Cybersecurity News | Daily Recap [29 Jan 2026]

Cybersecurity News | Daily Recap [29 Jan 2026]

Daily Recap, The day’s cybersecurity news shows ongoing exploitation of the WinRAR CVE-2025-8088 to drop silent payloads into Windows Startup folders by nation-state and criminal groups. It also highlights high-severity flaws such as Grist Core RCE in Pyodide, React2Shell deserialization, Fortinet FortiOS SSO bypass, and other attacks, underscoring urgent patching and proactive defense. #WinRAR #React2Shell

News:

Vulnerabilities & Exploits

  • WinRAR path-traversal (CVE-2025-8088) is still being exploited months after patch to drop silent payloads such as NESTPACKER/STOCKSTAY/POISONIVY into Windows Startup folders by nation-state and criminal groups – WinRAR Flaw, WinRAR Report
  • A critical Pyodide sandbox escape in Grist‑Core lets a single spreadsheet formula achieve RCE (patched in 1.7.9, CVSS 9.1) — upgrade now – Grist RCE
  • Two sandbox-escape flaws in n8n (including a 9.9-rated JS AST escape, CVE-2026-1470) allow authenticated RCE on self-hosted instances — apply patches – n8n Escape
  • SolarWinds Web Help Desk patched multiple critical auth-bypass and RCE flaws (CVE-2025-40551–40554) and a hardcoded-credentials issue — admins must update to 2026.1 immediately – Web Help Desk
  • React Server Components insecure-deserialization (CVE-2025-55182, “React2Shell”) is under active exploitation to deploy miners and botnets like XMRig, RustoBot and EtherRAT — hunt and patch – React2Shell
  • Fortinet patched an actively exploited FortiOS/FortiCloud SSO auth-bypass (CVE-2026-24858) and urges firmware upgrades, credential rotation and config audits – Fortinet SSO
  • Regional eScan update server breach pushed a malicious update with a modified loader and backdoor (CONSCTLX.exe); vendor isolated infra and urged remediation – eScan Update

Malware & Spyware

  • Romance-scam campaign GhostChat targets users in Pakistan with a fake chat app that performs silent surveillance and exfiltrates media via WhatsApp‑pairing techniques – GhostChat Spyware
  • Malicious and privacy‑invasive browser and IDE extensions are active: Chrome add-ons can spy on ChatGPT chats, and a fake Moltbot VS Code extension installs a ScreenConnect RAT on launch — investigate and remove untrusted extensions – Chrome Spy Extensions, Moltbot Extension
  • Wider Moltbot ecosystem risks: insecure deployments can leak API keys, OAuth tokens and conversation history and enable command execution, while local Moltbot storage is targeted by info‑stealers like RedLine – Moltbot Risk
  • Infostealer recovered from a compromised machine in the Gaza Strip revealed internal Breaking Dawn operational documents tied to the Al‑Aqsa Martyrs’ Brigades, including OPSEC requests and escalation triggers – Gaza Infosteal
  • Data‑theft wave claimed by ShinyHunters hit companies including Bumble, Panera, Match Group and CrunchBase with contractor account compromises, vishing and extortion tactics under investigation – ShinyHunters Wave

Supply‑chain & OSS Threats

  • Researchers found over 454,600 malicious open‑source packages across npm, PyPI, Maven, NuGet and Hugging Face in 2025, with npm the primary vector and actor playbooks becoming industrialized — harden CI/CD and vet dependencies – Malicious OSS
  • Google disrupted the large residential proxy network IPIDEA, removing millions of enrolled devices by taking down control domains and pursuing legal action — a notable takedown of commoditized proxy infrastructure – IPIDEA Takedown
  • Scammers are abusing a real Microsoft Power BI address to send subscription‑style scam emails that trick victims into calling and installing remote‑access tools — watch for [email protected] lures – PowerBI Scam

Crime Markets & Enforcement

  • The FBI seized the RAMP cybercrime forum, taking Tor/clearnet domains and enabling access to user data that may ID operators and affiliates – RAMP Seized
  • A co‑creator of Empire Market pleaded guilty to drug conspiracy after facilitating roughly $430 million in transactions and facing forfeiture of about $75 million in crypto; sentencing pending – Empire Guilty
  • Slovakian operator of Kingdom/Kingdown Market pleaded guilty to conspiracy for running a darknet marketplace selling drugs, stolen data and cyber tools — domains and crypto were surrendered – Kingdom Plea
  • Authorities in Hungary and Romania arrested teens tied to coordinated swatting and doxing campaigns that triggered false bomb threats; devices were seized and terrorism‑related charges filed – Teen Swatting
  • U.S. prosecutors charged 31 more defendants (bringing the total to 87) in an international ATM jackpotting scheme tied to Tren de Aragua that used Ploutus malware to force cash dispensals — massive multinational probe continues – ATM Jackpotting, ATM Update

Infrastructure & Corporate Incidents

  • Late‑December attacks compromised control/communications at about 30 distributed generation sites in Poland; vendors/researchers reported differing attributions (Dragos: ELECTRUM; other reporting: Sandworm + DynoWiper) and disabled OT equipment at multiple locations – Poland Grid, Poland Report
  • A major cyberattack disrupted services at Russian alarm and vehicle security provider Delta, causing vehicle lockouts and alarm failures while restoration continues and data‑leak claims circulate – Delta Outage
  • New wave of breaches hit consumer platforms and business directories, with limited exposures reported and extortion/vishing linked to groups like ShinyHunters — investigations ongoing – Data Breach Wave
  • Attackers are hijacking exposed LLM endpoints in a campaign named “Bizarre Bazaar” (> 35,000 sessions in 40 days) to cryptomine, resell API access, exfiltrate prompts and pivot laterally — secure and monitor LLM endpoints – Bizarre Bazaar

AI, Governance & Strategy

  • SecurityWeek’s Zero Trust roundup frames identity‑first continuous verification as a journey complicated by AI, OT/IT convergence and legacy perimeters — incremental progress and microsegmentation advised – Zero Trust
  • Offensive security is shifting to continuous, AI‑augmented programs combining automation, threat intel and red/blue collaboration to find and remediate vulnerabilities faster – Offense Shift
  • Experts warn against fully autonomous AI defense: model drift, poor data and lack of oversight risk systemic failure — keep humans‑in‑the‑loop and auditable governance – AI Caution
  • AI agents embedded in regulated workflows are rewriting compliance controls and raising CISO responsibility for identity, access and continuous auditing under regimes like GDPR/SOX — adapt controls and monitoring – AI Compliance

Industry Moves & Protections

  • WhatsApp is rolling out “Strict Account Settings” (lockdown mode) for high‑risk users to block unknown media/calls, enforce two‑step verification and harden code (new Rust media library) — opt‑in if targeted – WhatsApp Lockdown, WhatsApp Boost, WhatsApp Rollout
  • Mesh Security raised $12 million to scale a Cybersecurity Mesh Architecture platform that automates cross‑stack remediation and agentic response – Mesh Funding
  • The American Hospital Association released guides for medical surge and cyber preparedness in U.S. hospitals emphasizing staffing, supply, space and systems to sustain care in crises – AHA Guides
  • Report compares background activities of remote‑support tooling (e.g., GoTo Resolve) to ransomware tactics, underscoring the need to monitor vendor tools and background processes – GoTo Resolve

Vulnerabilities & Exploits

  • WinRAR path-traversal (CVE-2025-8088) is still being exploited months after patch to drop silent payloads such as NESTPACKER/STOCKSTAY/POISONIVY into Windows Startup folders by nation-state and criminal groups – WinRAR Flaw, WinRAR Report
  • A critical Pyodide sandbox escape in Grist‑Core lets a single spreadsheet formula achieve RCE (patched in 1.7.9, CVSS 9.1) — upgrade now – Grist RCE
  • Two sandbox-escape flaws in n8n (including a 9.9-rated JS AST escape, CVE-2026-1470) allow authenticated RCE on self-hosted instances — apply patches – n8n Escape
  • SolarWinds Web Help Desk patched multiple critical auth-bypass and RCE flaws (CVE-2025-40551–40554) and a hardcoded-credentials issue — admins must update to 2026.1 immediately – Web Help Desk
  • React Server Components insecure-deserialization (CVE-2025-55182, “React2Shell”) is under active exploitation to deploy miners and botnets like XMRig, RustoBot and EtherRAT — hunt and patch – React2Shell
  • Fortinet patched an actively exploited FortiOS/FortiCloud SSO auth-bypass (CVE-2026-24858) and urges firmware upgrades, credential rotation and config audits – Fortinet SSO
  • Regional eScan update server breach pushed a malicious update with a modified loader and backdoor (CONSCTLX.exe); vendor isolated infra and urged remediation – eScan Update

Malware & Spyware

  • Romance-scam campaign GhostChat targets users in Pakistan with a fake chat app that performs silent surveillance and exfiltrates media via WhatsApp‑pairing techniques – GhostChat Spyware
  • Malicious and privacy‑invasive browser and IDE extensions are active: Chrome add-ons can spy on ChatGPT chats, and a fake Moltbot VS Code extension installs a ScreenConnect RAT on launch — investigate and remove untrusted extensions – Chrome Spy Extensions, Moltbot Extension
  • Wider Moltbot ecosystem risks: insecure deployments can leak API keys, OAuth tokens and conversation history and enable command execution, while local Moltbot storage is targeted by info‑stealers like RedLine – Moltbot Risk
  • Infostealer recovered from a compromised machine in the Gaza Strip revealed internal Breaking Dawn operational documents tied to the Al‑Aqsa Martyrs’ Brigades, including OPSEC requests and escalation triggers – Gaza Infosteal
  • Data‑theft wave claimed by ShinyHunters hit companies including Bumble, Panera, Match Group and CrunchBase with contractor account compromises, vishing and extortion tactics under investigation – ShinyHunters Wave

Supply‑chain & OSS Threats

  • Researchers found over 454,600 malicious open‑source packages across npm, PyPI, Maven, NuGet and Hugging Face in 2025, with npm the primary vector and actor playbooks becoming industrialized — harden CI/CD and vet dependencies – Malicious OSS
  • Google disrupted the large residential proxy network IPIDEA, removing millions of enrolled devices by taking down control domains and pursuing legal action — a notable takedown of commoditized proxy infrastructure – IPIDEA Takedown
  • Scammers are abusing a real Microsoft Power BI address to send subscription‑style scam emails that trick victims into calling and installing remote‑access tools — watch for [email protected] lures – PowerBI Scam

Crime Markets & Enforcement

  • The FBI seized the RAMP cybercrime forum, taking Tor/clearnet domains and enabling access to user data that may ID operators and affiliates – RAMP Seized
  • A co‑creator of Empire Market pleaded guilty to drug conspiracy after facilitating roughly $430 million in transactions and facing forfeiture of about $75 million in crypto; sentencing pending – Empire Guilty
  • Slovakian operator of Kingdom/Kingdown Market pleaded guilty to conspiracy for running a darknet marketplace selling drugs, stolen data and cyber tools — domains and crypto were surrendered – Kingdom Plea
  • Authorities in Hungary and Romania arrested teens tied to coordinated swatting and doxing campaigns that triggered false bomb threats; devices were seized and terrorism‑related charges filed – Teen Swatting
  • U.S. prosecutors charged 31 more defendants (bringing the total to 87) in an international ATM jackpotting scheme tied to Tren de Aragua that used Ploutus malware to force cash dispensals — massive multinational probe continues – ATM Jackpotting, ATM Update

Infrastructure & Corporate Incidents

  • Late‑December attacks compromised control/communications at about 30 distributed generation sites in Poland; vendors/researchers reported differing attributions (Dragos: ELECTRUM; other reporting: Sandworm + DynoWiper) and disabled OT equipment at multiple locations – Poland Grid, Poland Report
  • A major cyberattack disrupted services at Russian alarm and vehicle security provider Delta, causing vehicle lockouts and alarm failures while restoration continues and data‑leak claims circulate – Delta Outage
  • New wave of breaches hit consumer platforms and business directories, with limited exposures reported and extortion/vishing linked to groups like ShinyHunters — investigations ongoing – Data Breach Wave
  • Attackers are hijacking exposed LLM endpoints in a campaign named “Bizarre Bazaar” (> 35,000 sessions in 40 days) to cryptomine, resell API access, exfiltrate prompts and pivot laterally — secure and monitor LLM endpoints – Bizarre Bazaar

AI, Governance & Strategy

  • SecurityWeek’s Zero Trust roundup frames identity‑first continuous verification as a journey complicated by AI, OT/IT convergence and legacy perimeters — incremental progress and microsegmentation advised – Zero Trust
  • Offensive security is shifting to continuous, AI‑augmented programs combining automation, threat intel and red/blue collaboration to find and remediate vulnerabilities faster – Offense Shift
  • Experts warn against fully autonomous AI defense: model drift, poor data and lack of oversight risk systemic failure — keep humans‑in‑the‑loop and auditable governance – AI Caution
  • AI agents embedded in regulated workflows are rewriting compliance controls and raising CISO responsibility for identity, access and continuous auditing under regimes like GDPR/SOX — adapt controls and monitoring – AI Compliance

Industry Moves & Protections

  • WhatsApp is rolling out “Strict Account Settings” (lockdown mode) for high‑risk users to block unknown media/calls, enforce two‑step verification and harden code (new Rust media library) — opt‑in if targeted – WhatsApp Lockdown, WhatsApp Boost, WhatsApp Rollout
  • Mesh Security raised $12 million to scale a Cybersecurity Mesh Architecture platform that automates cross‑stack remediation and agentic response – Mesh Funding
  • The American Hospital Association released guides for medical surge and cyber preparedness in U.S. hospitals emphasizing staffing, supply, space and systems to sustain care in crises – AHA Guides
  • Report compares background activities of remote‑support tooling (e.g., GoTo Resolve) to ransomware tactics, underscoring the need to monitor vendor tools and background processes – GoTo Resolve

Cybersecurity News | Daily Recap – hendryadrian.com