THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Cisco confirms critical 0‑day auth bypass under active exploitation

CISA has warned that a critical (10/10) Cisco authentication bypass vulnerability is being exploited in the wild, allowing attackers to downgrade or bypass security controls. Cisco has issued guidance and mitigations, with fixes expected or rolling out; organizations should immediately restrict access to management interfaces, apply Cisco’s recommended mitigations, and hunt for anomalous logins or configuration changes.

Source: Forbes Security


Thousands of public Google Cloud API keys expose access to Gemini endpoints

Researchers at Truffle Security found nearly 3,000 publicly exposed Google API keys (“AIza…”) embedded in client-side code that could be abused to authenticate to sensitive Gemini AI endpoints and access private data once relevant APIs are enabled. Teams should treat these keys as secrets: rotate any exposed keys, enforce referrer/IP restrictions and least-privilege scopes, and proxy sensitive requests through secured backends.

Source: TheHackerNews


CVE‑2025‑64328 mass‑exploited: 900 Sangoma FreePBX servers backdoored with web shells

Attackers have been exploiting a command injection flaw in Sangoma FreePBX since December 2025, leaving roughly 900 instances infected with persistent web shells. Admins should urgently patch to a fixed version, audit for web shells and unauthorized admin users, and rotate credentials and keys that may have been exposed.

Source: Security Affairs


Trojanized gaming utilities drop stealthy RAT via PowerShell and LOLBins, Microsoft warns

Microsoft researchers report threat actors are seeding trojanized gaming tools through browsers and chat platforms to deliver a remote access trojan. The campaign leans on PowerShell and living‑off‑the‑land binaries to blend in and employs Defender evasion tactics; restrict scripting where possible, monitor for unusual PowerShell activity, and only obtain game utilities from trusted publishers.

Source: Security Affairs


Canadian Tire breach impacts 38 million accounts

Canadian Tire disclosed that names, addresses, email addresses, phone numbers, and encrypted passwords were exposed in an October 2025 incident affecting 38 million accounts. Customers should reset passwords (and avoid reuse), enable MFA, and remain vigilant for targeted phishing; enterprises can expect credential stuffing attempts leveraging the stolen data.

Source: SecurityWeek


Krebs probes ‘Dort,’ alleged Kimwolf botnet boss behind DDoS, doxing, and swatting

KrebsOnSecurity examines public breadcrumbs around “Dort,” the controller of the Kimwolf botnet that coalesced after a disclosed vulnerability was weaponized. Since January, Dort has led sustained DDoS, doxing, email flooding, and even a swatting attack on a researcher—offering investigators fresh leads on the botnet’s infrastructure and operator persona.

Source: KrebsOnSecurity


Hacked prayer app pushes ‘surrender’ messages to Iranians in live psyops campaign

As strikes hit Tehran, Iranians received push notifications promising amnesty if they surrendered—apparently sent from a compromised prayer app. The incident underscores how mobile apps and push-notification keys can be hijacked for real‑time influence operations; developers should harden notification credentials with MFA and rotation, while users treat in‑app alerts during crises with caution.

Source: WIRED


You May Also Be Interested In...

ClawJacked flaw lets malicious sites hijack local OpenClaw AI agents via WebSocket

Check your Gmail account security now as hackers continue attacks

Iran plunges into ‘near‑total internet blackout’ amid regional strikes

Cybersecurity — March 1, 2026 | Briefing24