THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA warns spyware crews are hijacking Signal and WhatsApp

US cybersecurity officials say state-backed groups and cyber-mercenaries are using commercial spyware and RATs to compromise high-value mobile users, bypassing end-to-end encryption by taking device-level control. Techniques include spoofed apps and even zero-click exploits. Enterprises should lock down mobile fleets, enforce OS/app updates, restrict sideloading, and monitor for MDM bypass and abnormal messaging app behavior.

Source: The Register


New ‘Shai-Hulud’ npm supply-chain attack infects 640 packages

A fresh wave of the self-replicating npm worm has compromised at least 640 packages, with a destructive twist that wipes home directories if it cannot spread further. The campaign abuses preinstall hooks to exfiltrate secrets and propagate via developer tokens, rapidly impacting thousands of repositories. Teams should lock dependencies, audit CI/CD secrets, rotate tokens, and enforce 2FA and provenance for packages.

Source: SecurityWeek


Fluent Bit flaws expose cloud environments to RCE and data tampering

Five newly assigned, “trivial-to-exploit” vulnerabilities in the widely deployed Fluent Bit telemetry agent (15B+ instances) allow auth bypass, path traversal, DoS, and remote code execution. Because Fluent Bit underpins logging in major clouds and AI labs, the bugs pose systemic risk to service availability and telemetry integrity until patches and hardening are applied.

Source: The Register


ShadowPad malware exploits patched WSUS bug for full system access

Threat actors are abusing a recently fixed Windows Server Update Services vulnerability (CVE-2025-59287) to gain initial access, use PowerCat for shells, and deploy the ShadowPad backdoor. Targeting WSUS-enabled servers, the attack leverages trusted update infrastructure to establish persistence and command-and-control.

Source: The Hacker News


FCC scraps post–Salt Typhoon telecom cyber rules amid ongoing espionage risk

The FCC has repealed cybersecurity rules introduced after the China-linked Salt Typhoon campaign, rolling back measures meant to keep state-backed operators out of US networks. The reversal could shift more security burden onto carriers and their suppliers, increasing scrutiny on network monitoring and supply-chain controls.

Source: The Register


Third-party breach at SitusAMC triggers data exposure concerns for major banks

JPMorgan, Citi, and Morgan Stanley are assessing potential exposure after attackers stole confidential client data from real-estate finance firm SitusAMC. The FBI is investigating; the incident underscores how vendor compromises can cascade to core financial institutions and their customers.

Source: TechCrunch


CISA orders rapid patching of actively exploited Oracle Identity Manager flaw

US agencies must mitigate an Oracle Identity Manager authentication bypass (CVE-2025-61757) by December 12 following evidence of in-the-wild abuse, possibly predating Oracle’s fix. The KEV-listed bug poses serious identity-tier risk, potentially enabling SSO compromise and lateral movement if left unaddressed.

Source: The Register


You May Also Be Interested In...
Is Your Android TV Streaming Box Part of a Botnet? (KrebsOnSecurity)
Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims (SecurityWeek)
Maximum severity Grafana vulnerability fixed (SC Media)
Cybersecurity — November 25, 2025 | Briefing24