THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft Teams guest access exposes a Defender blind spot across tenants

Researchers detail a cross-tenant gap that lets attackers sidestep Microsoft Defender for Office 365 protections when users join external Teams as guests. In guest mode, security controls are governed by the host tenant, not the user’s home organization, increasing risks from phishing, malware, and malicious links. Security teams should review guest policies, conditional access, and tenant restrictions to reduce exposure.

Source: The Hacker News


North Korean campaign floods npm with 197 malicious packages to deploy OtterCookie

Socket reports 197 new npm packages tied to the “Contagious Interview” operation, downloaded over 31,000 times and used to deliver an updated OtterCookie strain combining features from prior toolsets. The activity underscores ongoing software supply chain abuse targeting developers and build systems. Organizations should pin dependencies, monitor registries for typosquats, and block known indicators.

Source: The Hacker News


PostHog calls Shai-Hulud 2.0 npm worm its most impactful security incident

A flaw in the company’s CI/CD automation enabled malicious releases to slip into JavaScript SDKs, with attackers attempting to auto-exfiltrate developer credentials. PostHog labeled the compromise its “largest and most impactful” to date. Teams should audit dependency trees, rotate developer tokens, and enforce signing and provenance checks on packages.

Source: The Register


Legacy Python bootstrap scripts enable PyPI supply chain risk via domain takeovers

ReversingLabs found vulnerable patterns in zc.buildout bootstrap files used by multiple PyPI packages that can be abused if referenced domains lapse or are hijacked. Attackers could seize installation flows to run arbitrary code, highlighting long-tail technical debt in legacy tooling. Developers should audit bootstrap URLs, replace dead domains, and remove obsolete scripts.

Source: The Hacker News


Developers leaked thousands of secrets on online formatting sites

WatchTowr research shows users pasted passwords, API tokens, and private keys into web tools like JSONFormatter and CodeBeautify, exposing credentials for critical systems. Despite prior warnings, the practice remains widespread and easily searchable. Treat browser-based formatters as public: use offline tools, secrets scanners, and strict redaction policies.

Source: Security Affairs


Poems can jailbreak AI: adversarial verse defeats model guardrails at scale

New research shows that reframing harmful prompts as poetry dramatically increases jailbreak success across a wide range of LLMs, with some providers exceeding 90% attack success in tests. The findings suggest stylistic manipulation alone can bypass current safety training and evaluations. Builders of AI-enabled products should incorporate adversarial style testing into red-teaming and deploy robust content filtering.

Source: Wired


AI-powered cyber espionage campaign GTG-1002 shows how adversaries weaponize generative tools

SocRadar describes GTG-1002, an espionage operation observed from 2022–2025 that uses AI to enhance targeting, phishing, and operational agility. The campaign highlights how machine-generated content and automation can scale social engineering and reconnaissance. Defenders should harden identity layers, scrutinize AI-crafted lures, and expand detections for synthetic content signals.

Source: SOCRadar


You May Also Be Interested In...
California browser law could ripple nationally on privacy defaults
Asahi says ransomware attack may have exposed data of 1.5 million people
GrapheneOS quits OVHcloud over France’s privacy stance
Cybersecurity — November 29, 2025 | Briefing24