THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China‑Nexus “DKnife” AitM toolkit targets network gateways

Cisco Talos uncovered “DKnife,” a gateway‑monitoring adversary‑in‑the‑middle framework composed of seven Linux implants designed to persist on edge devices. The tooling enables traffic interception, credential theft, and covert monitoring—highlighting the strategic shift toward owning gateways to surveil and manipulate enterprise traffic. Defenders should harden and continuously monitor internet‑exposed appliances, enforce strong credentials, and baseline egress from network edges.

Source: Cisco Talos


“LookOut” flaws in Google Looker enable full server takeover, data theft

Tenable disclosed two vulnerabilities in self‑hosted Google Looker that can be chained for remote code execution and data exfiltration, affecting a BI platform used by tens of thousands of organizations. Successful exploitation allows attackers to run arbitrary commands on Looker servers and pivot to sensitive corporate data. Self‑hosters should patch immediately, rotate credentials/API keys integrated with Looker, and review logs for anomalous queries and shell activity.

Source: Help Net Security


Predator spyware can hide iPhone mic/camera usage indicators

Jamf Threat Labs research shows the Predator spyware can suppress Apple’s on‑screen indicators that warn when the microphone or camera are active, by intercepting sensor activity on targeted devices. The finding underscores how commercial spyware can bypass user‑facing privacy safeguards, complicating detection and incident response for high‑risk users. Enforce mobile EDR, iOS updates, and MDM restrictions; treat anomalous battery/network patterns and unexpected profiles as compromise indicators.

Source: The Record


React2Shell exploitation fuels NGINX traffic hijacking campaign

Datadog observed active abuse of the React2Shell vulnerability (CVE‑2025‑55182) to compromise NGINX installations and management panels (e.g., Baota), loading malicious modules to reroute web traffic through attacker infrastructure. The campaign follows a surge in mass exploitation attempts and deployment of cryptominers and reverse shells seen in the wild. Patch vulnerable React Native/Metro components, audit NGINX modules and configs, and rotate secrets exposed on compromised hosts.

Source: The Hacker News


Critical n8n sandbox escape (CVE‑2026‑25049) allows server command execution

A sanitization flaw in n8n’s expression sandbox enables authenticated users to break out and execute arbitrary system commands on workflow servers. The bug bypasses earlier mitigations, posing high risk to self‑hosted automation environments commonly wired into secrets, APIs, and CI/CD. Update n8n immediately, restrict who can create/modify workflows, and segment automation nodes from sensitive backends to limit blast radius.

Source: SecurityWeek


SolarWinds Web Help Desk under active attack for unauthenticated RCE

A newly disclosed critical vulnerability in SolarWinds Web Help Desk is being exploited in the wild, enabling unauthenticated remote code execution. CISA has urged rapid remediation, setting tight patch deadlines for federal agencies. Organizations should patch or isolate affected instances, hunt for web shell and process anomalies, and rotate credentials integrated with WHD.

Source: SecurityWeek


Global cyber‑espionage group breached government and critical infrastructure in 37 countries

Palo Alto Networks detailed a long‑running APT operation compromising government agencies and critical infrastructure across 37 nations. While unattributed, evidence points to China‑linked operators using multi‑stage intrusions and stealthy persistence to siphon intelligence. Review exposure of edge services, enforce MFA on all remote access, and prioritize detection for living‑off‑the‑land activity and long‑dwell lateral movement.

Source: SecurityWeek


You May Also Be Interested In... GreyNoise tracks massive Citrix Gateway reconnaissance using 63K+ residential proxies
Microsoft: Cross‑platform infostealers pivot from Windows to macOS via Python and fake installers
Operator of Incognito darknet market sentenced to 30 years in U.S. prison
Cybersecurity — February 5, 2026 | Briefing24