THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical MikroTik SSH Authentication Bypass: Assume Compromise, Hunt for Backdoors

MikroTik has released a patch for a vulnerability that enables an SSH authentication bypass, and security reporting indicates it is already under active exploitation. If your MikroTik RouterOS instance is internet-exposed on SSH, the guidance is effectively to treat the device as compromised until proven otherwise. Beyond patching, responders should also check for persistence—attackers are reported to add new accounts to maintain access after remediation.

Source: SANS ISC


Attackers Abuse N-able N-central Hotfix 4: Pre-Auth RCE Remains a Priority for Patch Management

N-able issued a fourth hotfix in five weeks for its N-central RMM platform, addressing an unauthenticated (pre-auth) RCE flaw. The advisory notes the vulnerability has been exploited in the wild, though release notes indicate exploitation status is not fully confirmed. This is a clear reminder that RMM products remain high-value targets and that “time-to-hotfix” is now a core security metric.

Source: The Hacker News


ConnectWise ScreenConnect File Transfer Flaw: CVE and Fix Expected Soon—Prepare for Elevated MSP Risk

ConnectWise has confirmed a file transfer flaw in ScreenConnect that affects both cloud and on-premises deployments, and it said a CVE identifier and official fix will be published within the week. ScreenConnect is widely used by IT teams and managed service providers, meaning exploitation can quickly translate into broad access across multiple customer environments. Security teams should inventory ScreenConnect instances immediately and be ready to apply mitigations the moment the patched guidance drops.

Source: Help Net Security


JSCeal Steals Sessions to Bypass Google Authentication

Researchers detailed JSCeal, a sophisticated V8 JavaScript malware that can harvest credentials and surveillance data, including the ability to bypass Google authentication using stolen session cookies. Instead of relying only on password theft, session hijacking can be especially damaging because it may allow continued access even after some user-side resets. Organizations should focus on detection of suspicious web activity, anomalous session behavior, and rapid incident response for affected browser sessions.

Source: The Hacker News


Claude Account Takeovers: Infostealer Hijacks Login Sessions, Forcing Lockouts

Reports indicate Anthropic has started locking out Claude users because login sessions appear to have been compromised via infostealer malware. Session hijacking shifts the threat model from “credential stuffing” to “session persistence,” where attackers can maintain access until the provider intervenes. Users and security teams should treat unexpected account lockouts or strange activity as a potential endpoint and identity compromise indicator.

Source: Help Net Security


Berlin Ransomware Leak: Six Terabytes of State and Defense Data Released

After refusing a ransom demand, the Berlin-related incident escalated as attackers reportedly leaked roughly 6TB of sensitive administration and national defense data. For defenders, the key takeaway is that “no payment” does not mean “no incident,” and data-exfiltration containment must be treated as urgent even when negotiations fail. Organizations with government or critical services exposure should validate backups, confirm scope of exfiltration, and accelerate monitoring for follow-on leaks or targeted disclosures.

Source: Security Affairs


You May Also Be Interested In...

The Hidden Risks of Shadow AI (NCSC)
ToolHive: The open-source way to run any MCP server securely
UK Cyber Bill Accountability Debate: Why Exec Personal Liability Is Missing

Cybersecurity — September 7, 2026 | Briefing24