THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Shai‑Hulud 2.0 slams npm: preinstall abuse hits hundreds of packages

Check Point researchers detailed a fast‑moving supply chain attack that, between November 21–23, compromised hundreds of npm packages and more than 25,000 GitHub repositories within hours. The campaign, dubbed “The Second Coming,” abuses npm’s preinstall lifecycle script so the payload runs before installation finishes—speeding propagation and complicating detection. Teams should audit dependency trees, pin and verify package versions, and restrict lifecycle scripts in CI/CD.

Source: Check Point Blog


Ransomware disrupts U.S. local emergency alert platform; data breach confirmed

The Inc Ransom group targeted the OnSolve CodeRED platform, causing outages across local emergency alert services and exfiltrating data. The incident underscores the societal impact of third‑party service compromises and the need for resilient public‑safety communications. Agencies should validate contingency channels, test failovers, and review vendor incident response SLAs.

Source: SecurityWeek


Critical Fluent Bit flaws could enable cloud service takeover

Researchers disclosed five vulnerabilities in the widely used Fluent Bit telemetry agent that can enable path traversal, remote code execution, denial‑of‑service, and tag manipulation. Given Fluent Bit’s ubiquity in cloud‑native stacks, the blast radius spans SaaS platforms, security tools, and delivery apps. Patch promptly, harden agent configs, and reassess trust boundaries around log ingestion pipelines.

Source: SecurityWeek


FBI: $262M lost to account takeover fraud as holidays begin

The FBI reports more than 5,100 account takeover (ATO) complaints and at least $262 million in losses this year, driven by bank‑impersonation schemes. Attackers coax victims into sharing credentials or approving fraudulent transfers, exploiting seasonal shopping spikes to blend in. Organizations should enforce strong MFA, step‑up verification for high‑risk transactions, and proactive account monitoring.

Source: $262 million stolen in account takeover fraud schemes this year, FBI says ahead of holiday season | The Record


CISA: Commercial spyware crews are targeting Signal and WhatsApp users

CISA warns that state‑linked actors and cyber‑mercenaries are using commercial spyware and RATs to compromise high‑value targets’ mobile devices and messaging apps. By owning the endpoint via malicious apps and exploited vulnerabilities, attackers bypass end‑to‑end encryption and access message content. High‑risk users should disable sideloading, keep devices fully patched, and watch for signs of compromise.

Source: SecurityWeek


Tor to deploy Counter Galois Onion encryption across relays

The Tor Project is replacing its long‑standing tor1 relay encryption with Counter Galois Onion (CGO), a major upgrade to strengthen confidentiality and integrity across the network. The modernization lays groundwork for future performance and security improvements. Relay operators and users should follow the rollout guidance to ensure compatibility and smooth migration.

Source: Help Net Security


New ClickFix wave hides malware in PNGs, fakes Windows updates

Malware campaigns are evolving ClickFix lures by embedding payloads within images and presenting convincing “Windows Update” screens to trick victims into executing malicious commands. The technique is fueling fresh infostealer deliveries while evading basic detection. Block risky script execution paths, harden browser download policies, and train users to verify update prompts via trusted system channels.

Source: Malwarebytes


You May Also Be Interested In...
WhatsApp closes loophole that let researchers collect data on 3.5B accounts
HashJack attack shows AI browsers can be fooled with a simple ‘#’
Dartmouth College Confirms Data Theft in Oracle Hack
Cybersecurity — November 26, 2025 | Briefing24