THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Attackers are exploiting critical NGINX flaw “Rift” (CVE-2026-42945)

A newly disclosed critical NGINX vulnerability dubbed “NGINX Rift” is already being exploited in the wild, with researchers warning it can reliably trigger denial-of-service and potentially enable unauthenticated remote code execution via a crafted HTTP request. Given NGINX’s massive footprint across the internet, organizations should prioritize patching and consider temporary mitigations such as tightening exposure, applying WAF rules, and monitoring for anomalous traffic patterns.

Source: Help Net Security


Grafana confirms code theft via GitHub breach, refuses ransom

Grafana Labs said attackers accessed its GitHub environment and downloaded parts of its codebase, but the company declined to pay a ransom and reported no evidence of customer data compromise. With Grafana widely embedded in enterprise observability stacks, teams should track upstream advisories, review SBOMs and access policies, and watch for dependency or plugin updates tied to the incident.

Source: The Record


Mini Shai-Hulud supply-chain wave hits @antv packages to steal CI/CD secrets

The ongoing Mini Shai-Hulud campaign has compromised popular npm packages tied to the @antv ecosystem, including echarts-for-react, to harvest developer and CI/CD credentials and establish persistence. This is the latest phase of a multi-ecosystem supply-chain push; developers should audit recent installs, rotate tokens, disable package lifecycle scripts in CI by default, and pin to vetted versions.

Source: The Hacker News


CISA contractor exposed AWS GovCloud keys and internal build details on GitHub

A CISA contractor maintained a public GitHub repo that leaked credentials for highly privileged AWS GovCloud accounts along with internal build, test, and deployment details for CISA systems—an exposure experts called one of the most severe government data leaks in years. The incident underscores persistent “secrets sprawl” risks and the need for automated secret scanning, least-privilege design, and rapid key rotation playbooks.

Source: KrebsOnSecurity


INTERPOL’s Operation Ramz: 201 arrests in first regional MENA cybercrime crackdown

INTERPOL coordinated a 13-country operation across the Middle East and North Africa targeting phishing, malware, and online fraud infrastructure, leading to 201 arrests and hundreds more suspects identified. Large-scale seizures and victim notifications reflect growing cross-border capacity to disrupt cybercrime networks, with likely ripple effects on regional threat activity and tooling.

Source: SecurityWeek


New Windows “MiniPlasma” exploit revives an old CVE to gain SYSTEM privileges

A researcher released the “MiniPlasma” exploit, showing a 2020 Windows privilege escalation flaw believed to be fixed still grants SYSTEM access on fully patched Windows 11. With public PoC now available, defenders should harden local privilege pathways, monitor for suspicious token or service manipulation, and apply any vendor mitigations as they emerge.

Source: SecurityWeek


Critical bug exposes fleets of Universal Robots to command injection (CVE-2026-8153)

A command injection flaw in Universal Robots PolyScope 5 could let attackers execute OS commands, potentially compromising entire fleets of industrial robots. OT teams should prioritize vendor patches, segment robot networks from IT, enforce strict remote access controls, and monitor for abnormal robot behavior or unexpected command sequences.

Source: SecurityWeek


You May Also Be Interested In...

GitHub Actions workflow hijacked to steal CI/CD credentials

PoC released for ‘DirtyDecrypt’ Linux kernel privilege-escalation bug

Cisco Talos tracks BadIIS malware-as-a-service used by Chinese-speaking groups

Cybersecurity — May 19, 2026 | Briefing24