THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft Defender hit by three zero-days now exploited in the wild

A security researcher disclosed three Microsoft Defender flaws—BlueHammer, RedSun, and UnDefend—that enable local privilege escalation and, in some cases, block signature updates or disable Defender entirely. Huntress reports all three techniques are being exploited in active attacks, with two still lacking patches. Enterprises should monitor for Defender tampering, restrict local admin rights, and apply Microsoft mitigations as they become available.

Source: Help Net Security


NVD pivots to selective CVE enrichment as vulnerability volume surges

NIST’s National Vulnerability Database will stop enriching every CVE and instead focus on a subset, including CISA KEV entries, software used by the federal government, and designated critical software. The shift reflects a massive rise in CVE submissions and will push security teams to rely more on KEV, vendor advisories, and commercial intel for prioritization. Plan for internal triage processes and tooling that don’t depend solely on NVD enrichment metadata.

Source: Flashpoint


CISA adds critical Apache ActiveMQ RCE to Known Exploited Vulnerabilities

CISA added CVE-2026-34197, a critical Apache ActiveMQ remote code execution flaw (CVSS 8.8), to its KEV catalog, signaling confirmed exploitation. Federal agencies face an accelerated remediation timeline, and enterprises should urgently patch affected brokers, review exposed management endpoints, and hunt for post-exploitation activity.

Source: Security Affairs


Global ‘PowerOFF’ crackdown seizes DDoS-for-hire platforms; four arrested

Authorities in more than 20 countries coordinated a new Operation PowerOFF action, arresting four suspects and disrupting cheap “booter” services that sold on-demand DDoS attacks. Investigators also obtained extensive user data, which may fuel follow-on actions against customers. Expect temporary disruption in the DDoS marketplace and watch for service rebrands.

Source: The Record


Ukraine confirms APT28 campaign abusing Roundcube zero-click mail exploit

Ukrainian authorities validated a suspected APT28 operation targeting prosecutors and anti‑corruption agencies via Roundcube webmail vulnerabilities that execute code when a victim merely opens an email. The tradecraft highlights continued exploitation of server-side webmail platforms for initial access. Roundcube users should patch urgently, disable remote content, and monitor for anomalous mailbox processes.

Source: The Record


New Mirai variant ‘Nexcorium’ hijacks TBK DVRs for DDoS

Fortinet tracked a multi-architecture Mirai offshoot dubbed Nexcorium that chains exploitation of TBK DVRs (CVE-2024-3721), persistence, and brute-force tactics into a single campaign, while also reusing older bugs like CVE-2017-17215. The botnet targets widely deployed, rarely updated video recorders to amass DDoS firepower. Segment and patch IoT, disable WAN management, and rotate default credentials.

Source: Fortinet


ZionSiphon malware tailored to water-treatment ICS environments

Researchers detailed ZionSiphon, malware configured to operate on systems tied to Israeli water treatment and desalination facilities. The discovery underscores persistent OT targeting and the risk of process manipulation. Operators should harden HMIs and controllers, restrict USB and removable media, and increase network monitoring between IT and OT.

Source: SecurityWeek


You May Also Be Interested In...

CISA resources ‘more limited than I would like’ amid DHS shutdown
GitHub user attachments abused to spread novel infostealer
Ransomware continues to disrupt London healthcare nearly two years later
Cybersecurity — April 18, 2026 | Briefing24