THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA adds critical WatchGuard Fireware OS flaw to Known Exploited Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-14733, a critical out-of-bounds write in WatchGuard Fireware/Firebox OS (CVSS 9.3), to its Known Exploited Vulnerabilities catalog, signaling in-the-wild exploitation. Organizations running WatchGuard appliances should prioritize patches or mitigations and audit exposure of management interfaces and remote access.

Source: Security Affairs


Massive Android botnet “Kimwolf” infects 1.8M+ devices, issues 1.7B DDoS commands

Researchers at XLab uncovered Kimwolf, a new Android botnet linked to the Aisuru operation that has compromised more than 1.8 million devices and launched over 1.7 billion DDoS commands since late October. The campaign is expanding its command-and-control domains and weaponizing consumer phones at scale; defenders should curb side-loading, deploy mobile EDR, and monitor for abnormal outbound traffic.

Source: Security Affairs


NIST grappled with NTP disruption after outage led to atomic clock drift

Following a power outage near Boulder, Colorado, a NIST staffer attempted to disable backup generators supporting portions of its Network Time Protocol infrastructure after timekeeping errors emerged. The incident spotlights the fragility and systemic risk of time services that underpin TLS, Kerberos, logging, and financial systems; organizations should diversify time sources and alert on drift.

Source: The Register


U.S. indicts 54 in nationwide ATM jackpotting scheme using Ploutus malware

The Department of Justice charged 54 individuals tied to a multi-million-dollar ATM jackpotting conspiracy that used Ploutus malware to force machines to dispense cash. Authorities link suspects to the Tren de Aragua group; ATM operators should harden software updates, segment networks, and monitor for jackpotting indicators.

Source: TheHackerNews


Iran’s Infy (Prince of Persia) APT resurfaces with new malware activity

SafeBreach researchers report renewed operations from the Iranian-linked Infy/Prince of Persia group after years of quiet, with activity broader than previously understood. The actor, historically active against targets in Sweden, the Netherlands, and Turkey, is using updated tooling and infrastructure; security teams should refresh detections and block newly published IOCs.

Source: TheHackerNews


Dark web “DIG AI” tool emerges as a do-anything cyber weapon

A free, uncensored AI model dubbed DIG AI is being actively misused on the dark web for malware creation, fraud facilitation, and even generating CSAM, according to researchers. The tool lowers the barrier to entry for sophisticated attacks, underscoring the need for content safeguards, model abuse monitoring, and enhanced detection of AI-assisted threats.

Source: CyberNews


Hackers reportedly stole millions of Pornhub users’ data for extortion

Attackers allegedly exfiltrated data on millions of Pornhub users and are leveraging it for extortion, heightening risks of doxxing and coercion. The roundup also notes Cisco disclosed a zero-day with no available patch, a reminder to deploy compensating controls and monitoring while awaiting fixes.

Source: Wired


You May Also Be Interested In...

Cybersecurity — December 21, 2025 | Briefing24