THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA flags ScadaBR XSS flaw after hacktivist ICS attack

CISA added CVE-2021-26829, a cross-site scripting vulnerability in OpenPLC ScadaBR for Windows and Linux, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation tied to a hacktivist attack on industrial control systems. OT operators should audit any external exposure of ScadaBR, apply available fixes, and monitor for suspicious web interactions targeting system_settings.shtm.

Source: SecurityWeek


APT “Tomiris” pivots to Telegram/Discord-based implants for stealthy C2

Researchers report Tomiris is targeting foreign ministries and intergovernmental bodies with implants that use public services like Telegram and Discord for command-and-control. The shift reduces infrastructure risk and blends malicious traffic with normal cloud service use, complicating detection and takedown.

Source: The Hacker News


New Albiriox Android MaaS enables on‑device fraud against 400+ apps

“Albiriox” is a malware-as-a-service for Android offering screen control, real-time device interaction, and on‑device fraud, with a hard-coded target list spanning 400+ banking, fintech, payment, and crypto apps. Its capabilities can bypass out-of-band checks by operating on compromised devices, elevating risk for mobile financial services.

Source: The Hacker News


Swiss data watchdogs urge public sector to avoid M365 and SaaS lacking end‑to‑end encryption

Switzerland’s Conference of Data Protection Officers (Privatim) issued a resolution advising public bodies to steer clear of hyperscale clouds and SaaS—including Microsoft 365—because they lack end‑to‑end encryption and raise sovereignty and confidentiality concerns. The guidance could reshape procurement, pushing requirements for stronger encryption, data residency, and contractual control.

Source: The Register


Coupang breach exposes data of 33 million users in South Korea

E‑commerce giant Coupang disclosed a massive breach affecting 33 million customers, the country’s largest data leak in a decade. Authorities are probing a suspected insider angle involving a former employee in China, as investigators assess the scope of exposed personal information.

Source: CyberNews


Ransomware loves weekends: identity changes and org shake-ups heighten risk

Over half of ransomware incidents in the past year struck during weekends or holidays, according to Semperis, when staffing is thin and detection lags. Notably, 60% of incidents followed M&A, restructuring, or similar changes, with identity system shifts cited as a common trigger—underscoring the need for change‑control, MFA, and continuous monitoring around high‑risk periods.

Source: Help Net Security


Hackers leak sensitive Sorbonne Université staff data

A threat actor on the dark web is distributing files allegedly stolen from Sorbonne Université, including banking details, salary records, and social security numbers. If verified, the exposure poses significant risks of fraud and identity theft for staff while the university investigates.

Source: CyberNews


You May Also Be Interested In...

Offensive cyber power is spreading fast and changing global security

Singapore orders Apple and Google to curb fake government texts

Over 2,000 fake shopping sites spotted ahead of Cyber Monday

Cybersecurity — December 1, 2025 | Briefing24