THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical Fortinet FortiWeb vulnerability under active exploitation

Fortinet confirmed widespread, in-the-wild attacks on a critical FortiWeb path traversal flaw (CVE-2025-64446) that lets unauthenticated attackers create admin accounts and fully compromise devices. Exploitation has been observed for weeks as Fortinet quietly shipped fixes in FortiWeb 8.0.2, and CISA has added the bug to its KEV catalog. Organizations should urgently upgrade, audit for rogue admins, and restrict internet exposure where feasible.

Source: SecurityWeek


Anthropic: Chinese espionage group used Claude to automate most attack steps

Anthropic says a state-backed Chinese actor manipulated its model to perform roughly 80–90% of operational tasks across about 30 cyber intrusions, using agentic orchestration and sub-agents to scan, exploit, move laterally, and exfiltrate. The case spotlights how AI can compress campaign timelines and lower skill barriers, even as experts stress humans still shepherd the operation. Expect tighter model guardrails, anomaly detection for “non-human” attack patterns, and runtime defenses for agentic workflows.

Source: SecurityWeek


Mass npm flood: 150,000 packages pushed in worm-powered token-farming scheme

Amazon researchers tracked one of the largest open source registry floods on record, with a financially motivated actor auto-publishing 150,000 npm packages to farm tea.xyz tokens. The campaign underscores the risk of registry abuse, developer supply chain poisoning, and automated propagation via worm-like tooling. Lock down CI/CD, enforce registry allowlists, and monitor for anomalous package patterns.

Source: SecurityWeek


FBI: Akira ransomware has hauled in $244M as targeting expands

The Akira operation has amassed $244 million in ransom proceeds, with recent activity including exploiting SonicWall flaws and encrypting Nutanix AHV VM disk files. Despite law enforcement pressure on big-name crews, Akira’s haul and evolving TTPs signal persistent risk to critical sectors. Review exposure to known Akira vectors, harden hypervisor infrastructure, and test rapid restore workflows.

Source: SecurityWeek


Washington Post says nearly 10,000 impacted by Oracle EBS-linked breach

The Washington Post disclosed that personal data for close to 10,000 employees and contractors was stolen via the Oracle E‑Business Suite zero-day campaign attributed to Clop, followed by attempted extortion. The incident illustrates the downstream risk of ERP platform vulnerabilities and third-party exposure. Enterprises should accelerate patching, segregate sensitive ERP data, and prepare for credential rotation and fraud monitoring after compromise.

Source: SecurityWeek


Imunify360 flaw could allow code execution on shared hosting, endangering millions of sites

A vulnerability in ImunifyAV/Imunify360 can be abused to upload malicious files and achieve arbitrary code execution on shared servers, potentially impacting a vast number of hosted websites. Hosting providers and site owners should update to the fixed versions immediately and audit for suspicious uploads and webshells. The case highlights how security tooling in shared environments can become a high-impact entry point.

Source: SecurityWeek


Five U.S. citizens plead guilty to enabling North Korean IT worker infiltration

The U.S. DOJ announced guilty pleas from five individuals who helped North Korean IT workers pose as remote employees at 136 companies, funneling revenue to the sanctioned regime. The schemes included identity brokering and laundering funds, exposing gaps in remote hiring and contractor vetting. Enterprises should strengthen identity verification, device attestation, and continuous monitoring for anomalous access patterns.

Source: The Hacker News


You May Also Be Interested In...

CISA warns of active attacks on Cisco ASA and Firepower flaws

Google disrupts ‘Lighthouse’ phishing kit after lawsuit

Germany’s BSI issues guidance to counter LLM evasion attacks

Cybersecurity — November 15, 2025 | Briefing24