THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical F5 BIG-IP APM RCE (CVE-2025-53521) under active exploitation; added to CISA KEV

Attackers are actively exploiting a critical unauthenticated remote code execution flaw in F5’s BIG-IP Access Policy Manager, prompting CISA to add CVE-2025-53521 to its Known Exploited Vulnerabilities catalog. Organizations should prioritize patching per F5’s updated advisory and hunt for post-exploitation activity on exposed APM appliances.

Source: Help Net Security


Citrix NetScaler CVE-2026-3055 (CVSS 9.3) draws active reconnaissance for data-leakage bug

Researchers report active scanning for a newly disclosed memory overread in Citrix NetScaler ADC and Gateway (CVE-2026-3055) caused by insufficient input validation. While the flaw facilitates information leakage rather than direct code execution, exposed gateways are being probed at scale—admins should apply vendor fixes and monitor for anomalous requests and spikes in error responses.

Source: The Hacker News


TA446 wields leaked “DarkSword” iOS exploit kit in targeted spear-phishing

Proofpoint observed Russia-linked TA446 (aka Callisto) running a focused email campaign that uses the recently leaked DarkSword exploit kit to target iOS devices. The activity highlights growing mobile exploitation via social engineering; enterprises should harden mobile fleets, enforce rapid iOS patching, and train users to treat unsolicited links as hostile.

Source: The Hacker News


Apple pushes lock screen alerts urging updates amid active web-based iOS/iPadOS exploits

Apple is issuing on-device lock screen warnings to users running outdated iOS and iPadOS versions, citing active web-based attacks. The company urges immediate updates, reinforcing that delaying patches substantially increases exposure on mobile endpoints frequently targeted via malicious links and drive‑by exploits.

Source: Security Affairs


ShinyHunters claim breach of the European Commission; alleged mail server data posted

The ShinyHunters group added the European Commission to its leak site, alleging theft of internal communications and mail server content. Officials are investigating the claims; if confirmed, the incident could carry significant diplomatic and regulatory ramifications across the EU’s institutions and vendors.

Source: Security Affairs


Cloudflare-themed “ClickFix” lure drops Infiniti Stealer on Macs

A new macOS campaign impersonates Cloudflare challenges to socially engineer users into running a Bash script that loads a Nuitka-built Python component and delivers the Infiniti info‑stealer. The multilayer chain underscores that macOS users remain high‑value targets; tighten browser download controls, block unknown scripts, and expand EDR visibility on Macs.

Source: SecurityWeek


TeamPCP supply-chain campaign shifts from intrusion to monetization, no new compromises in 48 hours

SANS ISC reports an operational tempo change in the TeamPCP campaign as actors move into monetization, with no new compromises observed over the past two days. Earlier phases included the Telnyx PyPI compromise and ties to a Vect ransomware partnership—teams should review dependencies and lockdown CI/CD trust boundaries.

Source: SANS ISC


You May Also Be Interested In...

RSAC 2026: More auto-updating supply-chain attacks on the way

BSides SF: SaaS and cloud assets vulnerable to identity-based ransomware

Iran-linked group claims hack of FBI Director’s personal email

Cybersecurity — March 29, 2026 | Briefing24