Daily Recap, The dayâs cybersecurity news shows ongoing exploitation of the WinRAR CVE-2025-8088 to drop silent payloads into Windows Startup folders by nation-state and criminal groups. It also highlights high-severity flaws such as Grist Core RCE in Pyodide, React2Shell deserialization, Fortinet FortiOS SSO bypass, and other attacks, underscoring urgent patching and proactive defense. #WinRAR #React2Shell
News:
Vulnerabilities & Exploits
- WinRAR path-traversal (CVE-2025-8088) is still being exploited months after patch to drop silent payloads such as NESTPACKER/STOCKSTAY/POISONIVY into Windows Startup folders by nation-state and criminal groups â WinRAR Flaw, WinRAR Report
- A critical Pyodide sandbox escape in GristâCore lets a single spreadsheet formula achieve RCE (patched in 1.7.9, CVSS 9.1) â upgrade now â Grist RCE
- Two sandbox-escape flaws in n8n (including a 9.9-rated JS AST escape, CVE-2026-1470) allow authenticated RCE on self-hosted instances â apply patches â n8n Escape
- SolarWinds Web Help Desk patched multiple critical auth-bypass and RCE flaws (CVE-2025-40551â40554) and a hardcoded-credentials issue â admins must update to 2026.1 immediately â Web Help Desk
- React Server Components insecure-deserialization (CVE-2025-55182, âReact2Shellâ) is under active exploitation to deploy miners and botnets like XMRig, RustoBot and EtherRAT â hunt and patch â React2Shell
- Fortinet patched an actively exploited FortiOS/FortiCloud SSO auth-bypass (CVE-2026-24858) and urges firmware upgrades, credential rotation and config audits â Fortinet SSO
- Regional eScan update server breach pushed a malicious update with a modified loader and backdoor (CONSCTLX.exe); vendor isolated infra and urged remediation â eScan Update
Malware & Spyware
- Romance-scam campaign GhostChat targets users in Pakistan with a fake chat app that performs silent surveillance and exfiltrates media via WhatsAppâpairing techniques â GhostChat Spyware
- Malicious and privacyâinvasive browser and IDE extensions are active: Chrome add-ons can spy on ChatGPT chats, and a fake Moltbot VS Code extension installs a ScreenConnect RAT on launch â investigate and remove untrusted extensions â Chrome Spy Extensions, Moltbot Extension
- Wider Moltbot ecosystem risks: insecure deployments can leak API keys, OAuth tokens and conversation history and enable command execution, while local Moltbot storage is targeted by infoâstealers like RedLine â Moltbot Risk
- Infostealer recovered from a compromised machine in the Gaza Strip revealed internal Breaking Dawn operational documents tied to the AlâAqsa Martyrsâ Brigades, including OPSEC requests and escalation triggers â Gaza Infosteal
- Dataâtheft wave claimed by ShinyHunters hit companies including Bumble, Panera, Match Group and CrunchBase with contractor account compromises, vishing and extortion tactics under investigation â ShinyHunters Wave
Supplyâchain & OSS Threats
- Researchers found over 454,600 malicious openâsource packages across npm, PyPI, Maven, NuGet and Hugging Face in 2025, with npm the primary vector and actor playbooks becoming industrialized â harden CI/CD and vet dependencies â Malicious OSS
- Google disrupted the large residential proxy network IPIDEA, removing millions of enrolled devices by taking down control domains and pursuing legal action â a notable takedown of commoditized proxy infrastructure â IPIDEA Takedown
- Scammers are abusing a real Microsoft Power BI address to send subscriptionâstyle scam emails that trick victims into calling and installing remoteâaccess tools â watch for [email protected] lures â PowerBI Scam
Crime Markets & Enforcement
- The FBI seized the RAMP cybercrime forum, taking Tor/clearnet domains and enabling access to user data that may ID operators and affiliates â RAMP Seized
- A coâcreator of Empire Market pleaded guilty to drug conspiracy after facilitating roughly $430 million in transactions and facing forfeiture of about $75 million in crypto; sentencing pending â Empire Guilty
- Slovakian operator of Kingdom/Kingdown Market pleaded guilty to conspiracy for running a darknet marketplace selling drugs, stolen data and cyber tools â domains and crypto were surrendered â Kingdom Plea
- Authorities in Hungary and Romania arrested teens tied to coordinated swatting and doxing campaigns that triggered false bomb threats; devices were seized and terrorismârelated charges filed â Teen Swatting
- U.S. prosecutors charged 31 more defendants (bringing the total to 87) in an international ATM jackpotting scheme tied to Tren de Aragua that used Ploutus malware to force cash dispensals â massive multinational probe continues â ATM Jackpotting, ATM Update
Infrastructure & Corporate Incidents
- LateâDecember attacks compromised control/communications at about 30 distributed generation sites in Poland; vendors/researchers reported differing attributions (Dragos: ELECTRUM; other reporting: Sandworm + DynoWiper) and disabled OT equipment at multiple locations â Poland Grid, Poland Report
- A major cyberattack disrupted services at Russian alarm and vehicle security provider Delta, causing vehicle lockouts and alarm failures while restoration continues and dataâleak claims circulate â Delta Outage
- New wave of breaches hit consumer platforms and business directories, with limited exposures reported and extortion/vishing linked to groups like ShinyHunters â investigations ongoing â Data Breach Wave
- Attackers are hijacking exposed LLM endpoints in a campaign named âBizarre Bazaarâ (> 35,000 sessions in 40 days) to cryptomine, resell API access, exfiltrate prompts and pivot laterally â secure and monitor LLM endpoints â Bizarre Bazaar
AI, Governance & Strategy
- SecurityWeekâs Zero Trust roundup frames identityâfirst continuous verification as a journey complicated by AI, OT/IT convergence and legacy perimeters â incremental progress and microsegmentation advised â Zero Trust
- Offensive security is shifting to continuous, AIâaugmented programs combining automation, threat intel and red/blue collaboration to find and remediate vulnerabilities faster â Offense Shift
- Experts warn against fully autonomous AI defense: model drift, poor data and lack of oversight risk systemic failure â keep humansâinâtheâloop and auditable governance â AI Caution
- AI agents embedded in regulated workflows are rewriting compliance controls and raising CISO responsibility for identity, access and continuous auditing under regimes like GDPR/SOX â adapt controls and monitoring â AI Compliance
Industry Moves & Protections
- WhatsApp is rolling out âStrict Account Settingsâ (lockdown mode) for highârisk users to block unknown media/calls, enforce twoâstep verification and harden code (new Rust media library) â optâin if targeted â WhatsApp Lockdown, WhatsApp Boost, WhatsApp Rollout
- Mesh Security raised $12 million to scale a Cybersecurity Mesh Architecture platform that automates crossâstack remediation and agentic response â Mesh Funding
- The American Hospital Association released guides for medical surge and cyber preparedness in U.S. hospitals emphasizing staffing, supply, space and systems to sustain care in crises â AHA Guides
- Report compares background activities of remoteâsupport tooling (e.g., GoTo Resolve) to ransomware tactics, underscoring the need to monitor vendor tools and background processes â GoTo Resolve
Vulnerabilities & Exploits
- WinRAR path-traversal (CVE-2025-8088) is still being exploited months after patch to drop silent payloads such as NESTPACKER/STOCKSTAY/POISONIVY into Windows Startup folders by nation-state and criminal groups â WinRAR Flaw, WinRAR Report
- A critical Pyodide sandbox escape in GristâCore lets a single spreadsheet formula achieve RCE (patched in 1.7.9, CVSS 9.1) â upgrade now â Grist RCE
- Two sandbox-escape flaws in n8n (including a 9.9-rated JS AST escape, CVE-2026-1470) allow authenticated RCE on self-hosted instances â apply patches â n8n Escape
- SolarWinds Web Help Desk patched multiple critical auth-bypass and RCE flaws (CVE-2025-40551â40554) and a hardcoded-credentials issue â admins must update to 2026.1 immediately â Web Help Desk
- React Server Components insecure-deserialization (CVE-2025-55182, âReact2Shellâ) is under active exploitation to deploy miners and botnets like XMRig, RustoBot and EtherRAT â hunt and patch â React2Shell
- Fortinet patched an actively exploited FortiOS/FortiCloud SSO auth-bypass (CVE-2026-24858) and urges firmware upgrades, credential rotation and config audits â Fortinet SSO
- Regional eScan update server breach pushed a malicious update with a modified loader and backdoor (CONSCTLX.exe); vendor isolated infra and urged remediation â eScan Update
Malware & Spyware
- Romance-scam campaign GhostChat targets users in Pakistan with a fake chat app that performs silent surveillance and exfiltrates media via WhatsAppâpairing techniques â GhostChat Spyware
- Malicious and privacyâinvasive browser and IDE extensions are active: Chrome add-ons can spy on ChatGPT chats, and a fake Moltbot VS Code extension installs a ScreenConnect RAT on launch â investigate and remove untrusted extensions â Chrome Spy Extensions, Moltbot Extension
- Wider Moltbot ecosystem risks: insecure deployments can leak API keys, OAuth tokens and conversation history and enable command execution, while local Moltbot storage is targeted by infoâstealers like RedLine â Moltbot Risk
- Infostealer recovered from a compromised machine in the Gaza Strip revealed internal Breaking Dawn operational documents tied to the AlâAqsa Martyrsâ Brigades, including OPSEC requests and escalation triggers â Gaza Infosteal
- Dataâtheft wave claimed by ShinyHunters hit companies including Bumble, Panera, Match Group and CrunchBase with contractor account compromises, vishing and extortion tactics under investigation â ShinyHunters Wave
Supplyâchain & OSS Threats
- Researchers found over 454,600 malicious openâsource packages across npm, PyPI, Maven, NuGet and Hugging Face in 2025, with npm the primary vector and actor playbooks becoming industrialized â harden CI/CD and vet dependencies â Malicious OSS
- Google disrupted the large residential proxy network IPIDEA, removing millions of enrolled devices by taking down control domains and pursuing legal action â a notable takedown of commoditized proxy infrastructure â IPIDEA Takedown
- Scammers are abusing a real Microsoft Power BI address to send subscriptionâstyle scam emails that trick victims into calling and installing remoteâaccess tools â watch for [email protected] lures â PowerBI Scam
Crime Markets & Enforcement
- The FBI seized the RAMP cybercrime forum, taking Tor/clearnet domains and enabling access to user data that may ID operators and affiliates â RAMP Seized
- A coâcreator of Empire Market pleaded guilty to drug conspiracy after facilitating roughly $430 million in transactions and facing forfeiture of about $75 million in crypto; sentencing pending â Empire Guilty
- Slovakian operator of Kingdom/Kingdown Market pleaded guilty to conspiracy for running a darknet marketplace selling drugs, stolen data and cyber tools â domains and crypto were surrendered â Kingdom Plea
- Authorities in Hungary and Romania arrested teens tied to coordinated swatting and doxing campaigns that triggered false bomb threats; devices were seized and terrorismârelated charges filed â Teen Swatting
- U.S. prosecutors charged 31 more defendants (bringing the total to 87) in an international ATM jackpotting scheme tied to Tren de Aragua that used Ploutus malware to force cash dispensals â massive multinational probe continues â ATM Jackpotting, ATM Update
Infrastructure & Corporate Incidents
- LateâDecember attacks compromised control/communications at about 30 distributed generation sites in Poland; vendors/researchers reported differing attributions (Dragos: ELECTRUM; other reporting: Sandworm + DynoWiper) and disabled OT equipment at multiple locations â Poland Grid, Poland Report
- A major cyberattack disrupted services at Russian alarm and vehicle security provider Delta, causing vehicle lockouts and alarm failures while restoration continues and dataâleak claims circulate â Delta Outage
- New wave of breaches hit consumer platforms and business directories, with limited exposures reported and extortion/vishing linked to groups like ShinyHunters â investigations ongoing â Data Breach Wave
- Attackers are hijacking exposed LLM endpoints in a campaign named âBizarre Bazaarâ (> 35,000 sessions in 40 days) to cryptomine, resell API access, exfiltrate prompts and pivot laterally â secure and monitor LLM endpoints â Bizarre Bazaar
AI, Governance & Strategy
- SecurityWeekâs Zero Trust roundup frames identityâfirst continuous verification as a journey complicated by AI, OT/IT convergence and legacy perimeters â incremental progress and microsegmentation advised â Zero Trust
- Offensive security is shifting to continuous, AIâaugmented programs combining automation, threat intel and red/blue collaboration to find and remediate vulnerabilities faster â Offense Shift
- Experts warn against fully autonomous AI defense: model drift, poor data and lack of oversight risk systemic failure â keep humansâinâtheâloop and auditable governance â AI Caution
- AI agents embedded in regulated workflows are rewriting compliance controls and raising CISO responsibility for identity, access and continuous auditing under regimes like GDPR/SOX â adapt controls and monitoring â AI Compliance
Industry Moves & Protections
- WhatsApp is rolling out âStrict Account Settingsâ (lockdown mode) for highârisk users to block unknown media/calls, enforce twoâstep verification and harden code (new Rust media library) â optâin if targeted â WhatsApp Lockdown, WhatsApp Boost, WhatsApp Rollout
- Mesh Security raised $12 million to scale a Cybersecurity Mesh Architecture platform that automates crossâstack remediation and agentic response â Mesh Funding
- The American Hospital Association released guides for medical surge and cyber preparedness in U.S. hospitals emphasizing staffing, supply, space and systems to sustain care in crises â AHA Guides
- Report compares background activities of remoteâsupport tooling (e.g., GoTo Resolve) to ransomware tactics, underscoring the need to monitor vendor tools and background processes â GoTo Resolve