THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Google patches actively exploited Qualcomm zero-day in massive Android update

Google’s March update fixes 129 Android vulnerabilities, including CVE-2026-21385, a Qualcomm graphics component bug confirmed to be exploited in the wild. It’s the largest monthly Android patch batch since 2018 and underscores the need to fast-track updates on fleet devices. Prioritize the March security patch levels across OEMs and tighten MDM/EDR monitoring for post-patch exploitation attempts.

Source: CyberScoop


Chrome flaw let malicious extensions hijack Gemini Live and exfiltrate local files

Google patched CVE-2026-0628, an insufficient policy enforcement bug that allowed extensions to take over Chrome’s Gemini Live side panel, spy on users, and steal local files. The issue has been fixed since early January, but impacted users may still have risky extensions installed. Audit and remove untrusted extensions, update Chrome, and enforce extension allowlists for managed endpoints.

Source: SecurityWeek


OpenClaw “ClawJacked” bug let websites seize AI agents via localhost brute force

A high-severity OpenClaw flaw enabled malicious sites to open a WebSocket to the local gateway, brute-force credentials, and commandeer AI agents for silent data theft. The issue is fixed in version 2026.2.26. Update immediately and isolate local agent ports, enforce strong credentials, and consider browser/network controls that block website access to localhost services.

Source: SecurityWeek


APT28 exploited MSHTML CVE-2026-21513 before February’s patch Tuesday

Russia-linked APT28 is tied to pre-patch exploitation of CVE-2026-21513, a high-severity MSHTML security feature bypass. The activity highlights continued targeting of legacy IE/MSHTML components to enable downstream code execution chains. Ensure February 2026 cumulative updates are applied, reduce MSHTML exposure, and monitor for suspicious HTML/Office document activity.

Source: The Hacker News


North Korean APT targets air‑gapped networks with LNK-based toolchains

A recent ScarCruft/APT campaign used Windows shortcut files to deploy a new implant, loader, a propagation utility, and two backdoors, explicitly aiming to reach air-gapped systems. The operation underscores persistent use of removable media and cloud dead drops to bridge offline environments. Lock down LNK execution, harden USB media policies, and scrutinize unusual file system and process activity on isolated hosts.

Source: SecurityWeek


UK NCSC urges immediate hardening amid risk of Iranian cyber spillover

Following escalation in the Middle East, the UK’s NCSC advises organizations to review and strengthen controls against likely Iranian-linked phishing, DDoS, and disruptive ops. Recommended actions include patching exposed services, enforcing MFA, rehearsing incident response, and elevating spear-phish detection. Expect opportunistic targeting and potential supply-chain or third-party exposure.

Source: NCSC UK


Microsoft warns of OAuth redirect abuse delivering malware to government targets

Ongoing phishing campaigns use OAuth consent prompts and URL redirection to bypass traditional email and browser defenses, landing victims on attacker infrastructure without stealing tokens. Government and public-sector entities are in scope. Tighten cloud app consent policies, restrict user-authorized apps, monitor risky OAuth grants, and use conditional access to constrain high-risk flows.

Source: The Hacker News


You May Also Be Interested In...

Google Working Towards Quantum-Safe Chrome HTTPS Certificates
Wireshark 4.6.4 Released
A fake FileZilla site hosts a malicious download
Cybersecurity — March 3, 2026 | Briefing24