THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft’s December fixes include exploited Windows zero-day, PowerShell hardening, and no‑click Office RCEs

Microsoft shipped broad security updates addressing multiple high‑risk flaws, including an exploited Windows Cloud Files Mini Filter elevation-of-privilege (CVE-2025-62221) and a PowerShell zero‑day (CVE-2025-54100) that allowed code execution before Mark‑of‑the‑Web checks. Two Office remote code execution bugs are also notable because Outlook/Explorer Preview Pane can trigger them without user clicks. Prioritize endpoints running PowerShell 5.1 and Office, and review scripts that rely on Invoke‑WebRequest after Microsoft’s default-behavior change.

Source: Rapid7


React2Shell (CVE-2025-55182) under heavy exploitation, dropping miners and new malware

Attackers are mass‑exploiting the maximum‑severity React Server Components flaw to gain remote code execution in Node.js/Next.js apps. Campaigns observed deploy crypto miners alongside previously undocumented malware families and backdoors, underscoring the risk to internet‑exposed web stacks. Patch immediately, rotate credentials, and hunt for persistence on affected hosts.

Source: The Hacker News


Zero‑click “GeminiJack” bug in Google’s Gemini Enterprise could have exfiltrated corporate Gmail, Docs, and Calendar

Google fixed a flaw that enabled indirect prompt‑injection via crafted emails, calendar invites, or documents, allowing silent data exfiltration from Gemini‑connected enterprise apps. The case highlights the expanding attack surface as GenAI assistants gain privileged access to business data. Review Gemini configuration, apply updates, and enforce DLP/least‑privilege controls around AI integrations.

Source: SecurityWeek


Unpatched Gogs zero‑day (CVE-2025-8110) actively exploited; 700+ self‑hosted Git instances compromised

A file‑overwrite flaw in Gogs’ file update API enables remote code execution, and attackers are already abusing it at scale. With no upstream fix available yet, owners of internet‑exposed instances are urged to restrict access, audit for unauthorized users/files, and deploy compensating controls (WAF/reverse proxy) until patched.

Source: The Hacker News


Fortinet patches critical auth bypass in FortiOS, FortiWeb, FortiProxy, FortiSwitchManager

Two improper signature‑verification issues (CVE‑2025‑59718/59719, CVSS 9.1) allow authentication bypass when FortiCloud SSO is enabled, exposing network edges and management planes to takeover. Organizations should patch urgently, disable affected SSO paths if updates aren’t possible, and scrutinize admin logs for anomalous access.

Source: SecurityWeek


Chrome emergency update: Google fixes an in‑the‑wild high‑severity zero‑day

Google released a security update for Chrome to address a high‑severity flaw that is already being exploited; technical details and CVE are being withheld pending patch adoption. Enterprises should fast‑track browser updates and enforce auto‑updates/restarts to minimize exposure windows.

Source: SecurityWeek


HTTPS ecosystem tightening: CA/Browser Forum to sunset 11 email/phone‑based domain validation methods

Google’s Chrome Root Program and the CA/Browser Forum approved ballots to retire legacy Domain Control Validation methods (e.g., WHOIS/email/phone and reverse lookups) in favor of automated, cryptographically verifiable approaches like ACME/DNS. Phased deprecation through March 2028 aims to reduce mis‑issuance risks and improve certificate lifecycle agility across the web.

Source: Google Online Security Blog


You May Also Be Interested In...

DOJ, CISA warn of Russia‑linked attacks targeting critical infrastructure

WinRAR path traversal (CVE‑2025‑6218) added to CISA KEV amid active exploitation

WordPress auto‑login backdoor masquerades as a JavaScript data file

Cybersecurity — December 11, 2025 | Briefing24