THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
CISA warns FileZen users: actively exploited command injection bug (CVE-2026-25108)

CISA added an OS command injection flaw in Soliton Systems’ FileZen secure file transfer appliance to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild abuse. Organizations should patch immediately, restrict internet exposure, rotate credentials/tokens used on affected systems, and review logs for suspicious post-authentication command execution.

Source: Help Net Security


Self-spreading npm malware hits developers in supply chain worm “SANDWORM_MODE”

Researchers uncovered 19 typosquatted npm packages that steal credentials, propagate across projects, poison AI assistants, and include a destructive “dead switch.” The incident underscores expanding attacker focus on developer environments—audit dependencies, revoke exposed tokens, enable package provenance/2FA, and quarantine build systems that touched affected packages.

Source: SecurityWeek


RoguePilot: Copilot/Codespaces tricked via GitHub Issues to seize repos

A vulnerability allowed attackers to hide prompt-injection instructions inside GitHub Issues that Copilot would follow when launching a Codespace, potentially leaking GITHUB_TOKEN and enabling repository takeover. Microsoft patched the issue; teams should treat AI assistants as ingesting untrusted content, tighten GitHub App/Codespaces permissions, and review audit logs and tokens.

Source: SecurityWeek


SolarWinds Serv-U: four critical flaws enable root-level remote code execution—patch now

SolarWinds released fixes for four critical Serv-U 15.5 vulnerabilities that could let remote attackers execute code as root. Given the long history of file transfer software abuse for initial access, organizations should apply updates urgently, limit exposure, monitor for anomalous file transfers, and review Serv-U service accounts and access controls.

Source: The Hacker News


Edge under fire: VPNs/routers absorb bulk of internet-wide exploitation attempts

GreyNoise telemetry shows nearly 3 billion malicious sessions over 162 days in H2 2025, with attackers concentrating on internet-facing VPNs, routers, and remote access services for initial footholds. Defenders should prioritize edge hardening: patch and replace end-of-life appliances, enforce MFA, disable unused services, rate-limit and geo-filter access, and continuously monitor for brute force and exploit traffic.

Source: Help Net Security


Lazarus Group deploys Medusa ransomware against healthcare and Middle East targets

Symantec and Carbon Black spotted North Korea’s Lazarus using Medusa ransomware following identity-focused intrusions, including an attempted hit on a U.S. healthcare organization. The blending of state-linked tradecraft with financially motivated extortion heightens risk to critical services—tighten identity controls (MFA, conditional access), segment backups offline, and hunt for beaconing and credential theft.

Source: The Hacker News


U.S. sanctions Russian zero-day broker tied to exploits stolen from L3Harris

The Treasury Department sanctioned a Russian exploit broker, its founder, and affiliates for acquiring proprietary cyber tools stolen from L3Harris and selling them to unauthorized buyers. The move spotlights an increasingly commercialized exploit market and the downstream risks when sensitive offensive tooling leaks—expect added scrutiny of exploit sourcing and tougher export and financial controls.

Source: TechCrunch


You May Also Be Interested In...

Airline brands become launchpads for phishing, crypto fraud

VMware Aria Operations flaws could allow remote code execution

Fake Zoom “update” silently installs surveillance software

Cybersecurity — February 25, 2026 | Briefing24