THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China‑linked PlushDaemon hijacks network devices to intercept software updates

ESET researchers uncovered a network implant used by the PlushDaemon APT to perform adversary‑in‑the‑middle attacks by redirecting DNS on compromised routers and other gear. The operation hijacks software update traffic to attacker‑controlled infrastructure, creating a stealthy path to deploy malware at scale. Security teams should lock down egress DNS, audit network devices for unauthorized config changes, and verify update channels via certificate pinning and allowlists.

Source: ESET Blog


Stealth‑patched FortiWeb flaw under active exploitation (CVE‑2025‑58034)

Fortinet confirmed in‑the‑wild exploitation of an OS command injection bug in FortiWeb that was fixed without prior public disclosure. The vulnerability allows authenticated attackers to execute unauthorized code via crafted HTTP requests or CLI commands and is the second exploited FortiWeb zero‑day disclosed in a week. Patch immediately and review appliance logs for anomalous admin activity and suspicious command execution.

Source: Help Net Security


7‑Zip RCE (CVE‑2025‑11001) is being actively exploited

NHS England warns that attackers are exploiting a high‑severity path traversal bug in 7‑Zip to achieve remote code execution. The flaw, introduced in v21.02, is fixed in 7‑Zip v25.00; a related directory traversal (CVE‑2025‑11002) was also addressed. Organizations should upgrade to 25.00+ across endpoints, hunt for suspicious archive extraction activity, and restrict execution from temp/unpack locations.

Source: Help Net Security


Operation “WrtHug” hijacks tens of thousands of EoL ASUS routers

A global campaign dubbed WrtHug is exploiting multiple ASUSWRT flaws to compromise more than 50,000 end‑of‑life ASUS routers, largely in Taiwan, the U.S., and Russia. Researchers say the botnet appears geared toward stealthy cyber‑espionage, highlighting the systemic risk of unmanaged consumer and SMB edge devices. Replace unsupported routers, disable remote administration, and isolate/home‑office gear from corporate networks.

Source: The Hacker News


Amazon details “cyber‑enabled kinetic targeting” by Iran‑linked actors

Amazon threat intelligence documented cases where Iranian groups used cyber operations to map targets and enable real‑world missile strike attempts. The findings underscore the blurring line between state cyber activity and physical conflict, with commercial sectors like shipping, transportation, and electronics caught in the crossfire. Organizations with OT, maritime, or logistics exposure should elevate threat modeling, tighten telemetry around AIS and other operational data, and rehearse cross‑domain incident response.

Source: SecurityWeek


Cloudflare outage doubles as an unplanned security “roadmap”

A widespread Cloudflare incident briefly took top sites offline and forced some customers to bypass the platform—exposing origins directly to the internet. As Krebs notes, the failover acted like an impromptu penetration test for organizations that lean on Cloudflare to absorb DDoS and filter abuse. Teams should harden origin infrastructure, plan for equivalent protection during CDN/CDN‑WAF failover, and test fail‑open vs. fail‑closed behaviors.

Source: KrebsOnSecurity


US and allies sanction Russian bulletproof hosting used by ransomware gangs

The U.S., U.K., and Australia sanctioned Media Land and related entities accused of providing “bulletproof” hosting to ransomware operations, including LockBit and BlackSuit. The action targets infrastructure that underpins extortion and data theft, increasing compliance pressure on organizations to avoid tainted services. Security teams should update blocklists, scrutinize provider dependencies, and monitor for connections to sanctioned networks.

Source: Recorded Future News (The Record)


You May Also Be Interested In...

Google addresses Chrome zero‑day leveraged in attacks

Two‑year‑old Ray AI framework flaw exploited in ongoing campaign

EU designates 19 tech providers as critical infrastructure

Cybersecurity — November 20, 2025 | Briefing24