THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China-linked APT exploits Cisco Secure Email Gateway zero‑day

Cisco disclosed CVE-2025-20393, a critical zero‑day in Secure Email Gateway and Secure Email & Web Manager that’s being actively exploited by a China-linked group (tracked as UAT‑9686). The campaign began December 10 and targets management interfaces to gain footholds in enterprise mail infrastructure. Urgently apply Cisco guidance, restrict admin access to trusted networks, and monitor for anomalous admin activity and IOCs.

Source: Security Affairs


WatchGuard Firebox flaw under active attack enables unauthenticated RCE

WatchGuard patched CVE-2025-14733 (CVSS 9.3), an out‑of‑bounds write in the Fireware OS ike daemon that attackers are exploiting in the wild for remote code execution without authentication. Organizations should update immediately, ensure Firebox management and VPN services aren’t exposed to the internet, and review VPN logs for suspicious IKE activity.

Source: TheHackerNews


HPE OneView gets ‘perfect 10’ critical RCE—patch infrastructure management now

HPE warned of a maximum‑severity remote code execution bug in OneView, its trusted infrastructure management platform, that could allow unauthenticated attackers to run code without even hitting a login prompt. Because OneView orchestrates servers, storage, and networking, compromise could cascade across data center assets—patch urgently and restrict access to management planes.

Source: The Register


UEFI flaw enables early‑boot DMA attacks across ASUS, ASRock, GIGABYTE, MSI boards

Researchers detailed a new UEFI vulnerability affecting select motherboards that undermines IOMMU protections and enables pre‑boot DMA attacks, opening the door to memory compromise and stealthy code injection. Organizations should apply vendor firmware updates, enable DMA protections in BIOS, and verify secure/Measured Boot policies in addition to OS‑level controls.

Source: TheHackerNews


Denmark blames Russia for cyberattacks on water utility and pre‑election websites

Danish intelligence attributed destructive attacks on a water utility and election‑period DDoS campaigns to Russia, calling them part of a wider hybrid‑war effort to sow instability. The episode underscores the rising risk to European critical infrastructure—utilities should harden OT/IT boundaries, validate incident response playbooks, and deploy DDoS mitigation for public services.

Source: Security Week


Russia‑linked actors hijack Microsoft 365 via OAuth device code phishing

Proofpoint tracked a campaign since September abusing Microsoft’s device code authentication flow to steal credentials and take over M365 accounts. The technique bypasses typical MFA prompts and leverages compromised sender accounts; defenders should consider disabling device code flow where not needed, enforce Conditional Access with strong session controls, and monitor consent/token anomalies.

Source: TheHackerNews


Cybercriminals ramp up insider recruitment at banks, telecoms, and tech

Check Point reports a surge in darknet solicitations targeting employees, offering $3,000–$15,000 for access, data, or facilitating intrusions—especially at crypto exchanges, banks, and cloud providers. Programs to deter insider risk should include targeted awareness, least‑privilege and just‑in‑time access, anomaly detection on privileged actions, and proactive monitoring of underground forums.

Source: Checkpoint Blog


You May Also Be Interested In...

New Clop ransomware campaign sets sights on Gladinet CentreStack servers

DOJ charges gang for ATM hacks using Ploutus malware

CISA warns ASUS Live Update backdoor is still exploitable, seven years on

Cybersecurity — December 20, 2025 | Briefing24