THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Global takedown shutters LeakBase credential-trading forum

Europol and partners from 14 countries dismantled LeakBase, a major open‑web marketplace for breached databases and “stealer logs,” seizing infrastructure and disrupting a community of more than 142,000 registered users. The forum served as a hub for account takeover and downstream intrusions; its removal will ripple across infostealer and credential-stuffing operations, at least temporarily increasing friction for buyers and sellers.

Source: Europol


Authorities pull plug on Tycoon 2FA phishing-as-a-service that helped bypass MFA at scale

Law enforcement and industry partners disrupted Tycoon 2FA, a subscription PhaaS that let criminals conduct adversary‑in‑the‑middle phishing to defeat multi‑factor authentication. Investigators say the kit was responsible for a large share of recent phishing attempts, underscoring the need for phishing‑resistant MFA (FIDO2/WebAuthn), conditional access, and hardened session token protections.

Source: Help Net Security


Android March patches fix 129 flaws, including an actively exploited Qualcomm bug

Google shipped fixes for 129 Android vulnerabilities, notably an in‑the‑wild exploit against a widely used Qualcomm component. Mobile fleets should prioritize this month’s updates via MDM, especially on devices with Qualcomm chipsets, to reduce exposure to targeted attacks already observed in the wild.

Source: Malwarebytes


Nation-state “Coruna” iOS exploit kit surfaces in broader campaigns; update to latest iOS

Researchers detailed Coruna, a powerful iOS exploit kit first tied to Russian state activity that packages 23 exploits across five chains targeting iOS 13–17.2.1. While ineffective against the latest iOS release, the kit’s migration into criminal operations raises the stakes for lagging devices—organizations should enforce rapid iOS updates and limit high‑risk browsing on unmanaged phones.

Source: SecurityWeek


VMware Aria Operations RCE (CVE-2026-22719) exploited in the wild; on CISA’s KEV list

A recently patched Aria Operations command injection flaw allows unauthenticated remote code execution and is now under active exploitation. Admins should apply Broadcom’s February 24 fix immediately, restrict management interfaces, and monitor for post‑exploitation activity, as CISA has added the bug to its Known Exploited Vulnerabilities catalog.

Source: SecurityWeek


Attackers abuse OAuth redirects from legit Microsoft/Google logins to phishing and malware

Researchers warn that adversaries are crafting OAuth URLs that intentionally trigger redirects from genuine Microsoft or Google login flows to malicious destinations. Because the journey starts on a trusted screen, users are more likely to comply—security teams should lock down redirect URIs, block open redirects, enforce PKCE, and train users to spot suspicious consent flows.

Source: Malwarebytes


Cisco Talos: China‑nexus UAT‑9244 hits South American telecoms with three new implants

Cisco Talos exposed UAT‑9244, assessed with high confidence as a China‑nexus APT linked to Famous Sparrow, targeting telecommunications providers in South America. The campaign debuted three previously unseen implants, signaling ongoing investment in bespoke tooling against critical infrastructure and reinforcing the urgency of robust segmentation, monitoring, and supply‑chain vetting in telco environments.

Source: Cisco Talos


You May Also Be Interested In...

Supreme Court to decide whether geofence warrants are constitutional
Cisco patches 48 vulnerabilities across ASA, Secure FMC, and Secure FTD
Hacktivist DDoS surges after Middle East conflict: 149 attacks across 16 countries
Cybersecurity — March 5, 2026 | Briefing24