THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
React2Shell exploitation surges as attackers target CVE-2025-55182

Threat activity against the critical Meta React Server Components flaw (CVE-2025-55182) is ramping up, with more actors attempting remote code execution in the wild. With pre-auth exploit paths reported and CISA adding the bug to its Known Exploited Vulnerabilities list, teams should prioritize patching and tighten exposure of React applications. Monitor for unusual process launches and server-side template activity associated with React SSR and RSC components.

Source: SecurityWeek


Critical Apache Tika flaw enables XXE via malicious PDFs

A newly disclosed Apache Tika vulnerability allows XML External Entity (XXE) injection through crafted XFA content embedded in PDF files. Environments that automatically parse user-supplied documents (email gateways, content pipelines, e-discovery, and search/indexing) are particularly exposed. Patch Tika promptly and review document ingestion controls to prevent external entity resolution and outbound calls during parsing.

Source: SecurityWeek


Gartner: Block AI browsers for now as agentic risks mount

Gartner advises organizations to block AI/agentic browsers “for the foreseeable future,” warning that autonomous actions, tool integrations, and user misuse amplify data loss, compliance, and social engineering risks. Analysts also caution that employees could use agents to subvert security training, while attackers can automate far more damaging actions. Security leaders should enforce policy controls, restrict agent tool access, and evaluate agentic use cases in sandboxes first.

Source: The Register


NVIDIA research maps how agentic AI fails under attack

NVIDIA and Lakera AI unveiled a security framework that exposes failure modes in agentic AI systems as models interact with tools, data sources, and memory. The work shows that risks emerge from the orchestration layer itself, not just the base model, and can be measured inside real workflows. The guidance helps enterprises test and harden agentic pipelines before broad deployment.

Source: Help Net Security


MuddyWater deploys UDPGangster backdoor in targeted regional campaign

Iran-linked MuddyWater is using a new backdoor dubbed UDPGangster that relies on UDP for command-and-control to remotely operate compromised hosts. The campaign hits targets in Turkey, Israel, and Azerbaijan, underscoring continued regional espionage activity. Network defenders should scrutinize unusual UDP egress patterns and harden endpoint telemetry and allowlists.

Source: The Hacker News


MFA-bypassing phishing hits 18 US universities using Evilginx

Infoblox reports a months-long phishing spree that used the Evilginx kit to proxy login flows and steal session tokens from 18 U.S. universities, bypassing MFA. Attackers cycled through 70+ domains from April to November 2025, underscoring how higher education’s decentralized identity landscape remains a prime target. Institutions should move to phishing-resistant MFA (FIDO2/WebAuthn), implement domain and brand monitoring, and enforce conditional access.

Source: HackRead


Barts Health seeks court order after Clop steals NHS data via Oracle EBS

London’s Barts Health NHS Trust confirmed patient and staff data was stolen during Clop’s mass exploitation of Oracle E‑Business Suite, and is seeking a High Court injunction to prevent publication. The case highlights the downstream impact of ERP zero-days and the limited protection legal action offers once data is exfiltrated. Organizations should accelerate patching and segmentation for business-critical apps and prepare for extortion attempts even post-containment.

Source: The Register


You May Also Be Interested In...

Prompt injection is not SQL injection (it may be worse)

CISA adds Meta React Server Components flaw to the Known Exploited Vulnerabilities catalog

Android Malware FvncBot, SeedSnatcher, and ClayRat gain stronger data theft features

Cybersecurity — December 8, 2025 | Briefing24