THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft: Misconfigured email routing lets phishers spoof “internal” messages

Microsoft warns that threat actors are abusing complex mail routing and misconfigured spoof protections to send phishing emails that appear to originate from inside victim organizations. Operators tied to phishing-as-a-service offerings, including Tycoon 2FA, have used this vector to increase trust and bypass controls. Microsoft urges organizations to review routing paths and enforce SPF, DKIM, and DMARC alignment, including for third-party senders.

Source: Microsoft MMPC


Active exploitation: Critical RCE hitting legacy D-Link DSL routers (CVE-2026-0625)

A command injection flaw in legacy D-Link DSL gateway routers is being actively exploited in the wild, enabling unauthenticated remote attackers to execute commands via a vulnerable dnscfg.cgi endpoint. With many devices end-of-life, patches may be unavailable—administrators should retire affected models, disable remote management, and isolate devices immediately.

Source: TheHackerNews


“ClickFix” lures and fake BSODs target European hotels to drop DCRat

A sophisticated social-engineering campaign impersonates Booking.com, funneling hospitality staff to fake Blue Screen of Death pages that prompt them to “apply a fix,” ultimately executing malware and installing the DCRat remote access trojan. The operation chains phishing, fake CAPTCHAs, and staged support flows to defeat user caution and email filtering.

Source: SecurityWeek


900,000 users hit by malicious Chrome extensions stealing ChatGPT and DeepSeek chats

Researchers uncovered two popular Chrome extensions siphoning AI chat content and browsing data to attacker servers, creating a high-risk data leakage vector for enterprises experimenting with generative AI. Organizations should remove the flagged extensions, audit browser extension usage, and lock down extension policies in managed environments.

Source: TheHackerNews


Critical auth bypass in IBM API Connect (CVE-2025-13915) — patch now

The Cyber Security Agency of Singapore and IBM disclosed a critical authentication bypass (CVSS 9.8) affecting IBM API Connect versions up to 10.0.8.5 and 10.0.11.0. While no active exploitation is reported, the remotely exploitable flaw can grant unauthorized access; IBM has issued interim fixes and urges immediate upgrades.

Source: Cyble


Android January update fixes critical Dolby decoder bug (CVE-2025-54957)

Google’s January Android security release patches a critical vulnerability in the Dolby audio decoder first fixed for Pixel devices in December. The flaw could enable remote code execution via crafted media; administrators should prioritize rolling out the update across managed fleets.

Source: SecurityWeek


Ledger confirms third‑party breach exposing customer data; phishing begins

Crypto wallet maker Ledger says customer information was accessed via ecommerce partner Global-e, and warns that phishing attempts have already started. While seed phrases and passwords weren’t exposed, attackers are leveraging the data to push fake updates and wallet-draining scams—users should distrust unsolicited messages and verify firmware only in-app.

Source: The Register


You May Also Be Interested In...

CERT/CC warns of critical, unfixed vulnerability in TOTOLINK EX200

FCC finalizes new penalties for robocall violators

UK government admits years of cyber policy have failed, announces reset

Cybersecurity — January 7, 2026 | Briefing24