THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Android’s December patch fixes 107 flaws, including two exploited zero-days

Google’s latest Android security update addresses 107 vulnerabilities across Framework, System, kernel and vendor components. The company warns two of the flaws have been exploited in limited, targeted attacks, raising urgency for enterprises to push December updates and OEM patches quickly across fleets.

Source: SecurityWeek


Data breach at South Korea’s “Amazon” Coupang may impact 65% of the population

Online retail giant Coupang apologized after a massive breach prompted an emergency government meeting in Seoul. Early estimates suggest up to 33.7 million accounts could be affected, underscoring third-party and data governance risks at national scale while the investigation continues.

Source: Recorded Future News (The Record)


Police dismantle Cryptomixer, seize $29M in Bitcoin used to launder cybercrime proceeds

European law enforcement took down the Cryptomixer service under Operation Olympia, disrupting a laundering hub tied to ransomware and other illicit activity. Authorities seized servers and funds, signaling growing regulatory pressure on crypto obfuscation services used to cash out attacks.

Source: SecurityWeek


New Albiriox Android MaaS enables full on-device fraud and remote control

Researchers detail Albiriox, a malware-as-a-service banking trojan offered for roughly $720/month, that lets criminals take real-time control of compromised phones. With a hardcoded target list of 400+ financial apps and advanced screen manipulation, it dramatically elevates mobile fraud risk.

Source: SecurityWeek


CISA adds ScadaBR flaw to KEV after hacktivist ICS attack

CISA added CVE-2021-26829, a cross-site scripting bug in ScadaBR, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. OT/ICS operators should prioritize patching and restrict internet exposure of HMIs and consoles to reduce risk of lateral movement and process disruption.

Source: SecurityWeek


Seven-year browser extension campaign backdoored 4.3M Chrome/Edge users

Investigators uncovered a long-running operation that turned popular browser extensions into spyware and backdoors, exfiltrating data to servers in China. Some malicious add-ons reportedly remain in the Microsoft Edge store, making extension inventory and allowlisting a priority control.

Source: The Register


India orders undeletable government app on all new smartphones within 90 days

New directives require handset makers to preinstall the Sanchar Saathi app—meant to combat telecom fraud—on every device sold in India, with removal blocked. The mandate raises significant privacy, enterprise policy, and supply chain governance questions for vendors and organizations operating in the country.

Source: The Register


You May Also Be Interested In...

MuddyWater cyber campaign adds new backdoors in latest wave of attacks

AI models block 87% of single attacks, but just 8% when attackers persist

Accepting Microsoft Teams guest invitations could pose a security risk

Cybersecurity — December 2, 2025 | Briefing24