Security Brief Daily

Apr 02, 2026 · #14


Listen Later

Episode 14

Security Brief Daily | 02 Apr 2026

In This Episode
  • Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacksBleeping Computer
    Internet threat-monitoring non-profit Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability. BIG-IP APM (short for Access Policy Manager) is F5's centralized access...
  • Apple expands iOS 18 updates to more iPhones to block DarkSword attacksBleeping Computer
    Apple has now made it possible for more iPhones still running iOS 18 to receive security updates that protect against the actively exploited DarkSword exploit kit. "We enabled the availability of iOS 18.7.7 for more devices on April 1, 2026, so users with Automatic Updates...
  • Hackers exploit TrueConf zero-day to push malicious software updatesBleeping Computer
    Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints. The flaw is tracked as CVE-2026-3502 and received a medium severity score. It stems from a missing...
  • Google fixes fourth Chrome zero-day exploited in attacks in 2026Bleeping Computer
    Google released emergency updates to fix another Chrome zero-day vulnerability exploited in attacks, marking the fourth such security flaw patched since the start of the year. "Google is aware that an exploit for CVE-2026-5281 exists in the wild," Google said in a security...
  • New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch ReleasedThe Hacker News
    Google on Thursday released security updates for its Chrome web browser to address 21 vulnerabilities, including a zero-day flaw that it said has been exploited in the wild. The high-severity vulnerability, CVE-2026-5281 (CVSS score: N/A), concerns a use-after-free bug in...
  • Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC BypassThe Hacker News
    Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these scripts to initiate a multi-stage infection chain for establishing...
  • Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF LuresThe Hacker News
    A multi-pronged phishing campaign is targeting Spanish-speaking users in organizations across Latin America and Europe to deliver Windows banking trojans like Casbaneiro (aka Metamorfo) via another malware called Horabot. The activity has been attributed to a Brazilian...
  • CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million EmailsThe Hacker News
    The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency itself was impersonated to distribute a remote administration tool known as AGEWHEEZE. As part of the attacks, the threat actors,...
  • Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.

    ...more
    View all episodesView all episodes
    Download on the App Store

    Security Brief DailyBy Security Brief Daily