THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
North Korean hackers drain $285M from Drift in a 10‑second takeover

Drift Protocol confirmed a rapid, highly coordinated theft in which attackers abused Solana durable nonces to seize its Security Council administrative powers and empty five vaults in about 10 seconds. Researchers attribute the heist to DPRK-linked actors who pre-staged infrastructure and nonce-based transactions to bypass normal safeguards. The incident underscores the need to harden governance keys, restrict emergency admin pathways, and monitor for abnormal multi-sig escalations in DeFi environments.

Source: SecurityWeek


Trivy supply chain attack enabled European Commission cloud breach

CERT‑EU confirmed that the ShinyHunters group used fallout from the Trivy supply chain compromise to access EU Commission web infrastructure, stealing and leaking roughly 340 GB of data. The dataset includes names, usernames, and email addresses across multiple Union entities, highlighting how a single upstream compromise can cascade into institutional breach. EU defenders are assessing exposure while urging rapid rotation of secrets and hardening of CI/CD pipelines that consume third‑party components.

Source: Help Net Security


Cisco fixes critical IMC auth bypass granting admin control (CVE-2026-20093)

Cisco patched a 9.8‑rated vulnerability in the Integrated Management Controller (IMC) that allows unauthenticated, remote attackers to gain elevated access, alongside other high‑severity flaws. IMC underpins out‑of‑band management for UCS servers, making exposure especially risky for data centers and critical workloads. Organizations should patch immediately, restrict IMC interfaces to management networks, and review logs for anomalous access attempts.

Source: SecurityWeek


Chrome WebGPU zero‑day (CVE-2026-5281) exploited in the wild

Google patched a high‑severity use‑after‑free flaw in Dawn, Chromium’s WebGPU implementation, that attackers have already weaponized. The bug enables remote code execution via crafted web content, affecting users across platforms. Admins should fast‑track Chrome updates and consider interim mitigations (e.g., enterprise policies limiting WebGPU exposure) for high‑risk environments.

Source: SOCRadar


Rapid7 uncovers stealth BPFDoor variants using stateless C2 and ICMP relays

New research details seven BPFDoor variants that embed kernel‑level packet filters, enabling “magic packet” wakeups, stateless C2 routing, and ICMP‑based lateral relays beneath EDR visibility. The httpShell and icmpShell strains use tricks like fixed ICMP sequence numbers and invalid protocol codes, process masquerading, and SOCK_DGRAM decapsulation to evade detections in telecom‑grade networks. Rapid7 advises shifting detections toward protocol header anomalies, auditing AF_PACKET sockets, and hunting for spoofed root‑level daemons.

Source: Rapid7


Apple backports DarkSword protections to iOS 18, signaling a patching policy shift

Apple expanded security updates to more iOS 18 devices to blunt DarkSword exploit kit activity, a move that loosens its historical stance of tying some fixes to major OS upgrades. With exploitation observed across both state and commercial spyware ecosystems, Apple’s backports reduce upgrade friction for at‑risk users. Enterprises should prioritize deploying the new iOS/iPadOS 18.7.7 fixes and update their supported‑version baselines accordingly.

Source: Help Net Security


US bans new imports of foreign‑made consumer routers over supply chain risks

The FCC will require case‑by‑case approval for any new foreign‑produced consumer router imported, marketed, or sold in the US, citing severe cybersecurity and national security risks. While existing devices aren’t banned, the policy will reshape procurement, vendor certifications, and supply chain assurances for home and SMB networking gear. Security teams should expect tighter sourcing scrutiny and potential shifts in firmware transparency and SBOM requirements.

Source: Schneier Blog


You May Also Be Interested In...

OpenSSH 10.3 patches five security bugs and drops legacy rekeying support

DPRK-related LNK attacks abusing GitHub for covert C2

Large-scale automated credential harvesting targeting web apps

Cybersecurity — April 3, 2026 | Briefing24