THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Hackers exploit Triofox flaw to gain admin access and run code via AV feature

Mandiant detailed in-the-wild exploitation of CVE-2025-12480 in Gladinet’s Triofox platform, where attackers spoof a localhost Host header to reach setup pages, create a “Cluster Admin” account, and abuse the built-in antivirus configuration to execute SYSTEM-level scripts. The intruders then deployed remote access tools and set up reverse SSH tunnels using renamed PuTTY/Plink binaries. Triofox version 16.7.10368.56560 patches the issue; teams should upgrade immediately, audit admin accounts and AV paths, and hunt for reverse SSH and suspicious process launches.

Source: Google Cloud Security / Mandiant


GlassWorm malware resurfaces via VS Code extensions on Open VSX and GitHub

GlassWorm has re-emerged in the developer supply chain, with three additional Visual Studio Code extensions carrying the malware and thousands of downloads, per new research. Despite prior takedowns, attackers pivoted to alternative registries and repositories, underscoring persistent token abuse and publisher impersonation risks. Developers should audit installed extensions, verify publishers, rotate credentials, and restrict marketplace sources.

Source: SecurityWeek


Zero‑day LANDFA LL spyware targeted Samsung Galaxy devices via malicious images

Unit 42 uncovered “LANDFALL,” commercial-grade Android spyware, which exploited CVE-2025-21042 to trigger via booby-trapped images shared in apps like WhatsApp. Targeted Samsung Galaxy models include recent flagships; successful exploitation enabled remote surveillance and data theft. Users should apply Samsung’s security updates immediately and review SMS/media permissions.

Source: HackRead


New runC vulnerabilities enable container escapes; patches available

Three vulnerabilities in runC (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) allow attackers to break out of containers in Docker and Kubernetes environments. The flaws have been patched; organizations should update runC/container runtimes across clusters, rebuild affected nodes where applicable, and harden isolation policies (e.g., Pod Security, seccomp, and least-privilege).

Source: SecurityWeek


Congress moves to temporarily restore cyber info‑sharing liability protections

Senate legislation to end the government shutdown includes a short-term renewal of the 2015 law that shields companies from liability when sharing cyber threat indicators with the federal government. Extending the protections through January 30 aims to prevent a chilling effect on cross-sector information sharing while a longer-term solution is negotiated.

Source: The Record by Recorded Future


After F5 breach, BIG‑IP source code theft poses long‑tail risks

Following the nation-state breach of F5, researchers warn that stolen BIG-IP source code could aid vulnerability discovery and future exploit development, even if immediate impacts appear limited. Customers should accelerate patching, minimize public exposure of management interfaces, and monitor for abnormal device behavior and traffic patterns.

Source: CyberScoop


‘Whisper Leak’ side‑channel can reveal topics of encrypted LLM conversations

Microsoft researchers demonstrated a side-channel technique that can infer the subject of encrypted chats with large language models by observing model interaction patterns. Some providers reportedly remain unpatched, highlighting that transport encryption doesn’t hide contextual signals. Organizations should treat sensitive prompts with care and demand provider-level mitigations.

Source: The Register


You May Also Be Interested In...

Two New Web Application Risk Categories Added to OWASP Top 10

New Phishing Campaign Abuses Meta Business Suite to Target SMBs

QNAP Patches Vulnerabilities Exploited at Pwn2Own

Cybersecurity — November 11, 2025 | Briefing24