THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft’s January Patch Tuesday fixes exploited Windows zero‑day and Secure Boot changes

Microsoft shipped fixes for 114 vulnerabilities, including an actively exploited information disclosure in Desktop Window Manager (CVE-2026-20805) likely used as part of exploit chains. The release also introduces a Secure Boot certificate transition (CVE-2026-21265) that requires careful planning to avoid unbootable systems, and removes legacy Agere modem drivers tied to public elevation-of-privilege research (CVE-2023-31096). Admins should prioritize the zero‑day, plan Secure Boot certificate updates, and address high‑impact Windows/Office RCEs.

Source: Rapid7


VoidLink: Cloud‑native Linux malware framework targets stealth persistence in cloud infrastructure

Check Point Research detailed “VoidLink,” an advanced, modular malware framework engineered to maintain long‑term, covert access to Linux systems that underpin cloud services. Its plug‑in design, adaptive stealth, and shift away from endpoint‑centric tactics signal attacker focus on cloud runtime and control planes—raising the bar for detection and response in containerized and server environments.

Source: Check Point Blog


CISA adds exploited Gogs path traversal flaw to KEV, urges immediate mitigation

A high‑severity path traversal vulnerability in the self‑hosted Git service Gogs (CVE-2025-8110) is under active attack and now listed in CISA’s Known Exploited Vulnerabilities catalog. The bug can enable code execution via the repository file editor; U.S. federal agencies must remediate or remove affected instances, and enterprises running Gogs should patch or lock them down immediately.

Source: The Hacker News


Critical Node.js bug can crash servers across “virtually every” production app

Node.js released patches for a critical issue in async_hooks stack handling that can trigger denial‑of‑service across most production deployments. Because many frameworks rely on recoverable stack exhaustion behavior for availability, teams should fast‑track updates to the latest fixed versions and review DoS controls protecting Node stacks exposed to untrusted input.

Source: The Hacker News


Fortinet patches critical pre‑auth flaws in FortiFone and FortiSIEM

Fortinet addressed two critical vulnerabilities that are exploitable without authentication, leading to configuration disclosure and remote code execution. Given the prevalence of Fortinet gear in hybrid networks and SOC stacks, organizations should patch immediately and review exposure of management interfaces to the internet.

Source: SecurityWeek


ServiceNow fixes critical AI Platform bug allowing unauthenticated user impersonation

ServiceNow disclosed and patched CVE-2025-12420 (CVSS 9.3), a flaw in its AI Platform that could let an unauthenticated attacker impersonate users and perform arbitrary actions. Customers should apply updates promptly and audit recent activity for anomalous actions executed via AI workflows.

Source: The Hacker News


Long‑running Magecart campaign skims cards from enterprise checkout flows

Researchers uncovered a global web‑skimming (Magecart) operation active since January 2022 that targets major payment networks and enterprise e‑commerce sites via third‑party scripts. Because these attacks execute in the browser and evade traditional server‑side controls, defenders should enforce script integrity (e.g., SRI), strict Content Security Policy, and continuous third‑party script monitoring.

Source: Silent Push


You May Also Be Interested In...

Chrome 144, Firefox 147 Patch High‑Severity Vulnerabilities

Hack shuts down hospital IT, dozens of surgeries postponed

Target source code for sale on dark web as employees confirm it’s authentic

Cybersecurity — January 14, 2026 | Briefing24