THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
PAN-OS GlobalProtect auth bypass (CVE-2026-0257) is being actively exploited

Rapid7 reports in-the-wild exploitation of Palo Alto Networks PAN-OS/Prisma Access when “authentication override” cookies are enabled and the same certificate is reused, allowing forged cookies to bypass VPN authentication. Though rated medium, the edge-facing nature and available proof-of-concept make this effectively critical—organizations should urgently patch, disable auth override, or use a dedicated certificate for cookies.

Source: Rapid7


Dutch police dismantle 17M-device botnet, seize 200 servers

The Dutch National Police and NCSC took down 200 command servers controlling a botnet comprising at least 17 million infected devices across PCs, phones, IoT, and routers. It’s one of the largest disruptions this year and should significantly blunt the botnet’s capacity for DDoS, credential stuffing, and proxy abuse.

Source: Help Net Security


FortiClient EMS flaw abused to push enterprise-wide infostealer

Attackers are exploiting FortiClient EMS (CVE-2026-35616) to deliver a broad-spectrum infostealer to managed endpoints, masquerading as a legitimate Fortinet update executed via VPN scripting workflows. Fortinet admins should patch EMS immediately, audit update scripts and logs for suspicious activity, and review endpoint telemetry for anomalous “update” executions.

Source: Help Net Security


Critical Gogs zero‑day enables RCE via malicious pull requests

A critical argument-injection vulnerability in Gogs (CVSS 9.4) allows authenticated attackers to achieve remote code execution by submitting pull requests with malicious branch names. With exploit code public and no fix yet available, organizations should restrict PRs to trusted collaborators, isolate CI/CD runners, and monitor for suspicious repository events.

Source: SecurityWeek


New “FROST” web tracking attack fingerprints users via SSD timing

Researchers showed websites can profile users by measuring Solid-State Drive access timing through the browser’s Origin Private File System (OPFS), enabling stealthy device fingerprinting dubbed FROST. Until browser mitigations arrive, limit high-risk web features in untrusted contexts, clear site data regularly, and consider hardened browser profiles for sensitive work.

Source: Help Net Security


Chrome 148 fixes 151 vulnerabilities, including critical RCE

Google shipped Chrome 148 with patches for 151 security issues, some critical and potentially exploitable for remote code execution. Enterprises should expedite browser updates across managed fleets and validate that any frozen/extended channels receive the applicable fixes.

Source: SecurityWeek


Executive Order 14390 signals tougher U.S. stance on cybercrime, bigger private‑sector role

The new EO emphasizes disruption of cybercriminal networks, expanded intelligence sharing, and victim restitution—shifting federal focus beyond government systems to citizen and business impacts. While not immediately regulatory, it raises expectations for enterprise cooperation, faster incident reporting, and demonstrable security governance.

Source: TechTarget | SearchSecurity


You May Also Be Interested In...
LinkedIn-themed phishing abuses Adobe’s A/B testing platform
ChatGPhish: ChatGPT web summaries abused for prompt-injection phishing
Phishers impersonate Signal Support to steal backup recovery keys
Cybersecurity — May 30, 2026 | Briefing24