THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft patches high‑severity SharePoint RCE (CVE-2026-45659) — patch now

Microsoft fixed a remote code execution flaw in SharePoint caused by deserialization of untrusted data that can be exploited by an authenticated attacker with low complexity and no user interaction. The bug impacts SharePoint Server Subscription Edition, 2019, and 2016 — enterprises should prioritize patching due to broad deployment and likely rapid exploit development.

Source: Help Net Security


Trend Micro Apex One zero‑day actively exploited; CISA issues warning (CVE-2026-34926)

A path traversal vulnerability in Trend Micro’s Apex One endpoint platform has been exploited in the wild, with Trend noting observed attempts and CISA flagging urgent risk. Organizations should apply available updates immediately, review Apex One telemetry for suspicious file paths, and harden EDR management interfaces.

Source: Help Net Security


FBI flags Kali365 kit abusing Microsoft’s device code flow to steal tokens — no password needed

A phishing-as-a-service called Kali365 abuses Microsoft 365’s OAuth device code flow to obtain access tokens after victims complete MFA on legitimate Microsoft pages. Because MFA fires on the victim’s device, not the attacker’s, defenders should restrict device code flow via Conditional Access, monitor refresh-token usage, and enforce out‑of‑band verification for resets.

Source: Bitdefender Hot for Security


CISA urges immediate patching of exploited LiteSpeed cPanel plugin zero‑day

An already-resolved flaw in the LiteSpeed cPanel plugin was exploited as a zero‑day to execute scripts with root privileges on Linux servers. Hosting providers and site operators should update the plugin without delay and review systems for signs of post‑exploitation persistence.

Source: SecurityWeek


700+ education and tech sites hijacked via Ghost CMS flaw to push “ClickFix” malware

Attackers abused a Ghost CMS vulnerability to compromise hundreds of legitimate sites, serving fake Cloudflare verification pages that pressure users into installing malware. The campaign blends SEO and brand impersonation; organizations should patch Ghost CMS, audit themes/plugins, and warn users against unexpected “verification” prompts.

Source: Malwarebytes Labs


LA Metro breach linked to Iranian state‑sponsored infrastructure

An attack initially claimed by a hacktivist persona has been tied to infrastructure used by Iranian government threat actors, underscoring ongoing risks to U.S. critical services. The incident reportedly took weeks to recover from, highlighting the operational impact when transit and public systems are targeted.

Source: SecurityWeek


Google TIG: Chinese‑language phishing‑as‑a‑service ecosystems surge

Google’s Threat Intelligence Group reports mature Chinese‑language PhaaS offerings increasingly rival traditional Russian‑language markets, largely targeting non‑Chinese entities. Services marketed via Telegram bundle kits, hosting, and support, signaling broader accessibility and scale for credential theft operations.

Source: Help Net Security


You May Also Be Interested In... Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
Drupal SQL injection CVE-2026-9082 added to CISA KEV amid active attacks
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems
Cybersecurity — May 27, 2026 | Briefing24