THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Actively exploited Cisco zero-day hits Unified Communications and Webex Calling

Cisco patched CVE-2026-20045, a critical remote code execution flaw in multiple Unified Communications products and Webex Calling Dedicated Instance that attackers are already exploiting. The bug allows unauthenticated code execution via crafted HTTP requests to the web management interface; organizations should patch immediately, restrict management access, and monitor for anomalous admin actions. CISA has urged rapid remediation by adding the issue to its priority lists.

Source: SecurityWeek


Reports suggest FortiGate auth bypass persists despite “fixed” releases

Enterprises are reporting compromises of fully patched FortiGate firewalls linked to CVE-2025-59718, an authentication bypass Fortinet said was fixed in December. Admins observed unauthorized logins and rogue account creation on FortiOS versions thought to be remediated, raising concern that residual paths or related flaws remain. Fortinet customers should audit admin accounts, rotate credentials, and tighten external access while monitoring for new advisories.

Source: Help Net Security


Anthropic MCP server flaws enable code execution and data exposure via prompt injection

Multiple vulnerabilities in Anthropic’s official Model Context Protocol (MCP) Git server can be triggered through prompt injections to achieve code execution and exfiltrate sensitive data. The issues include path validation bypass and argument injection, underscoring how AI toolchains expand attack surfaces beyond traditional app logic. Teams integrating MCP should update promptly, harden permissions, and instrument runtime monitoring for tool invocation.

Source: SecurityWeek


North Korean campaign uses malicious VS Code projects to infect macOS developers

Attackers linked to North Korea are luring developers to open booby-trapped repositories in Visual Studio Code, delivering malware under the guise of coding projects. Targets include macOS engineers in crypto, fintech, and software sectors. Defenders should disable auto-running tasks, scrutinize dev dependencies, and gate repo access to trusted, verified sources.

Source: SecurityWeek


Hijacked Snap Store publishers push crypto-stealing malware to Linux users

Threat actors are taking over expired domains and email for legitimate Snap Store publishers to seize their Snapcraft accounts and ship trojanized packages. The malicious snaps target cryptocurrency assets and exploit the trust users place in official channels. Linux admins should verify publisher identity, review snap permissions, and consider pinning or vetting updates in high-risk environments.

Source: Help Net Security


EU moves to secure ICT supply chains, expand certification, and curb high‑risk suppliers

The European Commission proposed a revised EU Cybersecurity Act establishing an ICT supply chain security framework and streamlining certification. The package would support EU‑wide risk assessments and enable restrictions or phase-outs of high-risk vendors from sensitive infrastructure, elevating “secure by design” across products entering the EU market. Suppliers and operators should prepare for tighter scrutiny and new compliance obligations.

Source: Help Net Security


LastPass warns of phishing emails pushing fake “vault backups”

Attackers are sending convincing emails claiming imminent maintenance and urging LastPass users to create backups within 24 hours—an attempt to steal master passwords. The company cautions users to ignore unsolicited links, verify communications via official channels, and enable phishing-resistant MFA. Security teams should alert employees and watch for credential misuse tied to password manager accounts.

Source: SecurityWeek


You May Also Be Interested In...
CISA adds Cisco Unified Communications flaw to Known Exploited Vulnerabilities
Automated FortiGate attacks exploit FortiCloud SSO to alter firewall configs
Exposed training apps are showing up in active cloud attacks
Cybersecurity — January 22, 2026 | Briefing24