THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical LangChain Core flaw exposes secrets and manipulates LLM outputs

A newly disclosed critical vulnerability in LangChain Core enables attackers to exfiltrate sensitive secrets and even influence large language model responses via serialization injection. Because langchain-core underpins many AI-enabled Python applications, exposure in this package can cascade across the AI app ecosystem. The issue spotlights growing risks where AI frameworks intersect with traditional software supply chains.

Source: The Hacker News


High-severity MongoDB RCE (CVE-2025-14847) could lead to server takeover

MongoDB addressed a high-severity vulnerability (CVSS 8.7) that allows unauthenticated remote code execution on vulnerable servers. The flaw involves a client-side exploit path against the server’s zlib implementation that can return uninitialized heap data, enabling arbitrary code execution. Organizations should review the vendor’s advisory and patch promptly to prevent full server compromise.

Source: Security Affairs


Fortinet warns of active exploitation of FortiOS SSL VPN 2FA bypass (CVE-2020-12812)

Fortinet observed recent in-the-wild abuse of a five-year-old improper authentication flaw in FortiOS SSL VPN that can allow logins without a second factor under specific configurations. The alert underscores persistent attacker interest in edge VPN appliances and the long tail of older vulnerabilities. Review configurations and mitigations if FortiOS SSL VPN is deployed.

Source: The Hacker News


CISA adds actively exploited Digiever NVR bug to KEV catalog

CISA added a Digiever DS-2105 Pro NVR vulnerability (CVE-2023-52163, CVSS 8.8) to its Known Exploited Vulnerabilities list, citing evidence of active attacks. The flaw is a command injection issue that enables post-authentication remote code execution, putting surveillance infrastructure at risk. Agencies and enterprises should prioritize remediation per KEV deadlines.

Source: The Hacker News


LastPass 2022 breach still fueling cryptocurrency thefts in 2025

TRM Labs reports that encrypted vault backups stolen in the 2022 LastPass breach have been cracked in cases where users relied on weak master passwords, enabling crypto thefts as recently as late 2025. Evidence points to Russian cybercriminal involvement. The findings highlight the long-lasting impact of vault breaches and the importance of strong master passwords.

Source: The Hacker News


Russia’s crackdown on illicit data market backfires as spies exploit ‘probiv’ ecosystem

Russia is attempting to rein in its long-tolerated illicit market for leaked personal data, known as the probiv market—an underground network fueled by corrupt insiders selling access to restricted databases. The effort appears to be backfiring, with Ukrainian intelligence reportedly exploiting the same ecosystem. The episode shows how entrenched data-leak economies can undermine state controls and security.

Source: The Guardian


Industrial threat report shows miners, ransomware, and spyware targeting ICS in Q3 2025

New data from Q3 2025 tracks threats detected and blocked on industrial control systems, highlighting activity from cryptocurrency miners, ransomware, spyware, and more. The findings reinforce that OT environments remain in the crosshairs of both commodity malware and targeted intrusions. Effective segmentation and monitoring across IT/OT boundaries remain critical.

Source: SecureList


You May Also Be Interested In...

LLMs can assist with vulnerability scoring, but context still matters

Seven cybersecurity trends next year, as seen by IBM: only two are not directly related to AI

They are offering up to $15k reward for betraying your boss

Cybersecurity — December 26, 2025 | Briefing24