THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Cisco FMC zero-day exploited in Interlock ransomware campaign

A critical remote code execution flaw in Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20131, was exploited as a zero-day since late January to obtain root on targeted devices. Researchers link the activity to the Interlock ransomware group, with evidence suggesting Russian connections. Organizations should patch immediately per Cisco guidance, restrict FMC exposure, audit for new admin users or rogue tasks, and review outbound connections from management appliances.

Source: Security Week


DarkSword: Full-chain iOS exploit kit adopted by multiple threat actors

Google’s Threat Intelligence Group detailed “DarkSword,” a JavaScript-based, full-chain iOS exploit kit leveraging six vulnerabilities (including three zero-days) to compromise iOS 18.4–18.7 devices. Commercial spyware vendors and suspected state actors deployed it via watering holes against users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Apple has patched the vulnerabilities (latest coverage in iOS 26.3); users should update immediately and consider Lockdown Mode for high-risk profiles.

Source: GoogleCloud TI


CISA: Recent SharePoint RCE actively exploited in the wild

CISA warned that Microsoft SharePoint CVE-2026-20963, a remote code execution bug patched in January, is now being exploited. Federal agencies and enterprises should prioritize patching, restrict internet exposure for collaboration servers, and hunt for post-exploitation indicators such as suspicious webshells, newly created app pools, or anomalous process chains on SharePoint hosts.

Source: Security Week


Ubuntu Desktop 24.04+ flaw enables local root via systemd timing issue

A high-severity vulnerability (CVE-2026-3888, CVSS 7.8) in default Ubuntu Desktop 24.04+ allows local attackers to escalate to root by abusing a systemd cleanup timing condition. While not remotely exploitable, the bug can lead to full system takeover on shared or multi-user machines. Apply available fixes and tighten local account controls in high-risk environments.

Source: TheHackerNews


North Korean remote IT workers infiltrate Western firms at scale

IBM X-Force and Flare outline how North Korean nationals, including elite operatives, are securing remote IT and contractor roles through standard hiring channels to generate revenue and gain corporate access. The scheme blends legitimate work with covert tasking, heightening insider and supply-chain risk. Organizations should strengthen identity verification, monitor contractor access, and enforce continuous authentication and behavioral analytics for remote workers.

Source: HelpNet Security


Apple rolls out “Background Security Improvements” to speed patches, fixes WebKit bug

Apple introduced lightweight Background Security Improvements for iOS/iPadOS/macOS to deliver rapid component patches between full releases, starting with a fix for WebKit CVE-2026-20643. The move shortens exposure windows for browser-engine flaws frequently targeted in drive-by attacks. Ensure Background Security Improvements are enabled across managed fleets and monitor for any temporary rollbacks due to compatibility.

Source: HelpNet Security


Rapid7: Exploitation windows are collapsing as attackers weaponize faster

Rapid7’s 2026 Global Threat Landscape Report finds confirmed exploitation of newly disclosed high-severity CVEs more than doubled in 2025, while median time from disclosure to KEV inclusion dropped to five days. Ransomware appeared in 42% of MDR investigations, identity abuse remained prevalent, and AI accelerated phishing and malware development. The report urges preemptive exposure reduction, hardened identity controls, protected edge infrastructure, and AI-enabled defense workflows to match attacker velocity.

Source: Rapid7


You May Also Be Interested In...

Samba 4.24.0 ships Kerberos hardening and a CVE fix for domain encryption defaults

Betterleaks: Open-source secrets scanner

Arcjet enables inline defense against prompt injection in production AI systems

Cybersecurity — March 19, 2026 | Briefing24