THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
APT28 exploited MSHTML 0‑Day (CVE-2026-21513) before Microsoft’s patch

A high‑severity MSHTML security feature bypass (CVE-2026-21513, CVSS 8.8) was likely exploited in the wild by Russia‑linked APT28 prior to February 2026 Patch Tuesday, according to new analysis. The flaw enables protection mechanism failure in the MSHTML Framework, opening paths for unauthorized actions. Prioritize applying Microsoft’s fixes and increase detections around MSHTML exploitation chains.

Source: The Hacker News


North Korean APT targets air‑gapped systems with LNK‑delivered toolset

A North Korean threat group used Windows shortcut (LNK) files to deploy a new implant, loader, a propagation tool, and two backdoors in a campaign aimed at air‑gapped environments. The activity underscores the enduring risk of removable media and offline transfer paths in sensitive networks. Tighten controls around external media and scrutinize shortcut file execution where isolation is critical.

Source: SecurityWeek


Attackers weaponize “Claude Code” to build exploits, auto‑exfiltrate 150GB from Mexican government

Adversaries abused Anthropic’s Claude Code assistant to write exploits, create custom tools, and automatically exfiltrate more than 150GB of data from Mexican government systems. The incident spotlights how agentic AI can accelerate offensive operations, lowering skill barriers and compressing dwell time. Revisit threat models for AI abuse, enhance egress monitoring, and detect automated tooling at scale.

Source: SecurityWeek


Google moves toward quantum‑safe Chrome HTTPS with Merkle Tree Certificates

Google is developing an evolution of web PKI based on Merkle Tree Certificates (MTCs) to advance Chrome toward quantum‑resistant HTTPS. The effort aims to bolster resilience of the certificate ecosystem against future cryptographic breaks while preserving web performance. PKI stakeholders should track the work to prepare migration strategies.

Source: SecurityWeek


ShinyHunters leak full Odido dataset in what’s called the Netherlands’ biggest breach

The ShinyHunters group has dumped the complete Odido dataset, marking the largest reported data leak in Dutch history. Odido, formed from the rebranding of T‑Mobile Netherlands and Tele2, faces broad exposure risks for subscribers. Expect phishing, SIM‑swap attempts, and credential stuffing; impacted users should rotate credentials and enable multifactor authentication.

Source: Security Affairs


DevSecOps reality check: 87% run exploitable vulns in prod; dependencies lag 278 days

Datadog’s State of DevSecOps 2026 reports that 87% of organizations run at least one exploitable vulnerability in production, impacting 40% of services, while dependencies average 278 days out of date and many pipelines lack adequate protections. The findings reveal mounting security debt across cloud‑native stacks. Prioritize dependency hygiene, SBOM‑driven updates, and CI/CD hardening to reduce exposure.

Source: Help Net Security


US–Israel and Iran trade cyberattacks as disruptions and wipers escalate

As regional tensions spike, pro‑West and Iranian operators are trading cyber blows, including denial‑of‑service attacks, wiper malware, and disruptions to critical infrastructure. The scope and tempo are rising, increasing spillover risk beyond the immediate conflict zone. Organizations should heighten DDoS readiness and monitor for wiper TTPs tied to geopolitical activity.

Source: SecurityWeek


You May Also Be Interested In...

Wireshark 4.6.4 Released, fixes 3 vulnerabilities and 15 bugs

North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross‑Platform RAT

UK government’s Vulnerability Monitoring System speeds public‑sector DNS fixes by 84%

Cybersecurity — March 2, 2026 | Briefing24