The 5-Minute Cyber Brief
Good morning. The useful pattern today is broken trust in places defenders often treat as stable: network infrastructure, court software, infrastructure-as-code distribution, and legitimate runtimes already allowed inside the environment.
Lead Story
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco says certain Silicon One-based Nexus 9000 switches expose a path for unauthenticated remote code execution as `root`, which pushes this out of routine maintenance and into immediate network-platform triage. The same disclosure cycle also includes an IOS XR hardening release with seven umbrella CVEs, a reminder that teams running Cisco infrastructure should review adjacent network-device exposure rather than treating one product line in isolation.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Built from 100+ trusted cybersecurity sources.
Built from 100+ trusted cybersecurity sources.
Why it matters: Root on network gear is a visibility and control problem, not just a patch problem. If teams cannot quickly prove which switches are in scope, who owns them, and how their management plane is exposed, the real delay begins before remediation even starts.
Read more on CyberExperts: Read more on CyberExperts
Original source: The Hacker News
Also Worth Your Attention
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Thomson Reuters says an unauthorized party obtained files from its C-Track court case-management platform, with activity traced to March and discovery not reported until late June. The exposed data set may include Social Security numbers, financial and medical data, passports, court files, and sealed records across courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario.
Why it matters: This is not ordinary breach arithmetic. Court software holds data with procedural and legal sensitivity, so the real question is not only what was taken, but whether trust in case handling, confidentiality, and records workflow was quietly weakened during the gap between intrusion and discovery.
Read more on CyberExperts: Read more on CyberExperts
HPE patches critical ArubaOS-CX remote code execution flaw

HPE patched a critical ArubaOS-CX vulnerability that can lead to remote code execution on switching platforms that many organizations patch far less aggressively than identity, endpoint, or server software. That combination of deep network placement and slow maintenance rhythm is what makes the story worth attention.
Why it matters: A switching-platform flaw becomes dangerous fast when ownership is split and change windows are rare. The risk is not just code execution. It is losing confidence in configuration integrity, traffic handling, and the very management path defenders may need during an incident.
Read more on CyberExperts: Read more on CyberExperts
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Symantec says attackers have been using the legitimate Node.js runtime to stage malicious payloads against government departments, tech companies, and hotels since at least February. The technique works because `node.exe` often looks normal enough to evade simplistic controls, especially on mixed-use endpoints where developer tooling is already expected.
Why it matters: This is a context problem more than a malware-family problem. A trusted runtime can be perfectly normal on one host and deeply suspicious on another, which means defenders need better behavioral judgment than simple allow-list logic provides.
Read more on CyberExperts: Read more on CyberExperts
Coder's registry infrastructure compromised to push malicious modules

Attackers compromised Coder's registry infrastructure and added unauthorized servers that delivered malicious Terraform modules containing credential-stealing code. That turns a developer-platform incident into a supply-chain question about which automation runs, cloud credentials, and infrastructure changes inherited trust from the poisoned registry path.
Why it matters: Once an IaC distribution path is compromised, blocking the next download is only the first step. The harder job is proving which historical runs pulled bad content and whether those runs leaked secrets or changed infrastructure in ways teams still consider legitimate.
Read more on CyberExperts: Read more on CyberExperts
Go Deeper
Editorial Promise
CyberExperts should help you turn headlines into decisions. The value is in pulling the operational facts forward before the day turns them into background noise.