THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
MongoBleed: Critical MongoDB memory leak bug is under active exploitation

A newly disclosed vulnerability in MongoDB Server, CVE-2025-14847 (“MongoBleed”), allows unauthenticated remote memory disclosure when zlib network compression is enabled. Attackers can potentially leak credentials, session tokens, and sensitive data, with the US, China, and EU among the most targeted regions. Organizations should patch immediately, disable zlib compression where possible, and hunt for suspicious database activity.

Source: Security Affairs


SmarterMail flaw (CVSS 10) enables unauthenticated RCE; Singapore CSA issues alert

Singapore’s Cyber Security Agency warns of CVE-2025-52691, a maximum-severity vulnerability in SmarterMail that permits unauthenticated remote code execution via arbitrary file upload. The ease of exploitation and exposed mail servers make this a high-priority patch. Admins should update immediately, restrict public access to admin interfaces, and monitor for webshell indicators.

Source: Security Affairs


Trust Wallet $8.5M theft tied to Shai-Hulud supply chain compromise

A supply chain attack known as Shai-Hulud exposed Trust Wallet’s developer GitHub secrets, enabling attackers to publish a backdoored browser extension that drained funds from 2,520 wallets. The incident underscores risks from stolen CI/CD credentials and developer tokens, especially in browser extension ecosystems. Teams should rotate secrets, audit extension code paths, and enforce least-privilege automation.

Source: SecurityWeek


European Space Agency confirms breach after hacker offers “200GB” of data for sale

ESA says external science servers were compromised following claims by a threat actor offering a large trove of stolen documents, credentials, and source code. While ESA reports the impact is limited to external systems, the breach highlights ongoing targeting of the space sector and the sensitive research and IP it holds. Incident response and containment efforts are underway.

Source: SecurityWeek


DarkSpectre: Massive malicious browser extension campaigns hit 8.8 million users

Researchers linked the Chinese threat actor “DarkSpectre” to large-scale Chrome, Edge, and Firefox extension campaigns (ShadyPanda, GhostPoster, and DarkSpectre) that exfiltrate data and manipulate browser sessions. The campaigns collectively impacted millions of users worldwide and exploited lax extension governance. Enterprises should restrict extensions, enforce allowlists, and audit installed add-ons across managed endpoints.

Source: The Hacker News


RondoDox botnet hijacks IoT and web servers via React2Shell (CVE-2025-55182) mega-flaw

A nine-month campaign has been enrolling IoT devices and web apps into the RondoDox botnet by abusing the critical React2Shell vulnerability (CVSS 10.0). The operators use the bug as an initial access vector to take over exposed systems at scale. Patch React2Shell immediately, segment IoT networks, and monitor for anomalous outbound traffic indicative of botnet activity.

Source: The Hacker News


Iranian APT ‘Prince of Persia’ retools with three new malware strains for critical infrastructure

SC researchers report that an Iranian state-aligned actor has developed three new malware families and is likely to use them against energy, water, and transportation systems. The renewed toolkit suggests a focus on operational disruption and espionage in the critical infrastructure sector. OT defenders should tighten segmentation, validate logging/alerting in ICS environments, and rehearse incident response playbooks.

Source: SC Media


You May Also Be Interested In...

IBM warns of critical API Connect auth bypass (CVE-2025-13915)

Finland seizes ship suspected of Baltic subsea cable sabotage

Mustang Panda deploys kernel rootkit to stealth TONESHELL malware

Cybersecurity — January 1, 2026 | Briefing24