THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Ransomware cripples CodeRED emergency alert platform, triggers nationwide warnings

A ransomware attack on the CodeRED emergency alert platform caused outages and triggered warnings across the U.S., raising alarms about the resilience of public-notification infrastructure. The incident highlights third‑party risk in crisis communications and the need for vendor access hardening, redundancy, and joint incident response exercises with municipalities and 911/EMA stakeholders.

Source: Malwarebytes Blog


OpenAI cuts off Mixpanel after analytics breach exposes API user data

OpenAI said API users may have been affected by a breach at its former analytics provider, Mixpanel, and it has severed ties with the vendor while reviewing others. The episode underscores supply‑chain risk from telemetry tools and the importance of limiting data shared with third‑party analytics.

Source: The Register


Critical auth bypass in ASUS AiCloud routers patched—update now

ASUS released new firmware addressing nine flaws, including CVE‑2025‑59366 (CVSS 9.2), a critical authentication bypass in routers with AiCloud enabled. Admins should prioritize patching affected models and disable unneeded cloud features to reduce exposure.

Source: Security Affairs


Teams guest access can sidestep Defender protections across tenants

Researchers warn that when users join external tenants as Teams guests, their protections are governed by the host environment—potentially bypassing Microsoft Defender for Office 365 safeguards from their home organization. Adversaries can abuse this cross‑tenant blind spot for phishing and malware delivery; tighten guest policies, apply Conditional Access, and monitor cross‑tenant activity.

Source: The Hacker News


Asahi confirms data on nearly 2M people stolen before ransomware attack

Asahi said hackers exfiltrated personal information on about 2 million customers and employees prior to deploying ransomware that disrupted its operations in Japan. The disclosure illustrates the continuing convergence of data theft and encryption, and the long recovery tail for large manufacturers.

Source: SecurityWeek


Thousands of secrets exposed on JSONFormatter and CodeBeautify

WatchTowr researchers found widespread leakage of credentials, API tokens, and private keys on developer formatting sites including JSONFormatter and CodeBeautify. Organizations should prohibit pasting sensitive payloads into public tools, use local/offline formatters, and enforce secret-scanning and key rotation.

Source: Security Affairs


New Mirai variant ‘ShadowV2’ probed IoT exploits during AWS outage

FortiGuard Labs observed a Mirai‑based botnet dubbed ShadowV2 targeting vulnerable IoT devices across multiple countries while October’s AWS disruption unfolded, then going quiet—likely a test run. The timing suggests actors are using major cloud outages to cloak live-fire trials and validate exploit chains.

Source: Security Affairs


You May Also Be Interested In...

Tomiris wreaks Havoc: New tools and techniques of the APT group

FCC sounds alarm after emergency tones turned into profanity-laced radio takeover

Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update

Cybersecurity — November 28, 2025 | Briefing24