THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical WatchGuard Firebox zero-day exploited in the wild

WatchGuard shipped fixes for a critical vulnerability in Fireware OS’s iked process that allows unauthenticated remote code execution, and it’s already being exploited. Edge appliances remain prime targets for rapid mass exploitation, so admins should prioritize patching, audit exposure of VPN/IKE services, and monitor for anomalous iked activity. Consider temporarily restricting management and VPN endpoints to trusted IPs until updates are fully deployed.

Source: SecurityWeek


Kimwolf Android botnet infects 1.8 million+ devices, unleashes massive DDoS

Researchers report the newly discovered Kimwolf Android botnet has compromised more than 1.8 million devices and issued over 1.7 billion DDoS commands, with links to the Aisuru botnet. Mobile devices are increasingly being weaponized for large-scale traffic floods; organizations should expand DDoS defenses to consider mobile-origin traffic and users should avoid sideloaded apps and keep devices updated.

Source: Security Affairs


Session token theft is surging, giving attackers a shortcut around MFA

Web apps commonly store session tokens in cookies or browser storage that are accessible to in-page scripts, including third-party tags—making theft easier than credential phishing. Stolen tokens let attackers bypass MFA and move quickly; mitigate with HttpOnly/Secure/SameSite cookies, short token lifetimes, token binding/DPoP where possible, strict CSP and tag governance, and continuous session anomaly detection.

Source: Help Net Security


NIST issues guidance to secure smart speakers in telehealth

As smart speakers and IoT assistants enter home health settings, NIST highlights risks from prescription tampering to medical data theft and patient impersonation. The new guidance outlines controls for device hardening, identity verification, data minimization, and secure connectivity to protect patients and providers in “virtual care” environments.

Source: Help Net Security


Europol-led operation nets 574 arrests in Africa-wide cybercrime crackdown

Operation Sentinel, spanning 19 countries over a month, targeted business email compromise, digital extortion, and ransomware, resulting in 574 arrests and roughly $3 million recovered. The takedown underscores BEC’s dominance and the value of coordinated international action; businesses should reinforce invoice/payment verification and tighten email security controls.

Source: Help Net Security


UK government probes “cyber incident” after reports of China-linked access to documents

Britain’s government confirmed it is investigating a cyber incident following media reports that China-linked hackers accessed thousands of confidential files. Details remain limited, but the case highlights ongoing state-aligned targeting of government data and the need for robust segmentation, access controls, and incident response readiness across the public sector.

Source: SecurityWeek


Docker makes hardened, open-source container images free for all

Docker released more than 1,000 Hardened Images—based on Debian and Alpine—at no cost under Apache 2.0, aiming to improve baseline security early in the software supply chain. Transparent, maintained base images help reduce image drift and vulnerability noise, enabling teams to focus on application-layer risks and consistent CI/CD trust policies.

Source: Help Net Security


You May Also Be Interested In... - Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale - Browser agents don’t always respect your privacy choices - University of Sydney discloses data breach impacting 27,000 people
Cybersecurity — December 22, 2025 | Briefing24