THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Chrome ships device-bound session credentials to blunt cookie theft

Google is rolling out Device Bound Session Credentials in Chrome, cryptographically tying session tokens to the device so stolen cookies are useless to attackers. The control directly targets the booming infostealer-to-AiTM ecosystem and is publicly available for Windows in Chrome 146, with macOS support to follow. Enterprises should pilot DBSC with critical web apps and SSO flows, and plan for policy-based rollout.

Source: SecurityWeek


Adobe Reader zero‑day leveraged in months‑long campaign

Researchers flagged an actively exploited, still-unpatched Adobe Reader vulnerability after a malicious PDF sample surfaced, prompting a community call to analyze the exploit chain. The campaign underscores the enduring risk of weaponized PDFs and the need to harden document workflows (disabling risky features, tightening EDR rules) while preparing for rapid patch deployment once fixes arrive.

Source: SC Magazine


Vulnerability in EngageLab SDK exposed millions of Android crypto wallet users

A critical flaw in the EngageLab SDK could let apps bypass Android’s sandbox, exposing private data and impacting apps with 50+ million installs, including crypto wallets totaling over 30 million downloads. The vendor has addressed the issue; developers must update to patched SDK versions and republish apps, and users should apply app updates promptly.

Source: SecurityWeek


SEO poisoning of “Office 365” searches leads to paycheck redirection

Microsoft tracks Storm‑2755, a financially motivated group abusing poisoned search results and malicious ads for “Office 365” to funnel victims to lookalike portals and intercept credentials via AiTM. The operators then covertly reroute salary payments to attacker-controlled accounts. Defenders should tighten payroll change controls, favor phishing-resistant MFA, and consider safe browsing controls to reduce malvertising exposure.

Source: Help Net Security


Trusted download site CPUID briefly hijacked to deliver malware

Attackers compromised CPUID’s backend for roughly six hours, turning links for popular tools like CPU‑Z and HWMonitor into a chance of receiving credential‑stealing malware. The incident highlights how fast-moving website compromises can convert trusted utilities into software supply chain threats; users should verify signatures and hashes and reimage any system that executed suspect binaries.

Source: The Register


Adtech‑powered “Webloc” enabled mass device tracking by law enforcement

Citizen Lab research attributes the use of a global ad‑based geolocation system called Webloc to agencies in Hungary, El Salvador, and several U.S. departments, enabling tracking of up to 500 million devices. The findings intensify scrutiny on the adtech data supply chain and its exploitation for surveillance, raising urgent questions for regulators and enterprises about SDK usage, mobile telemetry, and data brokering.

Source: The Hacker News


US warns Iran‑linked actors are manipulating PLCs and SCADA in critical infrastructure

Federal agencies cautioned that Iranian threat groups are actively targeting programmable logic controllers and SCADA systems to cause disruption, prompting industry calls to accelerate OT segmentation and remove direct internet exposure. The advisory reinforces long‑standing concerns about insecure-by-design OT and the need for continuous monitoring, access hardening, and vendor patching programs tailored to industrial environments.

Source: SecurityWeek


You May Also Be Interested In...

Marimo RCE flaw exploited within 10 hours of disclosure

Just 21 IP addresses are behind nearly half of all RDP scanning

Fake Claude site pushes trojanized app and PlugX malware

Cybersecurity — April 11, 2026 | Briefing24