THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Oracle patches critical unauthenticated RCE in Identity Manager (CVE-2026-21992)

Oracle released fixes for a critical vulnerability in Identity Manager and Web Services Manager that allows remote code execution without authentication (CVSS 9.8). Given the exposure of identity infrastructure, organizations should prioritize patching and review external access to affected services.

Source: TheHackerNews


Trivy supply chain compromise unleashes self-spreading 'CanisterWorm' across 47 npm packages

Attackers behind the recent compromise of the popular Trivy scanner are conducting follow-on supply chain attacks, seeding a previously undocumented self-propagating worm dubbed CanisterWorm into dozens of npm packages. The malware leverages an ICP canister (tamperproof smart contracts) as part of its operation, underscoring growing sophistication in open-source package abuse; teams should audit dependency trees and lockfiles immediately.

Source: TheHackerNews


CISA adds Apple, Craft CMS, and Laravel bugs to KEV; federal patch deadline April 3

CISA added five exploited vulnerabilities impacting Apple products, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by April 3, 2026. Inclusion in KEV signals confirmed in‑the‑wild exploitation; enterprises should inventory exposure and expedite remediation.

Source: TheHackerNews


'PolyShell' flaw exposes Magento and Adobe Commerce to unauthenticated file uploads

Sansec disclosed a critical REST API flaw, dubbed PolyShell, in Magento and Adobe Commerce that allows attackers to upload executable files without authentication and may enable XSS in older versions. The issue affects releases up to 2.4.9‑alpha2, putting e‑commerce storefronts at risk of webshell deployment and data theft.

Source: Security Affairs


FBI, CISA warn Russian actors are phishing Signal and WhatsApp to hijack high‑value accounts

U.S. agencies report Russian intelligence–linked threat actors are running phishing campaigns to take over accounts on commercial messaging apps like WhatsApp and Signal. Targets include individuals with high intelligence value; users should be vigilant for suspicious login prompts or device‑linking requests and enable available account protections.

Source: TheHackerNews


Critical Quest KACE flaw (CVE-2025-32975) potentially exploited against education sector

A critical vulnerability tracked as CVE‑2025‑32975 in Quest KACE may have been exploited in attacks against the education sector. Organizations using KACE should apply available patches and review logs for anomalous admin actions or lateral movement.

Source: Security Week


WorldLeaks ransomware disrupts Los Angeles Metro; Bay Area cities declare emergencies

The WorldLeaks group reportedly breached the City of Los Angeles and its Metro system, forcing a shutdown of internal systems, while two Bay Area cities declared emergencies following ransomware incidents. The wave of attacks highlights ongoing threats to municipal services and transportation infrastructure.

Source: Security Affairs


You May Also Be Interested In...
Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck
Delve accused of misleading customers with ‘fake compliance’
Hackers aren't impossible to catch, it's politics and borders that make it nearly impossible
Cybersecurity — March 22, 2026 | Briefing24