THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Apple rushes fixes for two WebKit zero‑days under active exploitation

Apple shipped emergency updates for iOS, iPadOS, macOS, and Safari to patch CVE-2025-14174 and CVE-2025-43529, WebKit flaws exploited in “extremely sophisticated” attacks. One bug traces back to an ANGLE issue first fixed in Chrome, and both can enable code execution via malicious web content. Patch immediately and consider updating Safari separately on macOS systems that don’t auto‑update the browser.

Source: Help Net Security


React2Shell (CVE-2025-55182) mass exploitation expands to nation‑state actors

Google reports at least five China‑linked clusters—and some Iranian activity—actively exploiting the React2Shell pre‑auth RCE in React Server Components/Next.js. With a CVSS 10.0 and widespread use of affected stacks, attackers are landing initial access quickly; organizations should patch frameworks, comb logs for web shells and anomalous child processes, and review WAF rules for Flight protocol abuse.

Source: SecurityWeek


Fortinet FortiGate authentication bypasses now under active attack

Threat actors began exploiting CVE-2025-59718 and CVE-2025-59719 to perform malicious SSO logins on FortiGate appliances, bypassing authentication in certain configurations. Fortinet customers should patch without delay, audit SAML SSO settings and authentication logs, and consider temporary controls (IP restrictions, MFA enforcement, disable external SSO) where patching lags.

Source: SecurityWeek


Atlassian ships fixes for max‑severity Apache Tika XXE (CVSS 10) across product line

Atlassian released updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira to remediate a critical Apache Tika XXE flaw (CVE-2025-66516). Successful exploitation can enable SSRF, sensitive file exposure, or code execution in some parsing paths—teams should update bundled Tika components and ensure content parsing occurs in sandboxed, least‑privileged contexts.

Source: SecurityWeek


AWS ties years‑long critical‑infrastructure intrusions to Russia’s GRU

Amazon Threat Intelligence details a GRU campaign pivoting to misconfigured edge devices as primary initial access, reducing reliance on 1‑day/0‑day exploits. The operation targeted energy, telecom, and tech providers to gain persistent, credentialed access. Defenders should harden and inventory edge devices, remove default creds, restrict management exposure, and continuously monitor for anomalous device‑to‑cloud traffic.

Source: AWS Security Blog


Nearly 20 million impacted in Prosper, 700Credit data breaches

Two finance sector incidents—at fintech Prosper Marketplace and auto‑services provider 700Credit—exposed sensitive PII for close to 20 million people, including SSNs and dates of birth. The events underscore third‑party risk in lending and dealership ecosystems; organizations should revisit vendor due diligence, data minimization, and rapid notification playbooks.

Source: The Record by Recorded Future


New MaaS info‑stealer “SantaStealer” targets credentials and wallets with in‑memory modules

Rapid7 analyzed leaked samples of “SantaStealer,” a malware‑as‑a‑service infostealer rebranded from “BluelineStealer,” featuring in‑memory collection, Chrome ABE credential decryption via a bundled injector, and exfiltration in 10 MB chunks over plaintext HTTP. Despite operator claims of stealth, current builds are noisy—defenders should hunt for clear‑text /upload posts to hard‑coded C2s and apply IOCs provided by researchers.

Source: Rapid7


You May Also Be Interested In...

PayPal closes loophole that let scammers send real emails with fake purchase notices

Cloudflare’s 2025 Internet review: attack clusters, outages, and traffic shifts

SoundCloud confirms breach affecting 20% of users; phishing risk rises

Cybersecurity — December 16, 2025 | Briefing24