THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Sandworm linked to Poland power grid attack; new wiper “DynoWiper” analyzed

ESET attributed a late-December 2025 cyberattack on Poland’s power system to Russia’s Sandworm, identifying a data-wiping malware dubbed DynoWiper. Although the attempt did not disrupt electricity, the campaign underscores sustained nation-state interest in European energy infrastructure and the need for strong segmentation, backups, and OT/IT incident playbooks.

Source: ESET Blog


Okta users targeted as modern phishing kits supercharge vishing and bypass MFA

Researchers warn that new phishing kits enable real-time interception of credentials and allow attackers to steer authentication flows in victims’ browsers—amplifying vishing campaigns against Okta users. Sold as-a-service, these kits can defeat common MFA implementations, raising urgency for phishing‑resistant authentication (FIDO2), number-matching, and strict session/device controls.

Source: Help Net Security


Fortinet confirms FortiCloud SSO bypass hitting fully patched devices

Fortinet said attackers are bypassing FortiCloud single sign-on on some fully updated FortiGate devices, echoing recent SSO issues and prompting urgent reviews of access logs and controls. Customers should apply the latest updates as released, enforce IP allowlists and MFA on admin access, and monitor for anomalous logins.

Source: SecurityWeek


CISA adds actively exploited VMware vCenter bug (CVE-2024-37079) to KEV

A critical heap overflow in VMware vCenter Server patched in June 2024 is now under active attack, according to CISA’s KEV update. Organizations should immediately verify patch levels or isolate affected systems—vCenter compromises can cascade across virtualization estates and expose sensitive management planes.

Source: The Hacker News


149 million usernames and passwords exposed via unsecured database

An open cloud database leaked 149 million credentials from services including Gmail, Facebook, and financial accounts—likely compiled from infostealer logs. The trove is a “dream wish list for criminals,” reinforcing the need for password managers, unique credentials, and mandatory MFA, and for enterprises to check for exposed employee accounts.

Source: Wired


Reports: Microsoft provided FBI with BitLocker recovery keys in probe

Microsoft reportedly furnished court-ordered BitLocker recovery keys to the FBI to decrypt suspects’ laptops, spotlighting risks when vendors retain recovery capabilities. Enterprises that require high-assurance privacy should evaluate customer-managed keys and HSM-backed policies that prevent third-party key escrow.

Source: TechCrunch


11-year-old telnetd flaw (CVE-2026-24061) in GNU InetUtils allows root compromise

A critical authentication bypass affecting telnetd in GNU InetUtils versions 1.9.3–2.7 went unnoticed for nearly 11 years and can yield root access. Organizations should disable telnet where present, patch or remove affected components—especially on legacy Linux/embedded systems—and prefer SSH with strong auth.

Source: Security Affairs


You May Also Be Interested In...

CISA won’t attend the RSA Conference this year

Cloudflare explains BGP route leak incident on January 22

Phishers abuse SharePoint in new campaign targeting energy firms

Cybersecurity — January 24, 2026 | Briefing24