THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Emergency update: Google patches actively exploited Chrome zero-day (CVE-2025-13223)

Google shipped an out-of-band fix for a type confusion bug in Chrome’s V8 engine that’s being actively exploited in the wild. The flaw can be triggered via a crafted HTML page to corrupt memory and enable unauthorized actions, making rapid updating critical for Chrome and Chromium-based browsers across all platforms.

Source: Help Net Security


FortiWeb under active attack: second exploited zero-day disclosed in a week (CVE-2025-58034)

Fortinet warned that a new OS command injection flaw in FortiWeb is being exploited, allowing attackers to execute arbitrary code on affected systems. Patches are available; organizations should urgently update, restrict management interfaces, and hunt for post-exploitation indicators.

Source: SecurityWeek


China-aligned PlushDaemon reroutes software updates via hacked routers

ESET researchers uncovered “EdgeStepper,” a Go-based implant used by the PlushDaemon group to hijack DNS on compromised routers and redirect software update traffic to attacker-controlled servers. The adversary-in-the-middle technique turns ordinary network gear into a stealthy entry point for espionage, underscoring the need for hardened edge devices, DNS monitoring, and strict update verification.

Source: Help Net Security


Cloudflare outage was a configuration error, not an attack—resilience lessons abound

An hours-long Cloudflare incident briefly disrupted access to major services including ChatGPT and X, but a postmortem confirmed a configuration error—not malicious activity—was to blame. The disruption highlights systemic dependence on single providers and the case for multi-CDN strategies, health checks, and clear failover playbooks.

Source: The Verge


Microsoft thwarts record 15.72 Tbps Aisuru botnet DDoS attack on Azure

Microsoft reported its largest-ever cloud DDoS attack—15.72 Tbps and 3.64 Bpps—targeting an Australian endpoint, mitigated by Azure DDoS Protection. Linked to the Aisuru/TurboMirai botnet, the event underscores ongoing volumetric risk fueled by insecure consumer/IoT devices and the need to test runbooks and protections before peak seasons.

Source: SecurityWeek


MI5: Chinese spies using LinkedIn to cultivate UK lawmakers

Britain’s domestic intelligence agency warned that operatives tied to China’s MSS are running fake LinkedIn personas to build relationships and extract intelligence from Westminster. The alert serves as a fresh reminder to validate unsolicited outreach, tighten social media vetting, and train staff on long-game social engineering.

Source: SecurityWeek


Self-replicating botnet hits internet-facing Ray AI clusters

Attackers are abusing exposed Ray clusters to deploy a worming botnet that mines cryptocurrency, steals data, and launches DDoS attacks—an “AI attacks AI” scenario targeting MLOps infrastructure. Teams should lock down Ray endpoints, require authentication, apply updates, and segment AI workloads from the public internet.

Source: The Register


You May Also Be Interested In...

Full renewal of state and local cyber grants program passes in House

DoorDash data breach and customer backlash over communications

Princeton University data breach impacts alumni, donors, and staff

Cybersecurity — November 19, 2025 | Briefing24