THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical React Server Components flaw allows unauthenticated RCE

A maximum‑severity bug (CVE-2025-55182) in React Server Components can enable unauthenticated remote code execution in affected apps, including popular frameworks like Next.js. Researchers warn in‑the‑wild exploitation is likely; however, impact is limited to instances using a newer RSC feature. Organizations should patch React and framework updates immediately, review server function exposure, and rotate secrets possibly exposed via server actions.

Source: SecurityWeek


Cloudflare blocks record 29.7 Tbps DDoS from AISURU “botnet‑for‑hire”

Cloudflare mitigated the largest recorded DDoS attack at 29.7 Tbps, traced to the AISURU botnet that has fueled a series of hyper‑volumetric attacks. The 69‑second blast underscores growing access to turnkey DDoS services and the need for always‑on network‑layer protection, automatic traffic engineering, and upstream coordination with providers.

Source: The Hacker News


Shai Hulud 2.0 npm worm adds wiper capabilities; mass secret leakage follows

Kaspersky reports a new Shai Hulud 2.0 variant propagating via npm with added “wiper” functionality alongside its supply‑chain worming behavior. Follow‑on reporting shows hundreds of thousands of unique secrets exposed from compromised repos, highlighting the urgency of tightening package publishing controls, pinning dependencies, and enforcing CI/CD signing and secret scanning.

Source: Securelist (Kaspersky)


Oracle E‑Business Suite campaign hits universities; more victims expected

The University of Pennsylvania and the University of Phoenix disclosed data breaches tied to a broader campaign exploiting Oracle E‑Business Suite, with threat actors exfiltrating sensitive data at scale. The incidents reinforce third‑party/ERP risk: EBS customers should apply vendor fixes, monitor for anomalous ERP access, and validate segmentation and egress controls.

Source: SecurityWeek


Mercenary spyware vendor Intellexa continues prolific zero‑day use despite sanctions

Google’s Threat Intelligence Group details Intellexa’s sustained zero‑day exploitation (15 unique 0‑days since 2021) and novel delivery tactics, including malicious ads for fingerprinting and exploit delivery. Google issued government‑backed attack warnings to hundreds of targets and added indicators to Safe Browsing; at‑risk orgs should harden mobile fleets, accelerate patching, and consider high‑risk protections like iOS Lockdown Mode.

Source: Google Cloud Threat Intelligence


Sprawling Indonesian gambling network moonlights as hidden C2/anonymity service

Researchers uncovered a 14‑year‑old infrastructure spanning 328,000+ domains—including tens of thousands of hacked sites and hijacked subdomains, some on government domains—used for illegal gambling, malware delivery, and likely command‑and‑control and anonymity services. The scale and longevity suggest durable adversary infrastructure; defenders should monitor for traffic to associated domains, enforce strict subdomain controls, and leverage domain takedown where possible.

Source: Help Net Security


Actively exploited Fortinet FortiWeb bugs affect older, unsupported versions too

Recent exploitation of FortiWeb OS command injection (CVE-2025-58034) and path traversal (CVE-2025-64446) extends beyond documented 7.x/8.x releases to older 6.x instances, broadening exposure. Fortinet customers should urgently patch supported versions, isolate or retire unsupported appliances, and audit for indicators of compromise on internet‑exposed WAFs.

Source: SC Media


You May Also Be Interested In...

Microsoft silently mitigated an LNK flaw exploited since 2017

Android Framework bugs added to CISA’s KEV list amid active attacks

CIS, Astrix, and Cequence partner on new AI security guidance

Cybersecurity — December 4, 2025 | Briefing24