THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
North Korea-linked supply chain attack backdoors Axios NPM to drop cross-platform RAT

Google’s Threat Intelligence Group says a North Korea–nexus actor (UNC1069) hijacked a maintainer account and slipped a malicious dependency (“plain-crypto-js”) into axios 1.14.1 and 0.30.4, triggering a postinstall dropper that deploys the WAVESHAPER.V2 backdoor on Windows, macOS, and Linux. Axios sees ~100M weekly downloads, amplifying blast radius; defenders should pin to safe versions (1.14.0 / 0.30.3 or earlier), audit lockfiles for “plain-crypto-js,” block C2 (sfrclak.com; 142.11.206.73), clear caches, and rotate credentials on impacted hosts.

Source: Google Threat Intelligence


CISA orders urgent patching of actively exploited Citrix NetScaler flaw

US federal agencies have been told to patch a Citrix NetScaler bug (CVE-2026-3055, severity 9.3) by April 2 after reports of exploitation that could disclose sensitive data via crafted requests. Given the broad footprint of NetScaler ADC/Gateway in enterprise networks, private-sector defenders should prioritize patching, hunt for anomalous requests, and enforce strict access on management interfaces.

Source: Recorded Future News


Exploitation underway for critical Fortinet FortiClient EMS SQLi (CVE-2026-21643)

A critical SQL injection flaw in FortiClient EMS allows unauthenticated remote code execution via crafted HTTP requests, and attacks have been observed in the wild since March 24. Patch immediately, restrict EMS exposure, review web server logs for suspicious POSTs, and monitor for persistence on affected Windows hosts.

Source: SecurityWeek


F5 BIG‑IP APM bug reclassified as unauthenticated RCE and is being exploited

CVE-2025-53521 in F5 BIG‑IP APM has been re-rated to critical (CVSS 9.8) after new findings showed unauthenticated remote code execution; active exploitation is reported. Organizations should patch without delay, isolate/lock down management and APM virtual servers, and hunt for indicators of compromise before and after maintenance windows.

Source: SOCRadar


Trusted updates abused: TrueConf zero‑day pushes malware to Southeast Asian governments

A zero‑day in TrueConf’s client update mechanism (CVE-2026-3502, CVSS 7.8) enabled tampered updates in a campaign dubbed “TrueChaos,” delivering malware without phishing. Researchers observed Havoc used as a post-exploitation framework and assess likely Chinese-nexus involvement, underscoring the risk of supply-chain and updater abuse.

Source: The Hacker News


Iran‑nexus actor hits Microsoft 365 tenants with password‑spray waves

Check Point tracked three waves (Mar 3, 13, 23) of password-spraying attacks against Microsoft 365, primarily targeting Israel (300+ orgs) and the UAE (>25), with spillover to the US, UK, EU, and Saudi Arabia. Enforce conditional access, block legacy auth, rate‑limit and monitor failed logins, and adopt stronger MFA to blunt spray‑and‑pray tactics.

Source: Check Point Research


Google research lowers the bar for quantum attacks on blockchain cryptography

New Google findings suggest significantly fewer qubits may be needed to break elliptic curve cryptography securing Bitcoin, Ethereum, and most modern wallets, shrinking timelines for quantum risk. Crypto and fintech ecosystems should accelerate post‑quantum migration planning, including key agility, quantum‑safe algorithms, and rapid rotation capabilities.

Source: SecurityWeek


You May Also Be Interested In...

Apple counters ClickFix attacks with macOS Terminal warning

Google addresses Vertex AI security issues after researchers weaponize AI agents

Android developers just got a new verification layer

Cybersecurity — April 1, 2026 | Briefing24