THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Iran-linked wiper attack cripples Stryker; CISA probing as supply chain slows

Stryker confirmed a global disruption to its Microsoft environment after an Iran-linked group claimed responsibility, with evidence suggesting attackers abused existing endpoint management tools to wipe devices rather than deploy custom malware. The incident disrupted manufacturing and shipping, underscoring the growing spillover of the Middle East conflict into cyber operations targeting U.S. healthcare supply chains. Organizations with healthcare exposure should review EDR telemetry for mass-wipe commands, validate device management access controls, and harden remote admin paths.

Source: SecurityWeek


Global takedown of SocksEscort proxy service hits AVrecon botnet abusing 360k+ routers

US and European authorities disrupted SocksEscort, a long-running criminal proxy service powered by the AVrecon botnet that hijacked hundreds of thousands of home and small-business routers since 2020. The network enabled large-scale fraud and cloaked threat actor activity; defenders should hunt for signs of router compromise, disable remote administration, patch firmware, and rotate credentials on edge devices.

Source: SecurityWeek


Google patches two Chrome zero-days under active exploitation—update to 146 now

Google shipped Chrome 146 fixes for two exploited high-severity flaws affecting Skia and V8 that could enable memory corruption and security bypass leading to code execution. Enterprises should expedite updates across desktop fleets and Chromium-based browsers, and consider enforcing restart policies to ensure patches take effect.

Source: SecurityWeek


n8n workflow platform: critical RCE bugs allowed server takeover; actively exploited

Multiple critical vulnerabilities in the n8n automation platform allowed unauthenticated code execution, credential theft, and full server compromise; CISA added related issues to the Known Exploited Vulnerabilities list. Immediate upgrades are advised, along with rotating secrets stored in n8n (tokens, API keys), isolating automation nodes, and reviewing logs for suspicious workflow creations and command execution.

Source: SecurityWeek


Veeam fixes seven critical VBR flaws enabling remote code execution—ransomware teams will notice

Veeam released patches for Backup & Replication addressing seven critical issues—including CVE-2026-21666 (CVSS 9.9)—that could let an authenticated domain user execute code on the backup server. Given Veeam’s history as a ransomware target, prioritize patching, restrict network access to VBR management ports, and monitor for abnormal backup job modifications or unexpected service restarts.

Source: The Hacker News


Microsoft Authenticator bug could leak one-time codes—update iOS and Android apps

A flaw in Microsoft Authenticator for Android and iOS could have allowed malicious apps on the same device to intercept login codes or sign-in links, weakening MFA protections. Users and admins should update the Authenticator app immediately, enforce device integrity checks, and prefer phishing-resistant methods (FIDO2/Passkeys) where possible.

Source: Malwarebytes Blog


‘Zombie ZIP’ evasion trick slips malware past 98% of AV engines

Researchers detailed a compression abuse technique that causes security tools to misinterpret ZIP structure, treating compressed data as benign bytes and allowing payloads to bypass scanning. Security teams should add robust archive parsing/sandbox extraction to pipelines, re-scan decompressed contents, and tune mail/web gateways to flag malformed archives.

Source: SC Media


You May Also Be Interested In...

Apple updates legacy iOS/iPadOS to patch Coruna exploits used in the wild
ENISA advisory: Secure use of package managers to reduce supply chain risk
Ally WordPress plugin SQLi exposes 200,000+ sites to data theft
Cybersecurity — March 13, 2026 | Briefing24