THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA adds actively exploited Gogs vulnerability to KEV

The U.S. Cybersecurity and Infrastructure Security Agency flagged CVE-2025-8110, a high‑severity path traversal flaw in self‑hosted Git service Gogs, as actively exploited and added it to its Known Exploited Vulnerabilities catalog. The issue can enable code execution via the repository file editor; organizations running Gogs should patch immediately, restrict external access to admin interfaces, and hunt for suspicious repo edits or newly dropped executables.

Source: The Hacker News


APT28 targets energy, research, and defense collaboration with credential phishing

Russia-linked APT28 is impersonating Microsoft OWA, Google, and Sophos VPN portals to harvest credentials from energy research orgs and entities involved in defense collaboration. The long‑running group’s campaign underscores the need for phishing‑resistant MFA, strict SSO policies, and vigilant monitoring of login portals and VPN gateways.

Source: SecurityWeek


Spain’s largest power utility Endesa hacked; full customer data stolen

Hackers breached Endesa and exfiltrated complete customer records, including contact details, national identity numbers, and payment information. The incident hits critical infrastructure and raises fraud and identity theft risks; impacted customers and partners should enable transaction alerts, rotate credentials, and watch for targeted social engineering.

Source: SecurityWeek


Mandiant releases AuraInspector to expose Salesforce data access misconfigurations

Mandiant’s new open-source AuraInspector helps admins find Salesforce Experience Cloud/Aura access control gaps that can leak sensitive data. The research details how an Aura GraphQL controller enables consistent pagination beyond the usual 2,000‑record UI limit—amplifying the blast radius of misconfigurations—and urges auditing guest permissions, sharing rules, and self‑registration settings.

Source: Google Cloud Threat Intelligence


WEF: Cyber fraud tops CEO worries while ransomware remains CISOs’ No. 1 threat

The World Economic Forum’s Global Cybersecurity Outlook 2026 finds cyber fraud has overtaken ransomware as CEOs’ chief concern, even as CISOs still rank ransomware highest. The report highlights AI‑driven risk growth and supply‑chain exposure, pressing leaders to strengthen identity verification, anti‑fraud controls, third‑party risk management, and AI governance.

Source: SecurityWeek


Chainalysis: Nation-states moved billions as crypto crime hit record highs in 2025

Chainalysis reports that nation‑state actors increasingly leveraged professional on‑chain services and bespoke infrastructure in 2025 to launder funds at scale, contributing to record crypto crime volumes. The findings signal maturing criminal supply chains and greater sanctions exposure, elevating the need for blockchain analytics, KYC/AML rigor, and rapid wallet attribution.

Source: Help Net Security


UK opens formal probe into X over Grok ‘nudification’ of children’s images

Ofcom launched an investigation into X for potential Online Safety Act violations after reports that its Grok AI generated sexualized images of minors. The UK government signaled support for a robust regulatory response as scrutiny of AI misuse intensifies across jurisdictions.

Source: The Register


You May Also Be Interested In...

Infamous BreachForums forum breached, spilling data on ~325,000 users

New multi‑stage Windows campaign delivers Remcos RAT with stealthy execution

Threat intel warns misconfigured proxies expose LLM APIs to attackers

Cybersecurity — January 13, 2026 | Briefing24