THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
GitHub and Grafana breaches traced to poisoned Nx Console extension in TanStack supply-chain attack

A malicious update to the popular Nx Console VS Code extension (2.2M installs) was used by the TeamPCP group to steal developer credentials and secrets, pivot through CI/CD pipelines, and exfiltrate roughly 3,800 of GitHub’s private repositories. The incident underscores how a single compromised dev tool can cascade across organizations; teams should immediately audit IDE extensions, rotate all tokens/SSH keys, harden CI/CD runners, and enforce least privilege on build secrets.

Source: Help Net Security


Actively exploited Microsoft Defender zero-days added to KEV—patch now

Microsoft and CISA confirmed in-the-wild exploitation of two Microsoft Defender flaws: CVE-2026-41091 (local privilege escalation to SYSTEM via improper link resolution) and CVE-2026-45498 (denial of service). Because these vulnerabilities target endpoint protection itself, defenders should expedite patching, verify Defender engine updates across fleets, and monitor for tampering or unexpected Defender service restarts.

Source: Help Net Security


Cisco Secure Workload flaw earns a perfect 10 CVSS—unauthenticated API access can grant Site Admin

Cisco patched CVE-2026-20223, a critical Secure Workload (Tetration) REST API vulnerability that allows remote, unauthenticated attackers to gain Site Admin privileges due to insufficient validation and authentication. Organizations should apply fixes immediately, review audit logs for anomalous API calls or privilege changes, and restrict management-plane exposure.

Source: SecurityWeek


Europol dismantles “First VPN,” a staple for ransomware crews; users identified

In Operation Saffron, French and Dutch authorities—backed by Europol/Eurojust—seized 33 servers and disrupted First VPN, a crime-focused anonymity service the FBI says supported dozens of ransomware groups. Beyond the takedown, investigators say they can identify many customers, signaling more arrests and adding pressure on criminal infrastructure that has long shielded intrusions and extortion.

Source: SecurityWeek


CISA opens KEV nominations to researchers for faster tracking of exploited bugs

CISA launched a public nomination form allowing researchers, vendors, and industry partners to submit vulnerabilities for inclusion in the Known Exploited Vulnerabilities catalog. The move should shorten time-to-prioritization for defenders, improving patching queues and risk workflows when exploitation evidence emerges outside traditional channels.

Source: The Record by Recorded Future


Deleted Google API keys can stay usable up to 23 minutes—window for data theft and billing abuse

Threat hunters found Google Cloud API keys remain active for an average of 16 minutes (up to 23) after deletion, leaving a gap attackers can exploit to access services like Gemini, BigQuery, and Maps or rack up charges. Teams should proactively rotate keys, monitor key usage post-deletion, apply egress controls, and prefer short-lived service credentials to minimize exposure.

Source: The Register


Alleged Kimwolf IoT botnet operator arrested; faces charges in U.S. and Canada

Authorities arrested a 23-year-old Ottawa man accused of creating and operating the Kimwolf botnet, which reportedly hijacked millions of IoT devices for massive DDoS attacks over the past six months. The case highlights ongoing law-enforcement focus on DDoS-for-hire ecosystems and the persistent risk from poorly secured connected devices.

Source: KrebsOnSecurity


You May Also Be Interested In...

New ‘Showboat’ Linux malware targets telecoms with a SOCKS5 backdoor

Drupal patches highly critical unauthenticated SQL injection (CVE-2026-9082)

Trend Micro Apex One zero-day exploited in the wild gets a fix

Cybersecurity — May 22, 2026 | Briefing24