THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
GigaWiper: modular Windows wiper that combines remote access with multi-mode system destruction

Microsoft has detailed GigaWiper, a modular Go-based backdoor that stitches together multiple destructive capabilities—remote control plus several ways to wipe systems. The report highlights how modern destructive malware is evolving from “single-purpose” wipers into integrated toolkits that can both spy and permanently sabotage endpoints. For defenders, it reinforces the need to harden remote access paths and to treat wipe behavior as a full compromise signal, not an isolated incident.

Source: SecurityWeek


Zimbra Classic Web Client: critical stored XSS flaws being actively patched after no-CVE window

Zimbra has urged customers to apply an update to address a critical stored cross-site scripting vulnerability in the Zimbra Collaboration “Classic Web Client.” Because this bug executes when malicious emails are opened in user sessions, it creates a high-risk pathway for session compromise and downstream account impact. The reporting notes that the issue may not yet have a CVE assigned, so teams should rely on vendor version guidance and prioritize patch validation immediately.

Source: Security Affairs


Okta warns of vishing/passkey extortion targeting Microsoft 365: social engineering meets identity takeover

Okta has reported a vishing campaign targeting Microsoft 365 customers where attackers push victims to enroll a “new Entra passkey.” The scheme centers on social pressure that drives users through legitimate-looking security flows, allowing the adversary to register their own key and take over access. Organizations should treat passkey enrollment as a high-integrity action—tighten verification steps, monitor for unexpected key registrations, and reinforce employee call verification procedures.

Source: SecurityWeek


New/massive fake Go package operations: 200+ GitHub repos distributing malware via counterfeit code

Researchers say a large network of GitHub repositories has been used to spread malware through fake Go packages, delivering loaders, stealers, RATs, and cryptominers. The scale—hundreds of repositories—illustrates how attackers are weaponizing software ecosystems and trust signals rather than relying on a single static payload. Defenders should strengthen dependency vetting, GitHub supply-chain monitoring, and detection that focuses on malicious behavior rather than package names alone.

Source: Security Week


ClickFix + removable media remain dominant delivery methods; attackers increasingly target macOS too

ReliaQuest research finds ClickFix (prompt-and-paste command trickery) and USB/removable media are leading malware delivery routes, with fast turnover in payload families. Importantly, the findings note ClickFix targeting macOS as well, challenging the assumption that macOS is lower risk for this technique. The key defense takeaway is behavioral: monitor for suspicious command execution chains (e.g., script/terminal usage, base64 decoding, curl retrieval, PowerShell/osascript execution) and treat USB infections as possible precursors to ransomware.

Source: TechTarget


Windows HTTP.sys kernel RCE: CVE-2026-47291 exploitation possible via crafted HTTP/1.x headers over TLS

A kernel-mode remote code execution vulnerability in Windows HTTP.sys (HTTP protocol stack for IIS) has been analyzed in depth after a patch in the June 2026 cycle. The issue stems from invalidating incoming HTTP requests during HTTP/1.x header parsing and can lead to denial-of-service or—in specific conditions—kernel code execution. For rapid risk reduction, ensure the vendor patch is deployed and validate HTTP.sys exposure over HTTPS endpoints; additionally, watch for abnormal traffic patterns consistent with excessive header growth behavior.

Source: Zero Day Initiative (ZDI)


You May Also Be Interested In...

URGENT: Progress warns ShareFile customers to shut down Storage Zone Controllers

Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence

“Comment stuffing” in an HTML phishing attachment to evade AI detection?

Cybersecurity — July 11, 2026 | Briefing24