The 5-Minute Cyber Brief
Good morning. Here are the cybersecurity developments most likely to matter to your day.
Lead Story
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen.
Stay Current on Cyber Policy and Guidance
Track new CISA actions, regulations, guidance, and risk trends in a quick daily format.
Free. Weekday mornings. Unsubscribe anytime.
Why it matters: This matters because passkeys are supposed to cut off whole categories of phishing and credential theft. If local malware can still ride a trusted session into protected accounts, passwordless alone is not the comfort blanket many teams think it is.
Read more on CyberExperts: Read more on CyberExperts
Original source: The Hacker News
Also Worth Your Attention
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site.
Why it matters: This matters because edge remote-access appliances sit close to identity, administration, and business continuity all at once. When ransomware crews converge on a SonicWall path, patch delay stops being technical debt and starts looking like exposed access.
Read more on CyberExperts: Read more on CyberExperts
New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
Why it matters: This matters because ClickFix-style attacks keep evolving faster than user awareness programs do. Hiding payload stages in browser cache artifacts gives attackers another low-friction way to turn a convincing prompt into malware execution.
Read more on CyberExperts: Read more on CyberExperts
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
Why it matters: This matters because travel and hospitality workflows are built on quick trust decisions. If attackers can poison that moment, they can turn routine captive-portal behavior into credential theft and malware delivery before the victim realizes the session was never normal.
Read more on CyberExperts: Read more on CyberExperts
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.
Why it matters: This matters because developer-toolchain malware turns normal build activity into a supply-chain risk, and many teams still monitor production far more closely than their build environments.
Read more on CyberExperts: Read more on CyberExperts
Go Deeper
Editorial Promise
CyberExperts should help you get the signal fast, understand what actually matters, and know where to go deeper before the day gets noisy.