THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Fortinet rushes emergency fixes for exploited FortiClient EMS zero-day (CVE-2026-35616)

Fortinet released out-of-band patches for a FortiClient EMS improper access control flaw that enables unauthenticated remote code execution—and it’s already being exploited. Organizations should urgently patch, restrict EMS exposure, review logs for anomalous API activity, and rotate credentials where possible.

Source: SecurityWeek


Germany unmasks “UNKN,” alleged head of REvil and GandCrab ransomware crews

German authorities identified 31-year-old Russian Daniil Maksimovich Shchukin as the operator known as “UNKN,” tying him to leadership roles in the GandCrab and REvil RaaS operations and at least 130 sabotage and extortion incidents in Germany from 2019–2021. The dox underscores growing law-enforcement visibility into ransomware ecosystems, with potential disruption to affiliate networks and money flows.

Source: KrebsOnSecurity


Qilin and Warlock ransomware use vulnerable drivers to kill 300+ EDR tools

Researchers observed both groups deploying bring-your-own-vulnerable-driver (BYOVD) techniques to disable security tools on compromised hosts. Defenders should enforce kernel driver blocklists (e.g., Microsoft’s revocation list/HVCI), enable EDR tamper protections, and alert on unexpected driver loads to blunt this tactic.

Source: The Hacker News


Residential proxies erode the value of IP reputation, says new research

GreyNoise tracked 4 billion malicious sessions in 90 days and found attackers increasingly route traffic through residential, mobile, and small-business connections that blend in with legitimate users. Pure IP reputation and ASN blocking are no longer sufficient—combine network intel with device fingerprinting, behavioral risk scoring, and step-up authentication.

Source: Help Net Security


$285M Drift crypto heist traced to 6‑month DPRK social engineering campaign

Drift said the April 1 theft was the culmination of a targeted operation by North Korean actors that began in fall 2025, relying on meticulous, prolonged social engineering rather than novel exploits. The case highlights the need for rigorous identity verification, least-privilege access, and training to counter tailored, long-con social approaches.

Source: The Hacker News


European Commission cloud breach: stolen data posted online

Attackers reportedly exfiltrated data from a European Commission cloud service and published it, spotlighting the systemic risk concentrated in SaaS and cloud platforms. Security teams should reassess vendor access scopes, token lifetimes, data minimization, and incident response plans for third-party breaches.

Source: The Cyber Express


SANS ISC: How often are redirects used in phishing in 2026?

A new SANS Internet Storm Center analysis examines the prevalence and abuse patterns of open and third‑party redirects in modern phishing campaigns. Expect more trust‑anchored redirectors and multi‑hop URL chains designed to evade scanners—audit your own apps for open redirects and expand filtering to follow and score redirects.

Source: SANS ISC


You May Also Be Interested In...

CBP facility codes sure seem to have leaked via online flashcards

IT talent looks the other way as wireless security incidents pile up

Post-Quantum Cryptography: Moving From Awareness to Execution

Cybersecurity — April 6, 2026 | Briefing24