THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Europe issues baseline security standard for AI systems (ETSI EN 304 223)

ETSI released a new European Standard that defines baseline cybersecurity requirements for AI models and systems intended for real-world deployment. It treats AI as a distinct risk domain, addressing exposures tied to data pipelines and model behavior to guide builders and buyers toward more secure AI deployments.

Source: Help Net Security


Google Mandiant releases rainbow tables that crack Net-NTLMv1 logins in hours

Mandiant published Net-NTLMv1 rainbow tables to show how quickly the legacy Windows authentication protocol can be broken, underscoring the urgency to kill off NTLMv1. Organizations should audit for and disable NTLMv1, enforce stronger authentication, and accelerate deprecation of outdated protocols.

Source: CyberNews


Fake ad-blocker Chrome extension crashes browsers to push ModeloRAT (ClickFix-style “CrashFix”)

Researchers detailed “KongTuke,” an ongoing campaign using a malicious Chrome extension that masquerades as an ad blocker, deliberately crashes the browser, and then uses ClickFix-like lures to trick users into running commands. The endgame is delivery of a previously undocumented remote access trojan dubbed ModeloRAT.

Source: TheHackerNews


GootLoader evades defenses with hundreds of concatenated ZIP files

The GootLoader malware is leveraging malformed ZIP archives composed of hundreds of concatenated files to bypass security controls. Used as an initial-access tool by ransomware crews in an access-as-a-service model, GootLoader has accounted for a notable share of malware that slips past defenses in recent years.

Source: Security Affairs


Evelyn information-stealer targets software developers via malicious extensions

Trend Micro analyzed a campaign delivering the Evelyn stealer through a multistage chain that begins with a browser extension and progresses to full infection. The report highlights how developer-focused lures and tooling can be abused to harvest sensitive information at scale.

Source: TrendLabs Blog


Olympics cyber risk: Milan Cortina 2026 seen as target-rich environment

A Palo Alto Networks study warns that the 2026 Winter Olympic Games’ surge in traffic, temporary venues, fast-deployed systems, and short-term partnerships will draw attacker attention. Threats are expected across ticketing platforms, telecom infrastructure, and supporting services, demanding tighter controls and continuous monitoring.

Source: Help Net Security


North Korea-linked hackers weaponize Google and Naver ads to spread malware

A North Korea–linked group is abusing online ad infrastructure from Google and South Korea’s Naver to deliver malware while sidestepping security checks, according to Genians. The campaign underscores the persistence of malvertising risks even on mainstream platforms and the need for tighter ad supply chain controls.

Source: CyberNews


You May Also Be Interested In...

42,000 Impacted by Ingram Micro Ransomware Attack
Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations
Global tensions are pushing cyber activity toward dangerous territory
Cybersecurity — January 19, 2026 | Briefing24