THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China-linked hackers exploiting Cisco Secure Email zero-day (CVE-2025-20393)

A suspected China-nexus group has been compromising Cisco Secure Email Gateway and Secure Email and Web Manager appliances since late November by abusing a critical input validation flaw to gain root command execution. Victims show backdoors and log-purging tools on devices, with compromises more likely on non-standard configurations; Cisco has warned of active exploitation while defenders await a patch and should harden or isolate exposed gear.

Source: SecurityWeek


Fortinet auth bypass bugs (CVE-2025-59718/59719) actively exploited to pull configs

Attackers are abusing critical SAML-related auth bypass flaws to log in as admin on FortiOS/FortiProxy/FortiSwitchManager and FortiWeb, immediately exfiltrating configuration files that can expose hashed credentials and detailed network policy. CISA added CVE-2025-59718 to the KEV catalog; patches are available and Fortinet urges disabling FortiCloud SSO admin login as an immediate mitigation while upgrading.

Source: Rapid7


SonicWall patches actively exploited SMA 1000 zero‑day used for chained RCE

SonicWall fixed a medium-severity local privilege escalation in SMA 1000 (CVE-2025-40602) that attackers have combined with another flaw (CVE-2025-23006) to achieve unauthenticated remote code execution with root. Organizations should apply the vendor hotfix immediately and review appliances for signs of post-exploitation.

Source: Help Net Security


GhostPoster campaign hid malware in Firefox extension icons to hijack traffic

Researchers uncovered 17 Firefox add-ons (50,000+ installs) that used steganography in icon files to smuggle JavaScript for affiliate hijacking, user tracking, security header removal, and CAPTCHA evasion. The extensions have been pulled, but users should audit and remove suspicious add-ons and rotate credentials where session tokens may have been exposed.

Source: SecurityWeek


1.8M Android devices conscripted into “Kimwolf” DDoS botnet

A massive botnet dubbed Kimwolf has infected Android TVs, set-top boxes, and tablets at scale, briefly outpacing Google in observed traffic volumes before launching large DDoS attacks. The malware, built with Android NDK, highlights the ongoing risk from low-cost, poorly maintained Android-based IoT gear—defenders should segment, patch, and monitor for atypical outbound traffic from consumer devices.

Source: The Hacker News


China-aligned APT abuses Windows Group Policy for stealthy domain-wide malware deployment

ESET reports a previously undocumented espionage group (“LongNosedGoblin”) targeting governments in Southeast Asia and Japan, leveraging Active Directory Group Policy to distribute payloads and move laterally. Because GPO enjoys inherent trust in Windows environments, defenders should audit GPO changes, enforce admin tiering, and monitor SYSVOL for unauthorized script or policy modifications.

Source: Help Net Security


France probes suspected foreign cyber plot after remote‑control malware found on passenger ferry

France’s counterespionage agency is investigating “foreign interference” following discovery of remote-control malware on an international ferry, raising alarms over maritime OT/IT security. The incident underscores growing risks to transportation systems and the need for strict network segmentation, application allowlisting on bridge/engine networks, and continuous anomaly detection in operational environments.

Source: SecurityWeek


You May Also Be Interested In...

Cybersecurity — December 18, 2025 | Briefing24