THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Cisco patches critical AsyncOS zero-day exploited by China-linked group

Cisco released fixes for CVE-2025-20393, a maximum-severity AsyncOS flaw in Secure Email Gateway and Secure Email and Web Manager that had been actively exploited since late 2025. Investigators tie the intrusions to UAT-9686, which used the bug to deploy the AquaShell backdoor on internet-exposed appliances; admins should patch now, audit for compromise, and rebuild any affected devices. The flaw was previously added to CISA’s KEV list.

Source: SecurityWeek


HPE OneView under mass exploit as RondoDox botnet targets management stacks

A critical HPE OneView vulnerability is being exploited at scale, with Check Point observing tens of thousands of automated attack attempts linked to the RondoDox botnet, including against government organizations. Organizations should urgently apply HPE updates, isolate/ACL management interfaces, and review OneView credentials and logs for suspicious automation and command execution.

Source: The Register


“CodeBreach” in AWS CodeBuild could have enabled GitHub repo takeovers

Wiz researchers disclosed a supply chain vulnerability in AWS CodeBuild that hinged on subtle input filtering errors, potentially allowing attackers to compromise build environments and hijack connected GitHub repositories. AWS remediated the issue following disclosure; customers should verify they’re on patched CodeBuild infrastructure, tighten IAM roles and webhook scopes, rotate tokens, and enable build integrity controls (e.g., provenance/signing).

Source: SC Media


WhisperPair flaws expose millions of Bluetooth earbuds to hijacking and tracking

Researchers detailed “WhisperPair,” attacks that exploit improper implementations of Google’s Fast Pair protocol to take control of popular earbuds and headphones without user interaction. The weaknesses enable device hijacking, eavesdropping, and persistent tracking; users should apply vendor firmware updates, disable fast/auto-pairing in risky environments, and avoid pairing prompts from unknown sources.

Source: SecurityWeek


GootLoader adopts malformed ZIP archives to slip past defenses

The GootLoader crew is chaining 500–1,000 concatenated ZIP archives to craft malformed files that common tools (7-Zip, WinRAR) fail to extract—while Windows’ built-in utility opens them—evading both user suspicion and automated analysis. The technique ultimately delivers the JavaScript loader; defenders should block script execution from user directories, harden mail/web gateways against suspicious archives, and rely on EDR telemetry for post-execution detections.

Source: The Hacker News


Active exploitation: Modular DS WordPress plugin allows admin takeover (CVE-2026-23550)

A critical, unauthenticated privilege escalation flaw in the Modular DS plugin—installed on 40,000+ WordPress sites—is being actively exploited to seize administrator control. Site owners should update or disable the plugin immediately, rotate credentials/API keys, and hunt for indicators such as new admin users, altered settings, and dropped webshells.

Source: Security Affairs


Police raid homes of alleged Black Basta operators; ringleader hunt intensifies

European authorities raided properties tied to the Black Basta ransomware syndicate and added a suspected Russian ringleader to the EU most-wanted list. While the action may disrupt the group’s operations, history shows ransomware ecosystems rebrand and rebound—organizations should expect copycats and splinters and maintain strict backup, patch, and identity hygiene.

Source: The Record by Recorded Future


You May Also Be Interested In...

Palo Alto Networks patches denial-of-service flaw in GlobalProtect

Wireshark 4.6.3 ships with fixes for 4 vulnerabilities

750,000 affected in Canadian investment watchdog data breach

Cybersecurity — January 17, 2026 | Briefing24