THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Chinese-speaking attackers exploited VMware ESXi zero-days long before disclosure

New analysis finds that fresh attacks targeted three VMware ESXi vulnerabilities disclosed as zero-days in March 2025, with evidence suggesting an exploit kit was likely built roughly a year prior. The activity underscores the risk of hypervisor escape and the need to rapidly patch, restrict management interfaces, and monitor for signs of exploitation across virtualization stacks.

Source: SecurityWeek


Trend Micro patches critical Apex Central code execution flaw as PoC is released

Trend Micro shipped fixes for multiple Apex Central on‑prem Windows vulnerabilities, including a critical code execution issue, shortly before Tenable published technical details and proof-of-concept exploit code. With exploit guidance now public, enterprises should prioritize patching, lock down console access, and increase detection for post-exploitation activity.

Source: SecurityWeek


FBI warns Kimsuky using malicious QR codes for spear-phishing

The FBI says North Korea’s Kimsuky group has spear‑phished government, think tank, and academic targets using QR codes to drive victims to credential‑harvesting pages, often bypassing email link filters. Defenders should treat QR codes in messages like links: verify provenance, disable automatic URL opening, enforce phishing‑resistant MFA (FIDO2), and monitor mobile endpoints.

Source: SecurityWeek


CISA retires 10 emergency directives as KEV catalog becomes the north star

CISA has closed 10 emergency directives issued between 2019 and 2024, noting their objectives have been met or are now covered by the Known Exploited Vulnerabilities (KEV) catalog. The move signals a shift toward continuous, catalog‑driven remediation; agencies and enterprises should align patch SLAs and asset coverage to KEV entries and automate compliance tracking.

Source: SecurityWeek


‘ZombieAgent’ shows how attackers can take over ChatGPT via long‑term memory

Researchers at Radware demonstrated “ZombieAgent,” a technique that bypasses protections to exfiltrate user data and implant persistent logic into ChatGPT’s long‑term memory. The findings highlight AI agent risks like prompt injection and memory poisoning; mitigation requires sandboxing agents, resetting/cleansing memory, strict tool and data‑access policies, and input/output filtering.

Source: SecurityWeek


LLM infrastructure faces mass internet scanning, GreyNoise honeypots show

GreyNoise honeypots recorded more than 80,000 sessions probing LLM endpoints in just 11 days, indicating rapid reconnaissance of AI application surfaces. Organizations should put strong authentication and rate limiting in front of LLM gateways, restrict public exposure, and add detections for enumeration patterns and known-bad sources.

Source: SC Magazine


Cisco rushes ISE/ISE-PIC patch after public PoC for CVE‑2026‑20029

Cisco released updates for a medium‑severity flaw in Identity Services Engine and ISE Passive Identity Connector following a proof‑of‑concept exploit that could expose sensitive files. Even at medium CVSS, the public PoC raises risk; apply patches quickly, restrict access to ISE management services, and review logs for abnormal file access.

Source: SC Magazine


You May Also Be Interested In...

Metasploit Wrap-Up: New RISC‑V payloads and modules land

European Commission opens consultation on EU digital ecosystems

At least $26 million in crypto stolen from Truebit platform

Cybersecurity — January 10, 2026 | Briefing24