THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Android update patches two exploited Framework flaws—update now

Google’s December Android bulletin includes fixes for two high‑severity Android Framework bugs (CVE-2025-48633 and CVE-2025-48572) that may be under limited, targeted exploitation. Organizations should prioritize rapid patching, as Framework issues can be abused by apps to access sensitive data or escalate privileges, and several vendors will release device-specific updates over the coming days.

Source: Help Net Security


“Sleeper” Chrome/Edge extensions turned into spyware on 4 million devices

After years of benign behavior, five popular browser extensions with millions of installs abruptly began harvesting data and abusing permissions. The campaign illustrates the long-tail risk of extension supply chains—enterprises should audit installed add-ons, remove untrusted extensions, invalidate browser sessions, and monitor for unusual cookie and API access.

Source: MalwareBytes Blog


New Symbiote/BPFdoor variants hide via eBPF filters and covert IPv6/UDP C2

FortiGuard Labs reports Linux threats Symbiote and BPFdoor now leverage eBPF filters to boost stealth, adding IPv6 support, UDP channels, and dynamic port hopping for covert command-and-control. Defenders should hunt for unauthorized eBPF programs, kernel tampering, and anomalous IPv6/UDP traffic patterns, and tighten eBPF loading policies.

Source: Fortinet


MuddyWater targets Israeli and Egyptian infrastructure with new backdoor “MuddyViper”

ESET tracks Iran-aligned MuddyWater refining its playbook against critical sectors in Israel and one confirmed victim in Egypt, deploying custom loaders and a new MuddyViper backdoor. The campaign relies on phishing-led initial access and predictable post-exploitation steps, giving defenders concrete IOCs and TTPs to detect lateral movement earlier.

Source: ESET Blog


Global crackdowns squeeze cybercrime networks, crypto laundering pipelines

Law enforcement in 2025 intensified cross-border operations against criminal infrastructure, from takedowns of fraud rings to record asset seizures—including roughly $15 billion in Bitcoin tied to the Prince Group’s forced-labor scam centers. These moves disrupt monetization routes and raise recovery odds for victims, while signaling increased scrutiny of crypto mixers and mule networks.

Source: Help Net Security


Coupang breach exposes data of 33.7 million customers over five months

South Korea’s e‑commerce giant confirmed that names, addresses, email addresses, and phone numbers were stolen during a prolonged intrusion. The scale and dwell time underscore supply chain and fraud risks for downstream merchants; affected organizations should expect phishing waves and consider adding targeted monitoring and takedown support.

Source: Security Week


India orders messaging apps to require active SIM linkage to curb fraud

New directives from India’s DoT require WhatsApp, Telegram, Signal, and others to work only with mobile numbers tied to active SIMs, aiming to reduce scams and misuse. The policy raises privacy and anonymity concerns and will force platform changes to onboarding, account recovery, and lawful access processes for users in India.

Source: TheHackerNews


You May Also Be Interested In...

Chrome 143 Patches High-Severity Vulnerabilities

DOJ takes down Myanmar scam center website spoofing TickMill trading platform

GlassWorm returns with 24 malicious extensions impersonating popular developer tools

Cybersecurity — December 3, 2025 | Briefing24