THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China-linked APTs exploit critical zero-day in Cisco Secure Email appliances

Cisco confirmed active exploitation of CVE-2025-20393 (CVSS 10.0) in Secure Email Gateway and Secure Email/Web Manager, enabling attackers to execute commands with root privileges. The activity, attributed to China-linked actors, underscores the risk of management-plane exposure; organizations should apply Cisco’s latest advisories, restrict management interfaces, and hunt for post-exploitation indicators immediately.

Source: SecurityWeek


HPE OneView CVSS 10.0 unauthenticated RCE threatens data center control planes

HPE patched CVE-2025-37164, a maximum-severity flaw allowing unauthenticated remote code execution on OneView versions prior to 11.0. Rapid7’s analysis indicates the hotfix blocks a publicly reachable endpoint (/rest/id-pools/executeCommand), reinforcing urgency to upgrade or hotfix and to treat OneView as an assumed-breach target given its centralized control over servers and firmware.

Source: Rapid7


UEFI flaw enables early-boot DMA attacks on major motherboard vendors

Researchers disclosed a vulnerability affecting select ASRock, Asus, Gigabyte, and MSI motherboards that permits early-boot DMA attacks, bypassing IOMMU protections before the OS and many security tools are active. Organizations should apply vendor firmware updates as released, enforce Secure Boot and kernel DMA protection, and limit untrusted peripherals in sensitive environments.

Source: SecurityWeek


Microsoft 365 device code phishing bypasses MFA via OAuth abuse

Proofpoint observed attackers abusing Microsoft’s OAuth 2.0 device authorization grant to trick users into entering device codes that grant access tokens, enabling account compromise without stealing passwords. To mitigate, disable the device code flow where unnecessary, tighten Conditional Access, monitor and revoke suspicious OAuth grants, and require reconsent for risky applications.

Source: Help Net Security


“ClickFix” copy-paste attacks deliver StealC infostealer and Qilin ransomware

Sophos warns that fake “I am not a robot” human-verification pages coax users into copying and running malicious scripts, leading to StealC and later-stage ransomware. Defenses include browser and email hardening, disabling PowerShell/Script execution for standard users, application control, and user training focused on copy-paste–based social engineering.

Source: Naked Security (Sophos)


LongNosedGoblin APT abuses Group Policy to deploy espionage tools in Asia

ESET uncovered a China-aligned group, LongNosedGoblin, leveraging Windows Group Policy to distribute malware across government networks in Southeast Asia and Japan for long-term surveillance. Admins should audit GPO changes, restrict who can edit GPOs, enable change-control and signing where possible, and increase domain controller telemetry to catch policy-based lateral movement.

Source: ESET


North Korea tops crypto theft again: $2B stolen in 2025 as fake IT worker schemes multiply

Chainalysis data shows DPRK-linked groups stole roughly $2.02 billion in cryptocurrency this year, increasingly targeting large-scale services for maximum payout. Amazon separately blocked 1,800 suspected North Korean “IT worker” accounts, highlighting dual threats of direct theft and workforce infiltration; crypto and tech firms should tighten vendor onboarding and workforce verification controls.

Source: SecurityWeek


You May Also Be Interested In...

SonicWall Patches Exploited SMA 1000 Zero-Day

NIST releases draft cybersecurity framework for AI adoption

The ghosts of WhatsApp: How GhostPairing hijacks accounts

Cybersecurity — December 19, 2025 | Briefing24