THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Emergency patch: Microsoft fixes actively exploited Office zero‑day (CVE-2026-21509)

Microsoft released out-of-band updates to address a security feature bypass in Office that attackers are actively exploiting. The flaw stems from reliance on untrusted inputs in security decisions and affects multiple Office versions, including Microsoft 365 Apps. Admins should apply the emergency updates or Microsoft’s mitigations immediately to reduce exposure to targeted attacks.

Source: HelpNet Security


Poland thwarts data‑wiping attacks on energy systems; Sandworm suspected

Poland said it repelled late-December attacks using new wiper malware that targeted two CHP plants and systems managing wind and solar generation. Investigators and outside researchers link the activity to Russia-aligned Sandworm, underscoring persistent OT/ICS targeting and the need for network segmentation, tested incident response, and offline backups.

Source: HelpNet Security


Door access systems at major firms exposed by 20+ Dormakaba flaws

Researchers disclosed more than 20 vulnerabilities in Dormakaba enterprise access control systems that could let attackers remotely unlock doors. Patches are available; organizations should update affected exos 9300-based systems, isolate controllers from the internet, and review audit logs for suspicious access events.

Source: SecurityWeek


OMB reverses federal software attestation order, pivots to SBOMs

The White House Office of Management and Budget rescinded a Biden-era universal software attestation requirement, allowing agencies to lean on software bills of materials instead. The shift could reduce compliance friction but raises questions about consistency in software assurance and how effectively agencies will validate SBOM data at scale.

Source: NextGov Cyber


Malicious VS Code ‘AI’ extensions with 1.5M installs exfiltrate developer code

Two Visual Studio Code extensions posing as AI coding assistants siphoned source code and sensitive data to servers in China, yet remained available in the official marketplace. Teams should inventory installed extensions, remove suspicious add-ons, restrict marketplace access, and rotate any credentials or tokens that may have been exposed.

Source: TheHackerNews


MCP’s insecure defaults widen AI agent risk as Clawdbot spreads

New research warns the Model Context Protocol shipped without mandatory authentication, leaving thousands of MCP servers exposed and several critical CVEs enabling code execution. With viral AI agents like Clawdbot riding MCP into enterprises, security teams should enforce OAuth 2.1, bind servers to localhost, require human approval for high‑risk actions, and inventory MCP exposure now.

Source: VentureBeat Sec


EU opens formal probe into X’s Grok over illegal sexual imagery risks

The European Commission launched a Digital Services Act investigation into whether X’s AI tool Grok adequately assessed and mitigated risks tied to illegal content, including manipulated sexually explicit images and potential CSAM. The case signals rising regulatory scrutiny on AI content generation and platform governance, with significant compliance and enforcement implications.

Source: HelpNet Security


You May Also Be Interested In...

Cybersecurity — January 27, 2026 | Briefing24