THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Patch Tuesday highlights: SQL Server network EoP, Excel Copilot data leak, no in‑the‑wild zero‑days

Microsoft’s March updates ship fixes across Windows, Office, SharePoint, Edge, Azure, SQL Server and more, with two publicly disclosed issues but none known to be exploited. Notable risks include a SQL Server elevation-of-privilege flaw (CVE-2026-21262) that can grant sysadmin over the network, a .NET denial‑of‑service (CVE-2026-26127), and a Microsoft Excel issue (CVE-2026-26144) that can trigger zero‑click information disclosure via Copilot. Prioritize SQL Server (especially any exposed to the internet), SharePoint RCEs, and Print Spooler fixes. Review mobile MFA app policy in light of the Microsoft Authenticator information disclosure (CVE-2026-26123).

Source: Rapid7


Global WordPress compromises push multi‑stage infostealers via fake Cloudflare CAPTCHA

Rapid7 Labs uncovered a widespread campaign hijacking legitimate WordPress sites to inject a convincing “ClickFix” CAPTCHA overlay that social‑engineers users into running PowerShell. The in‑memory chain drops multiple stealers—including an updated Vidar, a .NET “Impure Stealer,” and a new C++ “VodkaStealer”—with more than 250 infected sites across at least a dozen countries (including a U.S. Senate candidate’s page). Defenders should hunt for unexpected PowerShell web requests, audit WordPress for obfuscated loaders, and use Rapid7’s shared IoCs/YARA. The operation demonstrates how trusted sites and criminal tooling amplify scale and evasion.

Source: Rapid7


Attackers mass‑scan Salesforce Experience Cloud misconfigs to siphon data

Salesforce customers are being targeted via overly permissive Experience Cloud guest user settings, with threat actors wielding a modified AuraInspector tool to enumerate and pull sensitive records. The activity highlights how configuration drift—rather than code flaws—can expose case data, attachments, and PII at scale. Lock down guest permissions, disable guest record access where possible, and monitor for automated scraping patterns against /s/sfsites/aura endpoints.

Source: The Hacker News


FortiGate appliances abused as beachheads to steal credentials and map networks

Researchers warn adversaries are exploiting FortiGate NGFWs—via recent CVEs or weak creds—to extract configuration files containing service account secrets and detailed topology data. Once inside, attackers pivot with high‑quality intel on internal services and credentials, shortening dwell time and raising blast radius. Urgently patch affected FortiOS versions, enforce strong auth on management, restrict access to admin interfaces, and rotate any secrets stored in device configs.

Source: The Hacker News


CISA tightens patch deadline for critical Ivanti and SolarWinds vulnerabilities

The U.S. cybersecurity agency ordered federal civilian agencies to remediate CVE‑2025‑26399 in SolarWinds Web Help Desk—and other high‑risk bugs—on an accelerated timeline, reflecting active threat pressure. The move signals urgency for all enterprises running affected products to inventory exposure, apply vendor fixes, and validate mitigation efficacy. Expect closer KEV tracking and shortened SLAs when exploitation likelihood rises.

Source: The Record by Recorded Future News


APT28/Sednit resurges with dual‑implant toolkit for long‑term military espionage

ESET reports Russia‑linked Sednit (APT28) is back with a modern espionage stack centered on BeardShell and Covenant implants, each leveraging separate cloud providers for resilience. Since at least April 2024, the group has sustained surveillance of Ukrainian military personnel, underscoring a renewed focus on operational durability and attribution friction. Network defenders should hunt for dual‑channel C2 patterns and cloud‑hosted implants tied to this toolkit.

Source: Help Net Security


Critical flaw in popular Java auth library pac4j poses downstream risk

A maximum‑severity defect in pac4j—a widely deployed Java security engine used for authentication—could be exploited with relative ease, creating cascading risk for dependent apps and services. While no in‑the‑wild exploitation has been observed, the ubiquity of the library increases the urgency to identify usage, apply patches, and validate auth flows. SBOM‑driven asset discovery and targeted regression testing are essential to reduce latent exposure.

Source: CyberScoop


You May Also Be Interested In...

Software vulnerabilities push credential abuse aside in cloud intrusions (Google Cloud report)
Hackers may have breached FBI wiretap network via supply chain
Mozilla fixes 22 Firefox vulnerabilities discovered by Anthropic’s Claude AI
Cybersecurity — March 11, 2026 | Briefing24