and persisted for weeks, using DLL sideloading via vetysafe.exe—a technique seen across clusters like Space Pirates and Kelp. The campaign highlights the continued APT pressure on civil society and policy institutions and the need to detect signed-binary abuse, DLL search-order hijacking, and long-dwell persistence.

Source: Security Affairs


Fifth Italian Target Hit by Paragon’s ‘Graphite’ Spyware, Escalating Surveillance Concerns

Italian political adviser Francesco Nicodemo revealed he was targeted with Paragon’s Graphite spyware, marking at least the fifth Italian victim. Graphite enables covert access to sensitive mobile data, renewing calls for stronger oversight of commercial spyware, improved mobile threat detection, and protections for political and civil-society figures.

Source: Security Affairs


FBI Subpoena Seeks to Unmask Archive.ph Operator via Registrar Records

The FBI issued a federal subpoena to registrar Tucows seeking extensive billing and session records to identify the operator of Archive.ph (also known as Archive.today and Archive.is). The case, tied to an undisclosed criminal investigation, spotlights how infrastructure providers can be compelled to disclose metadata and the privacy implications for operators of contentious online services.

Source: HackRead


EFF: Android’s Built-In Defenses Miss Stalkerware, Leaving Victims Exposed

The Electronic Frontier Foundation warns that Android’s built-in antivirus protections, including Google Play Protect, often fail to detect stalkerware. Organizations supporting at-risk users should consider specialized tools and safety practices, while platform vendors face growing pressure to better classify and block surveillanceware masquerading as legitimate apps.

Source: CyberNews


Cisco Patches Critical Flaws in Unified Contact Center Express; Patch Tuesday Looms

Cisco released fixes for critical vulnerabilities in its Unified Contact Center Express platform, with defenders urged to prioritize patching, especially for internet-exposed systems. With November’s Patch Tuesday approaching, teams should review asset inventories, test updates promptly, and prepare for likely patches across Microsoft and major enterprise stacks.

Source: Help Net Security


You May Also Be Interested In...

Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map — The Register
Why Cybersecurity Must Shift To Continuous Incident Response — Forbes Security
Policy Meets AI: Why Broken Rules Break Customer Service — GovTech
Cybersecurity — November 9, 2025 | Briefing24