THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
M-Trends 2026: Attackers hand off access in 22 seconds as exploits stay No. 1 entry point

Mandiant’s latest report finds the median time between initial access and a secondary actor taking over has collapsed to just 22 seconds, driving faster ransomware and data theft operations. Exploits remained the top initial vector for the sixth straight year, while highly interactive voice phishing surged, and attackers increasingly target backup and virtualization control planes to deny recovery.

Source: Help Net Security


Oracle rushes out-of-band fix for pre-auth RCE in Identity Manager (CVE-2026-21992)

Oracle issued an emergency patch for a critical vulnerability in Oracle Identity Manager and Oracle Web Services Manager caused by missing authentication on a critical function. While Oracle did not confirm in-the-wild exploitation, customers are urged to patch or apply mitigations immediately given the ease of exploitation and the component’s central role in enterprise identity.

Source: Help Net Security


Citrix NetScaler ADC/Gateway flaw (CVE-2026-3055) leaks memory when SAML IdP is enabled

Citrix disclosed a critical unauthenticated out-of-bounds read (CVSS 9.3) in NetScaler ADC and Gateway that can expose sensitive memory on appliances configured as a SAML Identity Provider. Fixed in 14.1-66.59 and 13.1-62.23 (and 13.1-37.262 for FIPS/NDcPP), Rapid7 warns exploitation is likely once PoC code appears; admins should urgently upgrade and check configs for SAML IdP profiles.

Source: Rapid7


Supply-chain hit on Aqua’s Trivy pushes infostealer via Docker images

Attackers published a malicious Trivy release and retagged images on Docker Hub to deliver information-stealing malware to developer environments. Teams relying on Trivy should verify they’re using clean versions, audit pipelines for suspicious image tags, and rotate any credentials that may have been exposed during scans.

Source: SecurityWeek


FBI/CISA: Russian intelligence-linked actors phishing high-value targets on Signal

US agencies warn that threat actors are compromising accounts on secure messaging platforms—especially Signal—by luring targets (journalists, officials, and others with sensitive access) into phishing flows. The alert stresses that “secure app” branding can create a false sense of safety; users should enable registration locks, verify contacts out-of-band, and be wary of unsolicited “support” messages.

Source: Help Net Security


‘CanisterWorm’ wiper targets Iran-aligned systems via cloud misconfigurations

A financially motivated extortion group is attempting to exploit the Iran conflict by unleashing a worm that propagates through poorly secured cloud services and wipes data on systems using Iran’s time zone or set to Farsi. The campaign underscores the need to harden cloud identities and storage, enforce least privilege, and monitor for destructive behaviors tied to locale-based triggers.

Source: KrebsOnSecurity


FCC blocks new foreign-made consumer routers, citing national security risks

US regulators moved to bar new foreign-made home routers from entering the market amid concerns about China-linked cyber threats to critical infrastructure. While existing devices can remain in use, the policy signals a tighter supply chain posture that could affect SOHO gear used by remote and hybrid workers.

Source: CyberNews


You May Also Be Interested In...

QNAP patches four vulnerabilities exploited at Pwn2Own
Google launches threat disruption unit to impede cyber adversaries
Forescout: The devices winning the race to get hacked in 2026
Cybersecurity — March 24, 2026 | Briefing24