THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Fortinet patches actively exploited FortiCloud SSO authentication bypass (CVE-2026-24858)

Fortinet released emergency fixes for a critical FortiCloud SSO authentication bypass that attackers were already exploiting to access devices tied to other FortiCloud accounts. The company temporarily disabled FortiCloud SSO and blocked abused accounts during the response, and urges customers to update immediately. Security teams should review access logs for anomalous SSO activity and enforce MFA on all administrative access.

Source: SecurityWeek


SolarWinds Web Help Desk: multiple critical flaws allow unauthenticated RCE and auth bypass

SolarWinds shipped updates for Web Help Desk that fix four critical vulnerabilities enabling unauthenticated remote code execution and authentication bypass, plus two high-severity issues. Researchers expect rapid exploit development; administrators should upgrade to WHD v2026.1 without delay and restrict external exposure of management interfaces.

Source: Help Net Security


APTs and cybercriminals are still abusing WinRAR CVE-2025-8088

Despite a patch landing over six months ago, state-backed and financially motivated actors continue exploiting a critical WinRAR path traversal bug to plant malware, often by hiding payloads in archives and dropping files into Windows Startup. Organizations should ensure WinRAR is updated across fleets, harden file-handling policies for archive formats, and monitor for suspicious archive extraction behavior.

Source: SecurityWeek


Google disrupts IPIDEA, one of the world’s largest residential proxy networks

Google and partners took legal and technical action to dismantle the IPIDEA proxy ecosystem, taking down C2 domains and removing apps embedding its SDKs via Play Protect—reducing the pool of hijacked devices by millions. Residential proxies were used by hundreds of threat groups for obfuscation and botnets, and can expose home networks of unwitting users. Enterprises should block known proxy exit nodes and scrutinize traffic originating from consumer IP space.

Source: Google Cloud Blog


OpenSSL patches 12 vulnerabilities, including high-severity remote code execution

The OpenSSL project fixed a dozen issues uncovered by a single research team, with one high-severity flaw that could enable remote code execution under specific conditions. Given OpenSSL’s ubiquity, teams should inventory dependencies, apply the latest releases, and recompile affected software to mitigate exposure.

Source: SecurityWeek


Open-source malware increasingly targets developer environments

Sonatype reports more than 450,000 malicious open-source components identified in 2025, with attacks increasingly focused on executing code within developer machines, build pipelines, and tooling. Campaigns scaled through public registries and batch publishing, underscoring the need for package allowlists, provenance controls, and pre-ingest scanning in software supply chains.

Source: Help Net Security


GhostChat Android spyware spreads via fake romance lures in Pakistan

ESET researchers uncovered a targeted Android spyware campaign using a sham dating/chat app that routes conversations through WhatsApp while quietly exfiltrating data from infected devices. Tracked as GhostChat, the operation appears linked to a broader surveillance effort. Users should avoid sideloaded apps and organizations should enforce mobile threat defense on BYOD and COPE devices.

Source: Help Net Security


You May Also Be Interested In...

FBI seizes RAMP cybercrime forum, disrupting ransomware marketplace

France to replace Zoom and Microsoft Teams in public administration over security concerns

Two high-severity n8n flaws allow authenticated remote code execution

Cybersecurity — January 29, 2026 | Briefing24