THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
New MongoDB flaw lets unauthenticated attackers read uninitialized memory (CVE-2025-14847)

MongoDB disclosed a high‑severity bug that allows unauthenticated users to read uninitialized heap memory, potentially exposing sensitive data from affected servers. Admins should patch immediately, restrict network exposure, and audit logs for suspicious access to reduce potential data leakage.

Source: TheHackerNews


Critical LangChain Core vulnerability exposes secrets via serialization injection (CVE-2025-68664)

A critical flaw in langchain-core enables attackers to exfiltrate secrets and manipulate LLM responses via serialization injection and prompt injection paths. Teams building agentic AI apps should upgrade promptly, rotate exposed credentials, and harden integrations that pass untrusted data into toolchains.

Source: TheHackerNews


CISA adds Digiever NVR RCE to Known Exploited Vulnerabilities catalog

CISA added a high‑severity missing-authorization flaw in Digiever DS-2105 Pro network video recorders (CVE-2025-52163) to its KEV list amid active exploitation. Agencies—and any enterprise using these NVRs—should prioritize patching, isolate internet exposure, and monitor for compromise given the devices’ role in physical security.

Source: SCMagazine


Mass compromises hit React/Next.js servers in “Operation PCPcat”

Over 59,000 servers running React frameworks like Next.js were reportedly breached in just 48 hours as part of an automated cyberespionage campaign dubbed Operation PCPcat. The speed and scale highlight the need to patch promptly, review server-side rendering configurations, and rotate exposed API keys and tokens.

Source: SCMagazine


Attackers revive exploitation of old Fortinet FortiOS SSL VPN bug (CVE-2020-12812)

Threat actors are actively exploiting a five-year-old improper authentication flaw in Fortinet FortiOS SSL VPN, underscoring how legacy edge vulnerabilities continue to yield access. Organizations should ensure appliances are upgraded beyond vulnerable versions, enforce MFA, and scrutinize VPN login anomalies.

Source: SCMagazine


Malicious npm package “lotusbail” stole WhatsApp credentials, installed backdoor

Researchers found that the npm package “lotusbail” (a fork of a WhatsApp Web API library) covertly stole WhatsApp credentials, hid activity, and deployed a backdoor—amassing over 56,000 downloads. Teams should remove the package, rotate any affected tokens/sessions, and review dependency hygiene and lockfiles.

Source: Security Affairs


Trust Wallet Chrome extension bug led to ~$7M in losses—update now

Trust Wallet warned users to update its Chrome extension after a security incident impacted version 2.68, contributing to roughly $7 million in losses. Users should upgrade immediately, verify extension integrity, and consider moving funds and revoking risky approvals as a precaution.

Source: TheHackerNews


You May Also Be Interested In...

Advanced NtKiller tool touts antivirus, EDR evasion on dark web

China-linked Evasive Panda used DNS poisoning to deliver MgBot

Aflac confirms June data breach affecting over 22 million customers

Cybersecurity — December 27, 2025 | Briefing24