THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

The latest edition

2 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • CISA added SharePoint, MikroTik RouterOS and WordPress Core vulnerabilities to KEV based on evidence of active exploitation.
  • Kaspersky reported a MacSync variant distributed through the Toria crypto wallet app that combines information theft with a persistent backdoor.
  • Fake desktop apps impersonating three browser-based payroll and HR platforms install ScreenConnect configured for covert attacker control.
01

CISA adds exploited SharePoint and MikroTik RouterOS flaws to KEV

CISA added CVE-2026-65660, a Microsoft SharePoint code-injection vulnerability, and CVE-2026-67279, a MikroTik RouterOS vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The agency encourages organizations to prioritize remediation of KEV-listed flaws; its binding directive applies to federal civilian agencies.

Why it matters Federal civilian security teams must weigh these findings against asset exposure and impact: the directive prioritizes KEV-listed flaws on publicly exposed assets where exploitation grants total control, rather than treating every affected asset equally.

US Certs Alerts ↗
02

CISA lists actively exploited WordPress Core remote file inclusion flaw

CISA added CVE-2026-87902, a WordPress Core remote file inclusion vulnerability, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. CISA encourages all organizations to prioritize KEV vulnerabilities, while its binding remediation directive applies to federal civilian agencies.

Why it matters For federal agencies with affected WordPress systems, patching may not be the entire response: the cited directive also sets expectations for checking whether attackers compromised a system before remediation.

US Certs Alerts ↗
03

MacSync malware uses an iCloud calendar to conceal commands

Kaspersky researchers say a new MacSync variant combines an infostealer with a persistent backdoor to target Mac users’ credentials, cryptocurrency wallet data, and files. Help Net Security reports that it spread through a crypto wallet app called Toria, promoted on X and Telegram.

Why it matters The exposure for Mac users extends beyond cryptocurrency holdings: the malware also targets credentials and files, while its persistent backdoor makes this more than a standalone data-stealing payload.

HelpNet Security ↗
04

Fake payroll apps install attacker-controlled ScreenConnect

Allure Security found an attacker offering desktop apps for three major U.S. payroll and HR platforms that have not released desktop apps. Help Net Security reports that running an installer deploys ScreenConnect, a legitimate remote-access tool configured to give the attacker control of the computer without the user’s knowledge.

Why it matters Users seeking a payroll desktop client can instead surrender control of their computer. The providers' browser-only delivery model is a concrete way to distinguish these installers from an authorized product.

HelpNet Security ↗
05

Report details telecom risks from SS7, BGP, and compromised routers

Cyble describes how weaknesses in SS7 signaling and BGP route validation can enable subscriber tracking, message interception, or traffic diversion, and says such activity can resemble legitimate network operations. The report also cites a 2025 joint advisory describing PRC state-sponsored actors targeting telecom routers and using compromised devices and trusted connections to pivot.

Why it matters Telecom security teams cannot rely on endpoint monitoring alone to detect these attacks: signaling abuse, route hijacks and rogue tunnels can resemble routine network operations and occur outside EDR visibility.

Cyble ↗
Briefing24 — A clearer view of today