THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
‘Starkiller’ Phishing-as-a-Service Proxies Real Login Pages and MFA

A new phishing kit lets criminals load a brand’s actual login site inside a relay, intercepting usernames, passwords, and even multi-factor authentication (MFA) codes in real time. By acting as a transparent middleman, Starkiller evades fast takedowns and defeats basic MFA, making FIDO2/WebAuthn and strict domain allowlisting increasingly critical for defense.

Source: KrebsOnSecurity


BeyondTrust Critical RCE Now Linked to Ransomware Attacks, CISA Flags KEV

CISA updated its Known Exploited Vulnerabilities catalog to note active ransomware exploitation of CVE-2026-1731 in BeyondTrust Remote Support/Privileged Remote Access. The bug enables OS command execution and has been leveraged for web shells and data theft, underscoring the need to patch immediately and restrict external access to management portals.

Source: SecurityWeek


PromptSpy: First Android Malware to Harness Gemini AI for Persistence

Researchers uncovered PromptSpy, Android malware that uses Google’s Gemini at runtime to analyze on-screen elements and maintain persistence across reboots. The AI-driven approach signals a shift toward adaptive, context-aware mobile threats capable of evading traditional controls.

Source: SecurityWeek


AI-Augmented Threat Actor Compromises 600+ FortiGate Devices Across 55+ Countries

Amazon Threat Intelligence observed a financially motivated actor using commercial generative AI services to scale scanning, exploitation, and access operations against FortiGate devices worldwide. The case highlights how off-the-shelf AI now enables less sophisticated attackers to run high-volume campaigns, reinforcing the need to harden edge appliances and accelerate patch pipelines.

Source: AWS Security Blog


CISA Orders Rapid Patching of Actively Exploited Dell RecoverPoint Flaw

Federal agencies were given three days to remediate a maximum-severity Dell RecoverPoint vulnerability involving hardcoded credentials that’s been exploited since at least mid-2024. Storage and recovery systems are high-value targets; organizations should patch urgently, rotate credentials, and review logs for anomalous replication or admin access.

Source: The Register


FBI: $20M Lost to ATM Jackpotting in 2025 as Ploutus Persists

Ploutus malware remains a major threat to U.S. financial institutions, contributing to more than 700 jackpotting incidents and $20 million in losses last year. The FBI urges firmware updates, physical and network hardening of ATMs, and tighter control of XFS software interfaces to blunt malware-driven cash-out schemes.

Source: SecurityWeek


Microsoft Copilot Ignored Sensitivity Labels for Weeks—And DLP Didn’t See It

A four-week Copilot bug allowed confidential emails in Sent Items and Drafts to be summarized despite sensitivity labels and DLP policies—marking the second trust-boundary failure in eight months. The incident exposes a monitoring blind spot inside vendor-hosted AI pipelines and drives urgency for direct Copilot enforcement testing, Purview log reviews, and restricting sensitive repositories from AI retrieval.

Source: VentureBeat


You May Also Be Interested In...

PayPal says cyber incident left Social Security numbers exposed for months
Cline CLI 2.3.0 supply chain attack installed OpenClaw on developer systems
Massive Winos 4.0 (ValleyRat) campaigns target Taiwan
Cybersecurity — February 21, 2026 | Briefing24