THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Emergency patch now: Ivanti EPMM zero‑days actively exploited (CVE‑2026‑1281, CVE‑2026‑1340)

Ivanti disclosed two pre‑auth code injection flaws in Endpoint Manager Mobile that allow remote arbitrary command execution, with exploitation observed before disclosure. CISA added CVE‑2026‑1281 to the KEV catalog with a 3‑day remediation deadline, and a public PoC is available—raising mass exploitation risk. Organizations should apply the vendor’s RPM patches on an emergency basis, hunt for hits to the “/mifs/c/(app|aft)store/fob/” endpoints, and restrict access until updated.

Source: Rapid7


Russia-linked Sandworm bricked ICS devices in coordinated strike on Polish energy sites

Investigators say Sandworm/Electrum targeted communication and control systems across more than 30 sites, leaving industrial devices inoperable. The incident underscores persistent OT exposure to basic weaknesses and the cascading impact when operator visibility is lost. Asset inventory, network segmentation, default-credential eradication, and tested incident playbooks remain critical for grid resilience.

Source: SecurityWeek


ShinyHunters expands to vishing-fueled SaaS data theft and aggressive extortion

Mandiant reports clusters tied to ShinyHunters are impersonating IT, driving targets to credential-harvesting sites, enrolling rogue MFA devices, and raiding cloud apps like SharePoint, Slack, Salesforce, and DocuSign. Operators have escalated to harassment and DDoS to pressure victims, while deleting security emails to hide traces. This is not a vendor flaw—shift to phishing‑resistant MFA (FIDO2/passkeys), harden help‑desk workflows, and tighten IdP and SaaS logging and detections.

Source: Google Cloud Threat Intelligence


Report finds 175,000 internet‑exposed Ollama AI servers at risk of abuse

Researchers identified a vast population of exposed Ollama instances—23,000 of which consistently accounted for most observed activity—potentially enabling model misuse, data exfiltration, or pivoting. Administrators should require authentication, restrict network access, and avoid exposing management endpoints to the public internet.

Source: SecurityWeek


Hugging Face abused to deliver Android RAT via malicious apps

Attackers lured users to Android apps that fetched a remote payload hosted in a Hugging Face repo, turning the AI ecosystem into a malware delivery channel. The campaign highlights the risks of sideloaded apps and supply‑chain trust in public model/code repositories. Mobile fleets should disable unknown sources and monitor DNS/HTTP egress for unusual repository fetches.

Source: SecurityWeek


OpenSSL fixes 12 flaws, including a high‑severity RCE—update widely

The OpenSSL project patched a dozen issues spanning memory safety and parsing problems, with one remote code execution bug rated high severity. Given OpenSSL’s ubiquity in servers, containers, appliances, and SDKs, organizations should fast‑track updates across distributions and vendor firmware to reduce exposure.

Source: SC Media


Ex‑Google engineer convicted for stealing AI trade secrets for China

A federal jury found Linwei “Leon” Ding guilty on seven counts of economic espionage and seven counts of trade‑secret theft tied to Google’s AI technology, exposing ongoing insider risks around high‑value models and tooling. The case reinforces the need for least‑privilege access, source‑code governance, DLP, and robust insider‑threat programs across AI R&D.

Source: Help Net Security


You May Also Be Interested In...

White House scraps ‘burdensome’ software security rules

Google disrupts IPIDEA residential proxy network used in cybercrime

CISA issues insider threat guidance amidst AI misuse concerns

Cybersecurity — January 31, 2026 | Briefing24