THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Actively Exploited Palo Alto PAN-OS Auth Bypass Demands Rapid Patching

A recently disclosed authentication bypass in Palo Alto Networks PAN-OS (CVE-2026-0257) has been under active exploitation, with attacks starting just days after disclosure. The flaw impacts GlobalProtect portal/gateway components and enables attackers to bypass VPN login, prompting urgent patching and tight access controls for internet-exposed devices.

Source: SecurityWeek


Websites Can Now Infer Your Activity via SSD Signals, Researchers Warn

New research details “FROST,” a technique that lets websites use simple JavaScript to measure telltale SSD activity and infer what a user is doing. The method raises serious fingerprinting and privacy concerns, potentially enabling cross-site tracking or behavioral surveillance without traditional permissions.

Source: Wired


Dutch Police Dismantle Botnet of 17 Million Infected Devices

Dutch authorities have taken down a massive botnet linked to at least 17 million compromised computers, phones, tablets, and IoT devices. More than 200 servers in the Netherlands supported the operation, which was used to conduct wide-ranging malicious activities; owners are urged to update, reset, and check devices for compromise.

Source: The Hacker News


Critical WP Maps Pro Exploit Used to Create Rogue Admin Accounts

Attackers are actively exploiting a critical flaw in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on vulnerable sites. With over 15,000 sales on Envato, affected sites should update immediately, audit user accounts and logs for suspicious additions, and disable the plugin if patching isn’t possible.

Source: The Hacker News


Popular npm Package “Codex UI” Caught Stealing OpenAI Refresh Tokens

A malicious npm package named Codex UI—with roughly 27,000 weekly downloads—was found exfiltrating OpenAI refresh tokens, enabling potential account takeover and downstream abuse. Developers should remove the package, rotate all exposed tokens and API keys, and review CI/CD pipelines and dependency locks for supply chain contamination.

Source: HackRead


OWASP Releases Agent Memory Guard to Thwart AI Agent Memory Attacks

OWASP introduced Agent Memory Guard, an open-source runtime defense designed to stop adversaries from weaponizing AI agents through their persistent memory. By monitoring and governing what enters long-lived stores (chat history, vector DBs, scratchpads), it aims to prevent instruction hijacking, data leakage, and tool-call manipulation that can persist across sessions.

Source: Help Net Security


Server Seizures in the Netherlands Disrupt Infrastructure Tied to Iran’s Cyber Ops

Dutch investigators seized roughly 800 servers from hosting provider WorkTitans B.V., uncovering infrastructure allegedly supporting some of Iran’s most active cyber-espionage campaigns. The takedown underscores how sanctioned and rebranded infrastructure can persist behind front companies, and it may trigger rapid APT fallback and migration to new hosting.

Source: Check Point Blog


You May Also Be Interested In...
Cybersecurity — June 1, 2026 | Briefing24