THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
MongoBleed actively exploited, tens of thousands of MongoDB servers at risk

Attackers are exploiting CVE-2025-14847 (“MongoBleed”), a critical memory-leak flaw in MongoDB’s zlib-based network compression, to expose secrets from server memory. More than 87,000 internet-exposed instances could be compromised as intrusions continue, underscoring the urgency of patching and reducing exposure of management interfaces.

Source: SC Media


Mustang Panda deploys signed kernel-mode rootkit to stealthily load TONESHELL

Kaspersky researchers observed Chinese APT Mustang Panda using a signed kernel driver containing user‑mode shellcode to deploy a new TONESHELL backdoor variant. The technique improves stealth and persistence, signaling continued escalation in driver-based tradecraft in espionage operations.

Source: SecurityWeek


Official EmEditor download button abused in software supply chain attack

The EmEditor website’s “download” button briefly served a malicious installer delivering an infostealer, turning a trusted update path into an infection vector. The incident highlights how small compromises in web distribution can ripple into large-scale compromise for software users.

Source: SecurityWeek


Evasive Panda used DNS poisoning to install MgBot backdoor

A China-linked APT leveraged DNS poisoning to intercept requests and quietly deliver the MgBot backdoor to targets in Türkiye, China, and India. The campaign shows how subverting name resolution can bypass perimeter defenses and deliver payloads without traditional phishing.

Source: Security Affairs


Air-gapped embedded devices can still “hear” radio commands, study warns

New research demonstrates that even embedded devices without radios or sensors can receive wireless commands once an attacker gains code execution, eroding assumptions about air-gap safety. The finding raises the stakes for hardware and firmware hardening and tight control over what code runs on critical systems.

Source: Help Net Security


Old FortiOS bug resurfaces: attackers bypass 2FA via CVE-2020-12812

Fortinet reports fresh exploitation of a 2020 FortiOS flaw that allows bypassing two-factor authentication, reminding defenders that long-patched issues remain potent when systems lag behind. Organizations should verify patch status and review access logs for suspicious authentications.

Source: SecurityWeek


Aflac breach impacts 22 million, exposing highly sensitive personal and medical data

Aflac is notifying roughly 22 million people after attackers stole names, addresses, Social Security and ID numbers, and medical and health insurance information. The scope and sensitivity of the data elevate risks of identity theft and fraud, with downstream compliance and notification obligations likely to follow.

Source: SecurityWeek


You May Also Be Interested In...

CISA adds MongoBleed to Known Exploited Vulnerabilities catalog
Non-human identities push identity security into uncharted territory
French software company fined $2 million for cyber failings leading to data breach
Cybersecurity — December 30, 2025 | Briefing24