THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Emergency fixes for Fortinet FortiClient EMS zero-day under active exploitation

Fortinet rushed out-of-band patches for CVE-2026-35616, a critical improper access control flaw in FortiClient Enterprise Management Server that allows unauthenticated remote code execution. The vulnerability has been exploited as a zero-day; organizations should patch immediately, restrict EMS exposure, and monitor for anomalous access to management APIs.

Source: SecurityWeek


Unpatched Windows “BlueHammer” zero-day leaked publicly, enables SYSTEM privileges

A disgruntled researcher published exploit details for a Windows privilege escalation flaw dubbed BlueHammer, allowing attackers to gain SYSTEM/admin rights with no vendor fix available yet. Until Microsoft issues a patch, defenders should tighten least-privilege, increase EDR scrutiny of token manipulation/privilege escalation behaviors, and prioritize rapid containment of suspicious local execution.

Source: CyberNews


Microsoft: Medusa ransomware operators weaponize fresh bugs to go from breach to ransomware in 24 hours

Microsoft warns that threat actor Storm-1175 runs high-tempo Medusa ransomware campaigns, rapidly exploiting newly disclosed vulnerabilities to gain initial access, exfiltrate data, and deploy ransomware within a day. The speed underscores the need for continuous attack surface monitoring, urgent patching of internet-facing services, and rehearsed containment playbooks.

Source: Microsoft Security Blog


Flowise AI platform hit by CVSS 10.0 RCE; 12,000+ exposed instances targeted

Attackers are actively exploiting CVE-2025-59528 in Flowise, an open-source AI agent builder, via a code injection bug in the CustomMCP node that leads to remote code execution. Impacted users should upgrade to patched versions immediately, lock down admin interfaces, and rotate any credentials or API keys that may have been accessed.

Source: The Hacker News


New “GPUBreach” Rowhammer attacks enable host takeover via Nvidia GPUs

Academic researchers detailed multiple GPU-focused Rowhammer variants (GPUBreach, GDDRHammer, GeForge) that can flip bits in GDDR6 memory to escalate privileges and, in some cases, fully compromise the CPU host. Given the prevalence of high-performance Nvidia GPUs in cloud and AI stacks, providers should track vendor guidance, prefer ECC memory where available, and isolate untrusted GPU workloads.

Source: The Hacker News


Supply chain alert: 36 malicious npm packages posed as Strapi plugins to steal creds and escape containers

Researchers found dozens of rogue npm packages impersonating Strapi plugins that executed reverse shells, harvested credentials, and attempted container escape—reportedly targeting Guardarian users among others. Teams should audit recent dependency changes, purge the listed packages, rotate secrets, and enforce package provenance controls in CI/CD.

Source: SecurityWeek


Hong Kong expands police powers to compel decryption, even for transiting travelers

Under revised National Security Law enforcement rules, Hong Kong police can require individuals to provide passwords or keys to unlock devices, potentially impacting travelers merely passing through the airport. Organizations should consider travel-ready devices with minimal data, strong full-disk encryption, and clear policies for cross-border data risk.

Source: Schneier on Security


You May Also Be Interested In...

Cybersecurity — April 7, 2026 | Briefing24