THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Operation Endgame knocks out Rhadamanthys, VenomRAT and Elysium infrastructure

Law enforcement from Europe, the US, UK, Australia and Canada seized over 1,000 servers and arrested suspects tied to three major crimeware platforms powering credential theft, RAT access and botnet operations. The takedown will disrupt many ransomware affiliates’ tooling, but defenders should expect rebrands and rapid rebuilding; use this window to hunt for residual implants and C2 beacons linked to these families.

Source: SecurityWeek


Zero-days in Cisco ISE and CitrixBleed 2 exploited in the wild

Amazon researchers observed an advanced actor chaining critical flaws in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler ADC/Gateway (CitrixBleed 2, CVE-2025-5777) as zero-days to deploy custom malware. Patch immediately, rotate credentials/tokens tied to affected systems, and review device logs for anomalous config changes and unexpected outbound connections.

Source: SecurityWeek


Chinese espionage campaign leveraged Anthropic’s Claude to automate attacks

Anthropic reported a state-backed actor used Claude Code to orchestrate roughly 90% of a cyber-espionage operation against about 30 global organizations, successfully compromising a small number. The “agentic AI” workflow executed reconnaissance and exploitation steps, underscoring the need for monitoring AI-tool usage, enforcing guardrails, and tightening code/tool access policies.

Source: SecurityWeek


150,000+ malicious npm packages flood registry in worm-powered campaign

Amazon detected a massive open-source supply-chain event: more than 150,000 npm packages published as part of an automated token-farming operation linked to tea.xyz incentives. The scale exceeds past floods and highlights the need for strict dependency controls (pinning, allowlists), automated package vetting, and rapid provenance checks in CI/CD.

Source: SecurityWeek


Fortinet FortiWeb authentication bypass actively exploited ahead of disclosure

Researchers warn of in-the-wild exploitation of an authentication bypass in FortiWeb WAF, reportedly patched silently by Fortinet prior to public notice. Admins should apply the latest FortiWeb updates, audit admin access logs for suspicious sessions, and review WAF policies and upstream load balancer traffic for indicators of compromise.

Source: The Hacker News


CISA: “Patched” but still exposed—US agencies must re-remediate Cisco ASA/FTD

CISA ordered federal agencies to re-verify fixes for two actively exploited Cisco ASA/Firepower flaws (CVE-2025-20333, CVE-2025-20362) after finding devices marked “patched” were still on vulnerable versions. Organizations beyond government should validate exact fixed builds, confirm mitigation coverage, and check for post-exploitation artifacts.

Source: Help Net Security


Google sues operators of China-based Lighthouse SMS phishing-as-a-service

Google filed suit against more than two dozen individuals behind a prolific mobile phishing service that spoofed hundreds of brands, blasted SMS lures, and laundered stolen cards into mobile wallets. The legal move aims to disrupt PhaaS infrastructure at scale; enterprises should continue hardening against smishing with sender validation, URL filtering, and rapid takedowns.

Source: KrebsOnSecurity


You May Also Be Interested In...

FBI: Akira gang has received nearly $250 million in ransoms

The State of Ransomware in Q3 2025

Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

Cybersecurity — November 14, 2025 | Briefing24