THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
WatchGuard Firebox zero‑day under active attack (CVE‑2025‑14733)

Shadowserver scans show more than 115,000 internet‑facing WatchGuard Firebox firewalls potentially exposed to CVE‑2025‑14733, an unauthenticated remote code execution bug that attackers are currently exploiting. Organizations should urgently patch Fireware OS, limit public exposure of management interfaces, and monitor for anomalous VPN/iked activity.

Source: Help Net Security


Attackers abuse Google Cloud to send phishing from a trusted google.com address

A campaign impersonating Google‑generated notifications leveraged Google Cloud Application Integration to send 9,394 phishing emails to roughly 3,200 customers in 14 days from noreply-application-integration@google.com. Because the messages originated from Google infrastructure, they bypassed typical sender checks; defenders should tighten workflow automation allowlists, apply bannering and content controls, and train users to verify “routine” alerts.

Source: Check Point Blog


Malicious npm package with 56,000 downloads steals WhatsApp data and accounts

A trojanized WhatsApp Web API package on npm offered legitimate functionality while covertly intercepting messages, harvesting credentials, and linking the attacker’s device to victims’ accounts. The incident underscores ongoing software supply chain risk; teams should inventory and pin dependencies, scan packages pre‑adoption, and revoke tokens/rotate credentials if exposed.

Source: SecurityWeek


Critical n8n workflow automation flaw enables RCE across exposed instances (CVE‑2025‑68613)

A CVSS 9.9 vulnerability in n8n’s expression evaluation can lead to arbitrary code execution in certain configurations, potentially impacting thousands of self‑hosted deployments. Patch immediately to the fixed release, restrict network access to the UI and webhooks, and rotate any secrets handled by impacted workflows.

Source: The Hacker News


DDoS disrupts France’s La Poste postal and banking services days before Christmas

La Poste confirmed a DDoS attack caused widespread outages across its websites and mobile apps, delaying package deliveries and blocking online payments during a peak shopping period. The incident highlights the need for layered DDoS protection, traffic engineering playbooks, and payment failover strategies for critical consumer services.

Source: SecurityWeek


INTERPOL/Europol operation nets 574 arrests, recovers $3M across Africa

Operation Sentinel, a month‑long crackdown spanning 19 countries, targeted business email compromise, digital extortion, and ransomware operations, leading to hundreds of arrests and device seizures. The results reflect growing international pressure on cybercriminal networks and reinforce the value of cross‑border evidence sharing for BEC and fraud investigations.

Source: SecurityWeek


Darknet “DIG AI” assistant accelerates cybercrime with uncensored capabilities

Researchers report the rapid rise of DIG AI, an uncensored darknet assistant enabling criminals and organized groups to perform advanced data processing and operational support for malicious activity. Usage surged through Q4, lowering barriers for less‑skilled actors; defenders should anticipate AI‑enabled reconnaissance, phishing, and tooling, and enhance detection around anomalous automation.

Source: Help Net Security


You May Also Be Interested In...

Potential attacks threaten over tens of thousands of Fortinet devices

UK Government Acknowledges It Is Investigating Cyber Incident After Media Reports

Around 1,000 systems compromised in ransomware attack on Romanian water agency

Cybersecurity — December 23, 2025 | Briefing24