THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Notepad++ supply chain hack conducted via hosting provider, likely China

The maintainer of Notepad++ disclosed that state-sponsored attackers compromised its hosting provider and redirected software update traffic to malicious servers. The intruders appear to have maintained access for months and selectively targeted certain customers, with no vulnerability found in Notepad++ itself. The incident underscores how third-party infrastructure compromises can subvert trusted update channels.

Source: SecurityWeek


eScan antivirus update servers compromised to deliver multi-stage malware

Unknown attackers hijacked eScan’s legitimate update infrastructure to push a persistent downloader to enterprise and consumer systems. The campaign used malicious updates to initiate a multi-stage infection chain, highlighting the growing risk of supply-chain abuse within security products themselves. Organizations should review endpoint telemetry for anomalous update behavior and follow vendor guidance.

Source: The Hacker News


Open VSX Registry attack used a compromised dev account to spread ‘GlassWorm’ via extensions

On January 30, threat actors took over a legitimate developer’s Open VSX account and published malicious versions of four established extensions embedding the GlassWorm malware. Because the packages appeared trusted, downstream users were exposed via normal update flows. The incident reinforces the need for strict publisher verification, pinned versions, and extension allowlists in dev environments.

Source: The Hacker News


Over 1,400 exposed MongoDB databases ransacked by a single threat actor

Researchers found 3,100 unprotected MongoDB instances online; roughly half had already been compromised, most by one attacker. The wave of breaches shows how quickly misconfigured databases are discovered and abused at Internet scale. Immediate actions include removing public exposure, enforcing authentication, and enabling backups and audit logging.

Source: SecurityWeek


Microsoft moves to disable NTLM by default in upcoming Windows and Windows Server

The next major Windows and Windows Server releases will ship with the long-deprecated NTLM authentication protocol disabled by default. Enterprises relying on NTLM should inventory legacy dependencies, test Kerberos/Negotiate scenarios, and mitigate relay risks before the change arrives. The shift is a significant step toward hardening identity across Windows estates.

Source: SecurityWeek


NSA releases phased Zero Trust implementation guidance aligned to DoD maturity model

The NSA published Phase One and Phase Two Zero Trust Implementation Guidelines, mapping 36 activities to 30 capabilities to help organizations sequence real-world deployments. The documents aim to translate framework principles into actionable steps across identity, network, data, and application domains, closing gaps between policy and enterprise reality.

Source: Help Net Security


ShinyHunters reportedly breached Bumble, OkCupid, and others via phone-based social engineering

The ShinyHunters group allegedly gained access to major brands by calling employees and persuading them to grant or reset access to cloud systems. The incidents highlight the continued effectiveness of vishing against help desks and internal support workflows, and the importance of call-back verification, strong MFA, and strict change-control procedures.

Source: CyberNews


You May Also Be Interested In...

AI is flooding IAM systems with new identities

Open-source AI pentesting tools are getting uncomfortably good

How fake party invitations are being used to install remote access tools

Cybersecurity — February 2, 2026 | Briefing24