THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical protobuf.js flaw allows remote JavaScript code execution; exploit PoC released

Researchers disclosed a critical remote code execution vulnerability in protobuf.js, a popular JavaScript implementation of Google’s Protocol Buffers, with proof-of-concept exploit code now publicly available. The library’s ubiquity across Node.js and browser-based applications raises supply-chain risk concerns, making rapid updates and dependency audits urgent for development teams.

Source: Bleeping Computer


Attackers hide malware in “invisible” QEMU VMs to evade detection

Sophos warns of rising abuse of QEMU, with adversaries running malware inside stealthy virtual machines to bypass endpoint controls and leave minimal forensic traces. The technique enables quiet data theft and ransomware deployment while complicating incident response, pushing defenders to monitor for unusual virtualization artifacts and off-host activity.

Source: Security Affairs


Nexcorium Mirai variant hijacks TBK DVRs and EOL TP-Link routers for DDoS firepower

Fortinet researchers report a Mirai offshoot dubbed “Nexcorium” exploiting vulnerabilities in TBK DVRs and outdated TP-Link routers to conscript devices into DDoS botnets. The campaign underscores how unpatched and end-of-life IoT gear remains low-hanging fruit for threat actors and a persistent risk to upstream networks.

Source: Security Affairs


Old but gold: 5-year-old ShowDoc bug (patched in 2020) exploited for full server takeovers

Threat actors are actively abusing a long-patched ShowDoc vulnerability (CVE-2025-0520) to drop web shells, achieve remote code execution, and seize servers worldwide. The wave of compromises highlights lingering exposure from legacy internet-facing tools and the need to verify patching, remove abandoned instances, and hunt for web shell indicators.

Source: HackRead


Operation PowerOFF: 75,000 users of DDoS-for-hire services unmasked; arrests and domain seizures follow

In a Europol-led crackdown, authorities identified and warned 75,000 consumers of DDoS-for-hire platforms, made four arrests, and seized 53 domains. The action signals mounting legal pressure on both operators and customers, raising the stakes for organizations tempted to outsource cyberattacks.

Source: HackRead


White House to meet Anthropic CEO as anxiety over “Mythos” model’s capabilities grows

The Biden administration plans talks with Anthropic amid concerns and policy questions surrounding the company’s new “Mythos” AI model. As officials weigh potential government use during an ongoing rift with the vendor, the meeting spotlights governance, security safeguards, and downstream risk from increasingly powerful AI systems.

Source: Politico Cyber


Report: EU age-verification app can be hacked in two minutes

Security researchers say the EU’s new age-verification app can be compromised in roughly two minutes, raising questions about the integrity of digital identity checks. The findings amplify calls for stronger security-by-design standards in government-backed identity and verification tools.

Source: Wired


You May Also Be Interested In...
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks — SecurityWeek
Microsoft Teams right-click paste broken by Edge update bug — Bleeping Computer
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims — TheHackerNews
Cybersecurity — April 19, 2026 | Briefing24