THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
APT28 rapidly exploits new Microsoft Office flaw (CVE-2026-21509)

Russian state-sponsored hackers (Fancy Bear/APT28) are actively exploiting a newly patched Microsoft Office vulnerability that bypasses OLE mitigations via booby-trapped Office files. Researchers observed phishing activity just days after Microsoft’s emergency fix; organizations should patch immediately, enforce Protected View, and limit macro execution to reduce risk.

Source: Help Net Security


CISA orders urgent fixes for actively exploited SolarWinds Web Help Desk RCE

Federal agencies were directed to patch CVE-2025-40551—a critical (CVSS 9.8) flaw in SolarWinds Web Help Desk—by Friday after evidence of in-the-wild exploitation. The ITSM platform’s wide footprint makes this a high-risk enterprise target; organizations should apply vendor updates, restrict WHD exposure, and monitor for suspicious deserialization activity.

Source: Recorded Future News


Notepad++ supply-chain attack tied to Lotus Blossom; new IoCs published

Researchers linked the hijacking of Notepad++’s update delivery infrastructure to China-nexus group Lotus Blossom, detailing previously unseen infection chains using DLL sideloading and Cobalt Strike. Targeting spanned multiple countries and sectors; defenders should ingest the latest IoCs, verify update signatures, and reassess trust in auto-update infrastructure.

Source: Help Net Security


React2Shell attacks surge: 1.4M exploit attempts dropping cryptominers and reverse shells

Exploitation of the React Native Metro server vulnerability (CVE-2025-11953) accelerated, with two IPs responsible for most of 1.4 million observed attempts in the past week. Attackers are deploying cryptominers and establishing remote shells; teams should upgrade affected packages, block external exposure of dev servers, and add WAF/network controls.

Source: SecurityWeek


AI agent platforms under fire: bot-to-bot prompt injection and data leaks on Moltbook

Security analysis of the Moltbook agent network found serious flaws enabling bot-to-bot prompt injection, data exposure, and misuse of agent-to-agent trust. As agent ecosystems proliferate, security teams should minimize agent permissions, isolate execution environments, validate tool outputs, and log/monitor agent interactions for abuse.

Source: SecurityWeek


Docker AI assistant flaw (DockerDash) allowed RCE and sensitive data theft

A critical issue in Docker’s Ask Gordon AI (the MCP Gateway trust model) let instructions pass without validation, enabling code execution and exfiltration. Patches are available; developers should update Docker Desktop/CLI, review agent permissions, rotate credentials/tokens, and consider disabling AI features where not required.

Source: SecurityWeek


Ivanti EPMM hit by mass exploitation of two zero-days

Following limited pre-disclosure activity, multiple threat groups began mass exploiting two critical Ivanti Endpoint Manager Mobile zero-days, with over 1,400 instances still exposed. Organizations should patch immediately, restrict management interfaces, increase EDR telemetry on MDM infrastructure, and hunt for post-exploitation indicators.

Source: CyberScoop


You May Also Be Interested In... White House drafting AI security policy framework (ONCD)
CISA says CIRCIA cyber reporting update is weeks away
NSA releases phased guidance for Zero Trust adoption
Cybersecurity — February 4, 2026 | Briefing24