THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Fortinet firewalls under active attack via critical SSO auth bypasses

Attackers are exploiting two critical authentication bypass flaws (CVE-2025-59718, CVE-2025-59719) in FortiGate appliances just days after disclosure, enabling malicious SAML SSO logins without valid credentials. CISA has added at least one to its Known Exploited Vulnerabilities catalog. Urgently apply Fortinet patches, audit SSO logs for anomalous sign-ins, rotate admin/API credentials, and review downstream trust with IdPs.

Source: SecurityWeek


GRU shifts to misconfigurations to target critical infrastructure, Amazon warns

Russian state-backed operators are increasingly abusing misconfigured network edge and cloud-hosted devices rather than burning zero-days, with years-long activity hitting energy and other critical sectors. The pivot lowers attacker cost and defender visibility, emphasizing hardening, external attack surface management, and configuration drift control across OT/IT boundaries.

Source: The Record by Recorded Future


China-linked “Ink Dragon” expands into Europe, uses victims as relay nodes

Check Point says the Ink Dragon espionage group (aka Earth Alux/REF7707) moved from Asia and South America into European government networks, co-opting compromised servers as covert relays. A new FINALDRAFT variant blends into Microsoft cloud activity to persist, and overlapping exploitation with other actors shows how single perimeter flaws can draw multiple APTs.

Source: Check Point Research


Study: Most parked domains now funnel users to scams and malware

Direct-navigation “parked” domains—expired holdings and typosquats—are increasingly weaponized to auto-redirect visitors into scam pages and malicious downloads. The shift turns casual URL guessing into a high-risk behavior; organizations should step up domain monitoring/defensive registrations and users should favor bookmarks or search over typed guesses.

Source: KrebsOnSecurity


GhostPoster: 17 Firefox add-ons hid malware in icon files, 50,000+ installs

Researchers uncovered a campaign that embedded malicious JavaScript inside extension logo assets across 17 Mozilla add-ons, hijacking affiliate links, injecting iframes, stripping security headers, and committing ad/click fraud. The extensions have been pulled, but users should review installed add-ons, remove unknown publishers, and rotate credentials if affected.

Source: The Hacker News


AWS: Ongoing crypto-mining campaign abusing compromised IAM credentials

GuardDuty detected an operation starting Nov. 2 targeting Amazon EC2/ECS via stolen IAM creds, adding novel persistence and evasion tactics to sustain illicit mining. AWS urges credential rotation, least-privilege IAM, service control policies, and continuous monitoring with GuardDuty/CloudTrail to spot anomalous resource launches and network patterns.

Source: AWS Security Blog


SoundCloud breach exposes emails for 20% of users amid follow-on DoS

SoundCloud confirmed a breach in which attackers accessed user email addresses for roughly one-fifth of its user base, warning of likely phishing waves. The platform also weathered denial-of-service attacks and made temporary configuration changes that affected some VPN traffic while mitigation was underway.

Source: SecurityWeek


You May Also Be Interested In...

Microsoft will finally kill RC4 for admin auth after decades of abuse

Rapid7 unwraps new SantaStealer malware-as-a-service

Popular Chrome extension caught harvesting AI chatbot prompts

Cybersecurity — December 17, 2025 | Briefing24