THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Emergency: Cisco SD‑WAN zero‑day exploited since 2023 gives attackers full admin control

A critical authentication bypass in Cisco Catalyst SD‑WAN Controller/Manager (CVE-2026-20127, CVSS 10.0) has been actively exploited since 2023 to gain unauthenticated administrative access. Organizations should patch immediately and lock down management interfaces, as successful exploitation enables policy push at scale and rapid lateral impact across sites.

Source: Security Affairs


Google disrupts China‑linked cyberespionage hitting 53 orgs across 42 countries

Google detailed and disrupted a long‑running cyberespionage campaign targeting at least 53 government and telecom organizations in 42 countries. The takedown underscores sustained, globally distributed targeting of critical public‑sector networks and telecom infrastructure by China‑nexus operators.

Source: Recorded Future News (The Record)


New “Dohdoor” backdoor targets U.S. education and healthcare

Cisco Talos tracked threat cluster UAT‑10027 deploying a previously unseen backdoor dubbed “Dohdoor” against U.S. education and healthcare orgs since at least December 2025. Initial access likely begins with phishing that launches PowerShell, with the stealthy implant designed for persistent remote control.

Source: Security Affairs


Anthropic patches Claude Code flaws that enabled silent RCE and API key theft

Anthropic fixed vulnerabilities in Claude Code that researchers showed could be triggered via malicious configuration files to achieve remote code execution and exfiltrate developer API credentials. Teams should update promptly, review developer environments for tampering, and rotate potentially exposed tokens and keys.

Source: SecurityWeek


OpenAI: Fraudsters fold ChatGPT into global romance scams and influence ops

OpenAI’s latest abuse report shows ChatGPT and related APIs integrated into worldwide fraud and influence campaigns, including romance scams, fake legal services, coordinated propaganda, and a state‑linked harassment effort. The findings highlight how off‑the‑shelf AI accelerates social engineering at scale, raising the urgency for content‑driven detection and user education.

Source: Help Net Security


Industrial networks still exposed: OT services leaking onto the public internet

New research from Palo Alto Networks, Siemens, and Idaho National Lab found ongoing growth in publicly reachable OT assets, including remote access portals and building automation servers, with over 110 million observations of exposed OT devices in 2024. Operators should urgently inventory external exposure, enforce segmentation, and eliminate unauthenticated remote access to industrial systems.

Source: Help Net Security


NATO greenlights iPhone and iPad for handling restricted‑level classified data

Apple confirmed iPhone and iPad are now approved for use with restricted‑level classified information in NATO environments and added to the NIAPC, without requiring specialized software or settings. The move expands COTS device usage in sensitive government contexts and raises the bar for enterprise‑grade mobile security baselines.

Source: SecurityWeek


You May Also Be Interested In...

Juniper Networks PTX Routers Affected by Critical Vulnerability

Trend Micro Patches Critical Apex One Vulnerabilities

Scattered Lapsus$ Hunters seeks women for vishing attacks

Cybersecurity — February 27, 2026 | Briefing24