THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Ransomware knocks out CodeRED emergency alert system across U.S. municipalities

The Inc Ransom group hit the OnSolve CodeRED platform, disrupting local emergency notifications for state and local governments and exposing data in the process. The outage underscores third‑party risk to critical communications and the need for contingency channels, incident response runbooks, and rapid credential/token rotation for connected services.

Source: SecurityWeek


New “HashJack” prompt injection hijacks AI browsers and assistants

Researchers detailed “HashJack,” an indirect prompt injection that hides malicious instructions in a URL’s fragment (#) to manipulate AI assistants into exfiltrating data, delivering phishing, or pushing risky actions. The attack affects popular AI-enabled browsing tools and highlights the need to strip fragments from fetched content, restrict tool use, and add robust content provenance and allowlists.

Source: Help Net Security


Mirai variant “ShadowV2” surfaced during AWS outage to conscript IoT for DDoS

FortiGuard Labs analyzed ShadowV2, a Mirai-based botnet that emerged amid a recent AWS disruption, targeting exposed IoT gear to build DDoS firepower. The campaign’s timing and propagation techniques reinforce the need to harden and segment IoT, disable UPnP and default services, and maintain continuous monitoring for anomalous outbound traffic.

Source: Fortinet


Salesforce issues IoCs and timeline after Gainsight-connected breach

Salesforce shared indicators of compromise and a likely attack window tied to the Gainsight incident, noting reconnaissance from November 8 and intrusions between November 16–23. Organizations should audit connected apps, revoke and reissue tokens, review access logs for the provided IPs/User Agents, and hunt for suspicious API activity.

Source: Help Net Security


ASUS patches critical AiCloud router auth bypass (CVE-2025-59366)

ASUS released firmware updates fixing nine flaws, including a critical authentication bypass (CVSS 9.2) affecting routers with AiCloud enabled. Admins should patch immediately, disable AiCloud if updates can’t be applied promptly, and restrict WAN access to management interfaces.

Source: Security Affairs


Shai‑hulud 2.0 targets cloud and developer ecosystems, backdoors victim packages

Trend Micro warns of a campaign stealing credentials and secrets from major cloud and developer platforms and automating backdoors into npm packages maintained by compromised developers. The supply chain risk to downstream users calls for token rotation, hardened CI/CD, package publishing protections (2FA, code signing), and vigilant dependency monitoring.

Source: Trend Micro Research


Thousands of secrets leaked via popular code formatting websites

Security researchers found JSONFormatter and CodeBeautify users inadvertently exposed more than 80,000 files containing sensitive data like passwords, API keys, and private configs across critical sectors. Teams should prohibit uploading sensitive data to third‑party tools, deploy DLP and secret scanning, and offer secure, internal alternatives for code formatting and sharing.

Source: SecurityWeek


You May Also Be Interested In...

Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malware
London councils probe cyber incident as shared IT systems knocked offline
Malicious Chrome extension injects hidden Solana transfer fees
Cybersecurity — November 27, 2025 | Briefing24