THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
APT28 targets energy and policy sectors in credential-harvesting campaigns

Recorded Future’s Insikt Group observed Russia-linked APT28 running credential-harvesting operations from February to September 2025, hitting Turkish energy and nuclear agency staff, European think tank personnel, and organizations in North Macedonia and Uzbekistan. The campaigns focus on account takeover to gain access to sensitive networks and policy information, underscoring the need to harden identity systems and phishing defenses across critical sectors.

Source: Security Affairs


LLMs in attacker crosshairs via misconfigured proxies

Threat actors are hunting for misconfigured proxy servers to obtain access to APIs for various large language models, a new threat intel warning says. Such access can enable data exfiltration, model abuse, and cost fraud against organizations piloting or deploying generative AI. Lock down API keys, enforce egress controls, and monitor usage anomalies.

Source: SecurityWeek


Telegram one-click flaw can leak users’ real IP addresses

A researcher detailed a one-click vulnerability in Telegram for Android and iOS that can expose a user’s real IP address, bypassing the app’s built-in proxy feature. The issue poses privacy and safety risks for users relying on Telegram proxies for anonymity; exercise caution with links and proxy configurations while awaiting vendor guidance.

Source: CyberNews


AsyncRAT campaign abuses Cloudflare free tier and Python environments

Trend Micro analyzed a multi-stage AsyncRAT operation that leverages Cloudflare’s free-tier infrastructure and legitimate Python environments to blend into trusted services and evade detection. The campaign highlights continued adversary abuse of commonplace cloud platforms for C2 and payload delivery; defenders should scrutinize outbound traffic to cloud providers and monitor local Python execution chains.

Source: Trend Micro Research


YARA-X 1.11.0 adds hash function warnings to aid rule authors

The latest YARA-X release introduces hash function warnings, helping analysts spot potentially problematic or inefficient hashing within rules. The feature supports higher-quality detections by nudging rule authors toward safer and more performant patterns; teams should test the update and address new warnings during rule maintenance.

Source: SANS Internet Storm Center


Crypto crime surges as state actors move billions on-chain

Chainalysis research shows nation-state involvement in crypto-related crime increased in 2025, with illicit groups operating large-scale on-chain infrastructure to support cross-border networks and launder funds. State actors are tapping the same infrastructure via professional service providers and custom systems designed to evade controls, blurring lines between organized crime and geopolitically driven activity.

Source: Help Net Security


‘Pig butchering’-as-a-service providers exposed

Researchers uncovered two service providers supplying tools and infrastructure to industrial-scale pig-butchering (romance-investment) scams. Since at least 2016, Chinese-speaking criminal groups have stood up scam centers across Southeast Asia, even establishing zones focused on fraudulent investment operations, illustrating how outsourcing continues to industrialize this fraud ecosystem.

Source: The Hacker News


You May Also Be Interested In...

Instagram says there’s been ‘no breach’ despite password reset requests

EU’s Chat Control could put government monitoring inside robots

What security teams can learn from torrent metadata

Cybersecurity — January 12, 2026 | Briefing24