THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
React2Shell RCE goes from disclosure to active exploitation; CISA adds it to KEV

A maximum-severity flaw in React Server Components (CVE-2025-55182, “React2Shell”) is being actively exploited within hours of disclosure. CISA has added the bug to its Known Exploited Vulnerabilities catalog, compelling rapid patching. Organizations should upgrade to React 19.0.1/19.1.2/19.2.1 and the latest affected framework versions, and deploy WAF rules and enhanced logging around suspicious Flight protocol requests.

Source: The Hacker News


CISA: China-linked ‘BRICKSTORM’ backdoor enables long-term persistence in US networks

US organizations are warned that Warp Panda has used BRICKSTORM, along with Junction and GuestConduit, to persist in VMware vSphere and Windows environments. The campaign abuses vCenter and edge devices, emphasizing the need to audit hypervisor admin paths, harden management interfaces, and hunt for stealthy persistence mechanisms.

Source: SecurityWeek


Leaks show Intellexa burning zero-days to keep Predator spyware effective

New reporting details how Intellexa sustained Predator spyware operations by acquiring and deploying high-value zero-days, allowing infections to bypass platform protections. The revelations highlight the ongoing commercialization of exploitation against civil society and government targets, underscoring the need for rapid patching and device hardening.

Source: Malwarebytes Labs


Record 29 Tbps DDoS attack mitigated as Aisuru botnet peaks at 14.1 Bpps

Cloudflare reports the largest recorded DDoS to date, with Aisuru surging to 29 Tbps and 14.1 billion packets per second. The event underscores escalating volumetric attacks and the need for resilient anycast architectures, automated mitigation pipelines, and L7 rate limiting and anomaly detection.

Source: SecurityWeek


Apache Tika hit by critical XXE (CVE-2025-66516) impacting core, PDF, and parser modules

A CVSS 10.0 XXE flaw in Apache Tika could enable data exfiltration, SSRF, or worse through crafted files such as PDFs with malicious XFA. Because Tika often sits in ingestion pipelines for search, e‑discovery, and analytics, organizations should patch immediately, sandbox parsers, and review content-processing exposure.

Source: The Hacker News


JPCERT/CC: Array Networks AG gateway flaw under widespread exploitation since August

A command injection bug affecting Array Networks AG Series DesktopDirect, patched in May 2025, has been actively exploited since August. Unpatched edge gateways risk remote command execution and internal pivoting—prioritize updates, rotate credentials, and review logs for post-exploitation activity.

Source: Security Affairs


Trump’s national security strategy tasks spy agencies with watching global supply chains

The new strategy prioritizes the Western Hemisphere and calls for deeper cyber collaboration with regional partners and the private sector. Expanded intelligence focus on supply chains signals more public‑private information sharing and potential impacts on procurement security baselines.

Source: Nextgov/FCW


You May Also Be Interested In...

Novel clickjacking attack relies on CSS and SVG

AutoIT3 Compiled Scripts Dropping Shellcodes

North Korean hacker infected by malware, exposing ties to $1.4B Bybit heist

Cybersecurity — December 6, 2025 | Briefing24