THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
FortiClient EMS zero-day exploited in the wild; hotfixes released (CVE-2026-35616)

Fortinet confirmed active exploitation of a critical pre-auth API access bypass in FortiClient Endpoint Management Server, allowing privilege escalation (CVE-2026-35616, CVSS 9.1). Emergency hotfixes are available for FortiClient EMS 7.4.5 and 7.4.6; organizations should patch immediately, restrict EMS exposure, and review logs for anomalous unauthenticated API activity.

Source: Help Net Security


European Commission breach tied to Trivy supply chain attack; 300GB exfiltrated

The European Commission confirmed that attackers linked a breach to the Trivy supply chain attack and stole over 300GB of data from its AWS environment, including personal information. The incident underscores risks from developer tooling; teams should inventory CI/CD dependencies, rotate tokens, and scrutinize cloud access logs for anomalous activity tied to scanning workflows.

Source: SecurityWeek


CISA adds TrueConf Client flaw (CVE-2026-3502) to KEV, signaling active exploitation

CISA added a TrueConf Client vulnerability (CVE-2026-3502, CVSS 7.8) to the Known Exploited Vulnerabilities catalog, indicating in-the-wild exploitation. Given TrueConf’s use in secure and offline environments, agencies and enterprises should prioritize patching or mitigations, enforce application allow‑listing, and monitor for suspicious client update or interprocess activity.

Source: Security Affairs


36 malicious npm packages masquerade as Strapi plugins to drop persistent implants

Researchers uncovered 36 npm packages posing as Strapi CMS plugins that executed postinstall payloads to exploit Redis and PostgreSQL, deploy reverse shells, harvest credentials, and establish persistence. Developers should audit dependencies for suspicious postinstall scripts, purge impacted packages, and rotate database credentials and tokens used in affected builds.

Source: The Hacker News


GitHub Actions under fire: prt-scan supply chain campaign abused pull_request_target

Wiz Research traced six waves of a coordinated GitHub Actions campaign to a single actor, exploiting pull_request_target to run untrusted code; over 500 malicious PRs were sent with roughly 10% success. Organizations should avoid pull_request_target where possible, harden workflows with least-privileged tokens and OIDC, and block Actions from forks unless explicitly required.

Source: Wiz


North Korean group UNC1069 targets Node.js maintainers via fake LinkedIn and Slack

UNC1069 is impersonating recruiters and community contacts on LinkedIn and Slack to social-engineer Node.js package maintainers, aiming to seed malware and compromise open-source releases. Package owners should enforce 2FA, verify identities out-of-band, restrict publisher permissions, and adopt signed releases and protected branches to curb supply chain risk.

Source: HackRead


Post-quantum cryptography urgency grows as research moves ‘Q‑Day’ as early as 2029

New research cited by Google accelerates timelines for quantum threats that could break today’s public-key cryptography, pushing enterprises from awareness to execution. Security leaders should begin crypto inventories, prioritize data with long confidentiality lifetimes, pilot hybrid PQC in protocols, and plan staged migrations aligned with NIST-approved algorithms.

Source: GovTech


You May Also Be Interested In... How critical Axios NPM package got hacked: maintainer shared full story
Qilin ransomware group claims the hack of German political party Die Linke
Hackers Are Posting the Claude Code Leak With Bonus Malware
Cybersecurity — April 5, 2026 | Briefing24