THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Critical auth bypass in IBM API Connect allows remote access (CVE-2025-13915)

IBM disclosed a CVSS 9.8 authentication bypass in API Connect that could let attackers gain remote access to applications and gateways. Organizations should patch immediately, review access logs for anomalous sessions, rotate credentials and tokens, and limit management interfaces to trusted networks.

Source: Security Affairs


Coordinated attacks hammer Adobe ColdFusion over the holidays

GreyNoise observed thousands of requests targeting a dozen ColdFusion vulnerabilities during the Christmas 2025 period. If you run ColdFusion, prioritize patching, restrict/admin-gate CFIDE and administrative endpoints, and deploy WAF rules to blunt exploit spray-and-pray campaigns.

Source: SecurityWeek


Millions at risk as malicious browser extensions steal meeting data

China-linked group DarkSpectre used 18 rogue extensions across Chrome, Firefox, and Edge to siphon corporate meeting information from 2.2 million users in a “Zoom Stealer” campaign. Enterprises should audit and lock down extension usage, remove suspicious add-ons, and enforce browser policies via MDM.

Source: SC Media


European Space Agency confirms cyberattack on external servers

ESA disclosed that a small number of external servers holding unclassified collaborative engineering data were compromised; attackers claim exfiltration of ~200 GB, including credentials and source code. While systems were not classified, stolen credentials and code could enable follow-on intrusions if not contained.

Source: SC Media


Sedgwick subsidiary serving U.S. federal agencies hit by cyber incident

Claims administration giant Sedgwick confirmed a cybersecurity incident at a subsidiary that contracts with several sensitive federal agencies. Incident scope and data exposure remain under investigation; third-party risk teams should seek impact statements and monitor for downstream exposure.

Source: The Record


Krebs: ‘Kimwolf’ botnet exposes dangerous assumptions about LAN security

A months-long exploitation wave tied to the “Kimwolf” botnet undermines long-held beliefs about the safety of networks behind consumer and SMB routers. The advisory urges immediate hardening of internal networks, segmentation, and east–west monitoring, as perimeter NAT alone no longer provides meaningful protection.

Source: KrebsOnSecurity


APT36 targets Indian government and universities with LNK-based spying campaign

Pakistan-linked Transparent Tribe (APT36) is using weaponized Windows shortcut (LNK) files to compromise Indian government bodies, military-linked organizations, and universities. The long-running espionage actor continues to refine delivery and persistence; defenders should block LNK execution from email and enforce script control policies.

Source: The Record


You May Also Be Interested In...
RondoDox Botnet Exploiting React2Shell Vulnerability
US Among Most Exposed to MongoBleed Intrusions
Treasury Lifts Sanctions for Intellexa-Linked Execs
Cybersecurity — January 3, 2026 | Briefing24