THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Cisco Unified Communications zero‑day actively exploited — patch immediately

Cisco released fixes for CVE‑2026‑20045, a remote code execution flaw in Unified Communications products that is already being exploited in the wild. Organizations should prioritize emergency patching and assume exposure where UC services are Internet‑reachable, monitoring for anomalous process launches and configuration changes post‑update.

Source: SecurityWeek


FortiGate firewalls hit by surge of automated configuration hijacks

Threat actors are bypassing FortiCloud SSO protections to create persistence accounts, alter device settings, and exfiltrate configurations from FortiGate appliances. The attacks mirror recent clusters seen since late 2025; defenders should audit admin accounts, review recent config diffs, rotate credentials, and enable out‑of‑band change alerts.

Source: SecurityWeek


SmarterMail auth bypass exploited two days after patch release

An authentication bypass in SmarterMail (WT‑2026‑0001) is under active exploitation, with attackers obtaining admin access shortly after vendor Build 9511 shipped. Admins should update immediately to the latest build, rotate credentials and API keys, and review admin/audit logs for suspicious logins and rule changes.

Source: SecurityWeek


Pwn2Own Automotive exposes 76 zero‑days across infotainment and EV chargers

Researchers earned over $1M for compromising systems from Tesla, Sony, Alpine and multiple EV charging platforms, disclosing 76 vulnerabilities over three days. The results highlight systemic weaknesses in automotive software supply chains and the urgency for rigorous SBOMs, hardening, and rapid patch pipelines for connected vehicles.

Source: SecurityWeek


Energy sector targeted by multi‑stage AiTM phishing and BEC using SharePoint

Microsoft warns that attackers are abusing trusted SharePoint file‑sharing to deliver adversary‑in‑the‑middle phishing, harvest credentials, and establish persistence with inbox rules before launching BEC. The campaign uses “NEW PROPOSAL – NDA” lures from compromised partners, reinforcing the need for conditional access, MFA hardening, and tenant‑to‑tenant trust controls.

Source: The Hacker News


North Korea‑linked KONNI pivots to developers with AI‑assisted lures

Check Point reports KONNI’s latest campaign targets software developers and engineering teams in blockchain/crypto projects, using project‑like documentation and AI‑enhanced tradecraft. The shift from diplomatic targets to technical staff with infrastructure access underscores the need for developer‑focused controls, including code signing, workstation hardening, and least‑privilege secrets access.

Source: Check Point Blog


Critical GNU InetUtils telnetd bug enables remote auth bypass to root

A newly disclosed flaw (CVE‑2026‑24061) in GNU InetUtils telnetd allows remote attackers to bypass login and gain root on affected systems — an issue lingering for nearly 11 years. While telnetd is legacy, its presence in older or embedded environments makes immediate removal or patching, and network‑level blocking of telnet, a priority.

Source: The Hacker News


You May Also Be Interested In...

GitLab patches critical 2FA bypass vulnerability
Zoom addresses critical remote code execution vulnerability
Malicious PyPI package impersonates SymPy to deploy XMRig miner
Cybersecurity — January 23, 2026 | Briefing24