THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China-nexus ‘DKnife’ AitM framework targets gateways with seven Linux implants

Cisco Talos disclosed DKnife, a fully featured gateway-monitoring and adversary‑in‑the‑middle framework with seven Linux-based implants attributed to a China-linked actor. The tooling focuses on edge visibility and traffic interception, and related reporting indicates activity dating back to at least 2019 and spanning desktop, mobile, and IoT ecosystems. Defenders should harden and monitor edge appliances, validate firmware integrity, and lock down certificate/trust and management access paths.

Source: Cisco Talos


CISA: VMware ESXi arbitrary write flaw now leveraged by ransomware

The VMware ESXi vulnerability CVE-2025-22225 has been confirmed in active ransomware campaigns and added to CISA’s Known Exploited Vulnerabilities catalog. Part of a trio of ESXi bugs patched in early 2025, the flaw enables arbitrary writes that can be chained for code execution. Urgently patch ESXi/Workstation/Fusion, restrict management interfaces, and hunt for post-exploitation activity.

Source: Help Net Security


Federal purge of unsupported edge gear: CISA orders removal of end‑of‑life devices

CISA issued a new operational directive requiring federal agencies to identify and remove end-of-life hardware and software—especially at the edge—citing active exploitation. The mandate tightens asset inventories and sets deadlines to rip and replace unsupported devices, shrinking a high-risk attack surface. Private-sector organizations should mirror this posture by accelerating tech refresh and enforcing OEM support baselines.

Source: Recorded Future News


Critical n8n sandbox escape (CVE-2026-25049) enables server-side command execution

A maximum‑severity expression sandbox escape in the n8n open-source automation/AI workflow platform allows attackers with workflow access to execute arbitrary commands on the host. Because n8n often orchestrates secrets and AI agent actions across systems, exploitation risks full server takeover and credential compromise. Patch immediately and review workflow permissions, network egress, and stored credentials.

Source: SecurityWeek


Decade-old EnCase driver resurfaces as an “EDR killer” for 59 security products

Huntress reported adversaries abusing a long‑revoked EnCase kernel driver to terminate or disable 59 endpoint security tools, despite the certificate’s expiration more than a decade ago. The BYOVD technique persists because Windows still allows the driver to load under certain conditions. Organizations should enable driver blocklists (e.g., HVCI/WDAC), review kernel-mode load policies, and monitor for suspicious driver loads.

Source: Help Net Security


Record 31.4 Tbps DDoS attack caps a year of hyper‑volumetric assaults

Cloudflare’s Q4 2025 report details a 31.4 Tbps, 35-second HTTP DDoS attack attributed to AISURU/Kimwolf and a 700% surge in hyper‑volumetric network‑layer events year over year. The data underscores attacker pivot to short, massive bursts designed to outpace capacity and scrubbing. Enterprises should adopt always‑on mitigation, anycast architectures, adaptive rate controls, and automated playbooks.

Source: Cloudflare


Global cyberespionage compromises governments and critical infrastructure in 37 countries

Research tracked compromises at least across 70 institutions in 37 nations, with evidence pointing toward a China-aligned operation. Victims include government bodies and critical infrastructure, with intruders maintaining access for months. The campaign highlights sustained APT persistence—bolster segmentation, enforce strong identity controls, and prioritize long‑dwell detection and threat hunting.

Source: SecurityWeek


You May Also Be Interested In...

Cybersecurity — February 6, 2026 | Briefing24