THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
BeyondTrust critical RCE (CVE-2026-1731) under active exploitation

Attackers began probing and exploiting internet-facing BeyondTrust Remote Support and Privileged Remote Access instances within hours of a public PoC release. Researchers report adversaries abusing pre-auth endpoints to extract tenant identifiers and establish WebSocket channels, enabling unauthenticated remote code execution. Patch immediately, remove public exposure where possible, and monitor for suspicious get_portal_info requests and unexpected WebSocket activity.

Source: Help Net Security


CISA adds exploited SolarWinds, Microsoft, Apple, Notepad++ flaws to KEV; patch deadlines loom

CISA added a fresh batch of actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including SolarWinds Web Help Desk, Microsoft Configuration Manager (a 2024 SQLi now being hit), Apple iOS, and Notepad++. Federal agencies must remediate by early March; enterprises should prioritize the same bugs given evidence of in-the-wild abuse.

Source: SC Media


Dutch carrier Odido discloses breach impacting roughly 6 million customers

Odido confirmed attackers accessed its customer contact system, exposing personal data such as names, addresses, and phone numbers for millions. While credentials and call content were not included, the dataset enables targeted phishing, account takeover social engineering, and potential SIM-swap attempts; customers should enable strong MFA and be alert to unsolicited requests.

Source: SecurityWeek


Credential-stealing Chrome extensions: how to find and remove them

Researchers identified 30 Chrome extensions siphoning user data, including emails and authentication tokens. Malwarebytes provides a practical walkthrough for auditing installed extensions, removing malicious add-ons, and locking down browser sync to prevent re-infection across devices—advice security teams can adapt into enterprise hardening guides.

Source: Malwarebytes Labs


Nation-state actors weaponize Gemini for reconnaissance; model IP under attack

Google’s threat teams report state-backed groups using Gemini for pre-attack reconnaissance and operational support, alongside a rise in model extraction (“distillation”) attempts aimed at stealing AI intellectual property. While frontier models weren’t breached, the trend highlights dual risks: adversary enablement via public AI and targeted theft of proprietary model capabilities.

Source: Security Affairs


Critical RCE in WPvivid Backup plugin (CVE-2026-1357) threatens WordPress sites

A 9.8‑severity flaw in the popular WPvivid Backup plugin allows unauthenticated remote code execution on vulnerable WordPress installations up to version 0.9.123. Website operators should update immediately, audit for unexpected admin users or webshells, and review access logs for exploitation attempts.

Source: SC Media


Impending DHS shutdown to furlough most of CISA, slowing key cyber initiatives

CISA expects to furlough much of its workforce if DHS funding lapses, with likely slowdowns to major efforts including the revamp of the national cyber incident reporting rule. Reduced staffing during an active exploitation cycle raises risk for federal defenders and may ripple into shared services, advisories, and coordination with critical infrastructure.

Source: Nextgov/FCW


You May Also Be Interested In...

CISA orders federal agencies to patch exploited SolarWinds, Apple, Microsoft bugs within weeks

New threat actor UAT-9921 deploys VoidLink to target tech and financial sectors

EU tech chief: Europe needs offensive cyber capabilities to deter adversaries

Cybersecurity — February 14, 2026 | Briefing24