THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Ransomware gangs exploit critical SmarterMail flaw (CVE-2026-24423)

Attackers are actively exploiting a new SmarterMail vulnerability to gain remote code execution, with incidents escalating to ransomware deployment. CISA added CVE-2026-24423 to its Known Exploited Vulnerabilities list after previously flagging two other SmarterMail bugs, signaling concerted targeting of the platform. Organizations should patch immediately, isolate exposed SmarterMail instances, and review logs for suspicious uploads or authentication bypass activity.

Source: HelpNet Security


Poland’s energy control systems breached via exposed VPN access

Coordinated cyberattacks on December 29 targeted Polish wind and solar farms, a CHP plant, and a manufacturer, with CERT Polska assessing a single destructive actor was responsible. While power generation wasn’t impacted, investigators found initial access hinged on exposed VPNs—a reminder that unmanaged remote access remains a prime vector into OT/ICS environments.

Source: HelpNet Security


CISA orders US agencies to remove unsupported edge devices

A new binding operational directive compels federal agencies to inventory and replace end-of-life edge devices—firewalls, load balancers, VPNs, routers, and similar gear—that no longer receive security updates. The move aims to reduce technical debt and close high-value ingress points routinely abused in real-world intrusions, with agencies given roughly 12–18 months to comply.

Source: HelpNet Security


Compromised dYdX npm/PyPI packages push wallet stealers and RATs

Legitimate dYdX client libraries on npm and PyPI were tampered with to distribute malware that can exfiltrate wallet credentials and enable remote code execution. The supply chain attack underscores the need for strict package pinning, integrity verification, and immediate rotation of compromised tokens and API keys in developer environments.

Source: TheHackerNews


China-linked ‘DKnife’ AitM toolkit targets routers and edge devices

Researchers detailed DKnife, a gateway-monitoring and adversary-in-the-middle framework with seven Linux implants capable of deep packet inspection, traffic manipulation, and on-path malware delivery. Active since at least 2019 and linked to China-nexus actors, DKnife highlights the strategic value of compromised routers and edge appliances in hijacking traffic and staging follow-on attacks.

Source: TheHackerNews


State-aligned espionage group breaches 70 orgs across 37 countries

Palo Alto Networks Unit 42 tracked an Asian state-backed operation, TGR-STA-1030, compromising at least 70 government and critical infrastructure entities and probing 155 more. Victims include national police, border control, parliaments, and telecoms, signaling broad objectives and sustained reconnaissance against high-value public-sector networks.

Source: TheHackerNews


Global DNS hijacking campaign abuses old, unsupported home routers

A widespread DNS hijacking operation is redirecting users via outdated consumer routers that no longer receive security updates. The campaign reinforces the risk posed by legacy SOHO devices to enterprise security—especially for remote workers—necessitating enforced DNS security controls, router refresh programs, and outbound DNS monitoring.

Source: SCMagazine


You May Also Be Interested In...

Apple Pay phish uses fake support calls to steal payment details

Google patches RCE, internal database leak flaws in Looker

State-backed phishing attacks targeting military officials and journalists on Signal

Cybersecurity — February 7, 2026 | Briefing24