It's been a busy 24 hours in the cyber world with a flurry of significant data breaches, critical vulnerabilities (including an actively exploited zero-day), and some fascinating new threat intelligence on malware and attack techniques. Let's dive in:
Recent Cyber Attacks and Breaches ๐จ
- Multiple organisations have reported data breaches, affecting millions of individuals. Monroe University disclosed a 2024 breach impacting over 320,000 people, exposing personal, financial, and health data. Spanish energy giant Endesa is investigating claims of a 1.05 TB data theft affecting 20 million customers.
- Australia's Victorian Department of Education reset student passwords after an attack exposed names, school details, and encrypted passwords, while cloud marketplace Pax8 accidentally exposed internal business and Microsoft licensing data for 1,800 MSP partners.
- Eurail confirmed a breach exposing passport numbers, bank details, and even photocopies of IDs for some DiscoverEU travellers. In Belgium, AZ Monica hospitals were hit by a cyberattack, forcing surgery cancellations and the transfer of critical patients, likely due to ransomware. Poland also thwarted a major cyberattack on its power grid, attributing it to Russia.
- Ukraine's Defense Forces were targeted in a charity-themed campaign by the Russian 'Void Blizzard' (aka 'Laundry Bear') group, delivering the PluggyApe backdoor via malicious PIF files in instant messages.
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/monroe-university-says-2024-data-breach-affects-320-000-people/
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/endesa_breach/
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/victorian-department-of-education-notifies-parents-of-data-breach/
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/cloud-marketplace-pax8-accidentally-exposes-data-on-1-800-msp-partners/
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/eurail_breach/
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/belgium_hospital_cyberattack/
๐๏ธ The Record | https://therecord.media/belgium-hospital-cyberattack-antwerp-az-monica
๐๏ธ The Record | https://therecord.media/poland-cyberattack-grid-russia
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/ukraines-army-targeted-in-new-charity-themed-malware-campaign/
New Threat Research and Tradecraft ๐ก๏ธ
- North Korea's IT worker scheme and cryptocurrency heists continue to fund its weapons program, impacting over 40 countries. The U.S. urged UN member states to take tougher action, highlighting the sophisticated identity theft and remote work fraud used by these actors.
- A new, advanced cloud-native Linux malware framework, VoidLink, has been discovered. Written in Zig, Go, and C, it features custom loaders, implants, rootkits, and over 30 plugins designed for modern cloud environments (Kubernetes, Docker, AWS, GCP, Azure), with sophisticated anti-analysis and anti-forensics capabilities.
- Researchers identified a "Reprompt" attack method that could hijack Microsoft Copilot sessions, allowing attackers to exfiltrate sensitive data via hidden malicious prompts in URLs. This leverages parameter-to-prompt injection, double-request, and chain-request techniques to bypass safeguards.
- The DeadLock ransomware gang is using Polygon smart contracts to hide their command-and-control (C2) infrastructure, making it difficult for defenders to block their operations. This novel technique allows for frequent rotation of proxy server URLs, a method also observed with North Korean state-sponsored attackers.
- Microsoft, in collaboration with international law enforcement, disrupted RedVDS, a fast-growing cybercrime-as-a-service marketplace. RedVDS facilitated over $40 million in fraud, providing cybercriminals with disposable virtual computers for phishing, business email compromise, and real estate scams.
- Predator spyware operators are using sophisticated anti-analysis techniques, including an error code system (e.g., "error code 304" for security tools detected) to diagnose failed infections and evade researchers. It also suppresses crash logs and can detect network monitoring by privacy-conscious users.
- The Kimwolf botnet, a splinter of the Aisuru DDoS botnet, has rapidly grown to over 2 million infected unofficial Android TV devices. Its operators abuse residential proxy networks for local control, primarily targeting Minecraft servers with short, high-volume DDoS attacks.
๐๏ธ The Record | https://therecord.media/40-countries-impacted-nk-it-thefts-united-nations
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/new-voidlink-malware-framework-targets-linux-cloud-servers/
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/voidlink_linux_malware/
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/reprompt-attack-let-hackers-hijack-microsoft-copilot-sessions/
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/deadlock_ransomware_smart_contracts/
๐คซ CyberScoop | https://cyberscoop.com/microsoft-seizes-disrupts-redvds-cybercrime-marketplace/
๐๏ธ The Record | https://therecord.media/microsoft-redvds-cybercrime-scam
๐คซ CyberScoop | https://cyberscoop.com/predator-spyware-demonstrates-troubleshooting-researcher-dodging-capabilities/
๐คซ CyberScoop | https://cyberscoop.com/kimwolf-aisuru-botnet-lumen-technologies/
Vulnerabilities and Exploitation โ ๏ธ
- Microsoft's January Patch Tuesday addressed 112 vulnerabilities, including one actively exploited information disclosure zero-day (CVE-2026-20805) in Desktop Window Manager. This medium-severity flaw (CVSS 5.5) can leak memory addresses, potentially aiding privilege escalation or arbitrary code execution, and CISA has added it to its Known Exploited Vulnerabilities catalog.
- Vulnerabilities in popular AI/ML Python libraries (NeMo, Uni2TS, FlexTok) used in Hugging Face models allow remote attackers to hide and execute malicious code in metadata. These RCE flaws, tracked by CVEs, stem from improper use of Hydra's instantiate() function, affecting models with millions of downloads.
- A "most severe AI-driven vulnerability to date" in ServiceNow's Virtual Agent chatbot allowed arbitrary attackers to gain full platform control. Authentication issues (universal credential, email-only user impersonation) combined with agentic AI capabilities enabled admin account creation and lateral movement to connected systems.
- A critical Node.js vulnerability (CVE-2025-59466, CVSS 7.5) can cause server crashes via async_hooks stack overflow, leading to denial-of-service. This impacts numerous frameworks and APM tools like React Server Components, Next.js, and Datadog, as Node.js exits instead of gracefully handling the exception.
- Exploit code has been publicly released for a critical FortiSIEM command injection flaw (CVE-2025-25256), allowing unauthenticated remote attackers to execute commands or code. The vulnerability, a combination of arbitrary write with admin permissions and privilege escalation to root, affects versions 6.7 to 7.5.
๐คซ CyberScoop | https://cyberscoop.com/microsoft-patch-tuesday-january-2026/
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/patch_tuesday_january_2026/
๐๏ธ The Record | https://therecord.media/desktop-windows-manager-vulnerability-added-to-cisa-list
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/13/ai_python_library_bugs_allow/
๐จ Dark Reading | https://www.darkreading.com/remote-workforce/ai-vulnerability-servicenow
๐ฐ The Hacker News | https://thehackernews.com/2026/01/critical-nodejs-vulnerability-can-cause.html
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/exploit-code-shared-for-critical-fortisiem-command-injection-flaw/
Threat Landscape Commentary ๐
- Taiwan is experiencing a significant increase in cyber pressure from China, with an average of 2.63 million attacks daily in 2025, a 6% rise from the previous year. Energy infrastructure saw a tenfold increase, and emergency/hospital systems a 54% jump, indicating a deliberate attempt to disrupt critical infrastructure during both peacetime and potential conflict.
- Western cyber agencies, including the NCSC, CISA, and FBI, have issued new guidance warning about growing digital threats to industrial operational technology (OT). With OT systems increasingly connected, they present a larger attack surface for ransomware gangs and state-backed hackers, necessitating strong authentication, network segmentation, and minimised remote access.
๐จ Dark Reading | https://www.darkreading.com/cyber-risk/taiwan-sees-greater-cyber-pressure-from-china
๐๏ธ The Record | https://therecord.media/cyber-agencies-warn-of-industrial-system-threats
Data Privacy ๐
- California's Attorney General has launched an investigation into xAI's Grok AI tool over allegations it's being used to create nonconsensual sexually explicit deepfakes of women and children. This follows similar probes by the UK's Ofcom and the Paris Prosecutor's Office, highlighting growing regulatory concern over AI-generated content.
- The California Privacy Protection Agency (CPPA) Board has appointed Nicole Ozer, a privacy and surveillance expert and former ACLU leader, as a new member. This appointment is expected to significantly influence the agency's data privacy policy decisions.
๐๏ธ The Record | https://therecord.media/california-grok-deepfakes-investigation
๐คซ CyberScoop | https://cyberscoop.com/california-ag-investigates-xai-grok-nonconsensual-deepfakes-defiance-act/
๐๏ธ The Record | https://therecord.media/ccpa-appoints-new-board-member
Regulatory Issues and Changes โ๏ธ
- France's data protection regulator, CNIL, has fined telecom companies Free and Free Mobile a collective โฌ42 million ($48.9 million) for GDPR violations stemming from an October 2024 data breach that compromised over 24 million customer records, including IBANs. The fines were due to inadequate security measures (weak VPN authentication, ineffective detection), insufficient breach notification, and excessive data retention.
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/france_fines_free_free_mobile/
๐๏ธ The Record | https://therecord.media/france-data-regulator-fine
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/security/france-fines-free-mobile-42-million-over-2024-data-breach-incident/
Government Staffing and Program Changes ๐๏ธ
- Alex Fitzsimmons, acting director of the Department of Energyโs Office of Cybersecurity, Energy and Emergency Response (CESER), endorsed new cybersecurity bills for the energy sector and highlighted a new AI-driven cyber defence program, AI-FORTS. This comes amidst Democratic concerns over thousands of job cuts at the Department of Energy impacting cybersecurity and reliability.
- Sean Plankey has been re-nominated by President Trump to lead the Cybersecurity and Infrastructure Security Agency (CISA). His previous nomination stalled in the Senate last year due to holds from Senators over unrelated issues.
๐คซ CyberScoop | https://cyberscoop.com/ceser-chief-touts-ai-projects-congressional-dems-point-to-cuts/
๐คซ CyberScoop | https://cyberscoop.com/sean-plankey-re-nominated-to-lead-cisa/
Everything Else ๐ก
- Anthropic, an AI upstart, has invested $1.5 million in the Python Software Foundation (PSF) to enhance security in the Python ecosystem, specifically CPython and the Python Package Index (PyPI). This aims to protect millions of PyPI users from supply-chain attacks and could benefit other open-source package repositories.
- Microsoft has resolved a known issue where security applications were incorrectly flagging a core Windows component, WinSqlite3.dll, as vulnerable to a memory corruption flaw (CVE-2025-6965). The update addresses these false positive detections across various Windows client and server platforms.
๐ต๐ผ The Register | https://go.theregister.com/feed/www.theregister.com/2026/01/14/anthropic_python_security/
๐ค Bleeping Computer | https://www.bleepingcomputer.com/news/microsoft/microsoft-updates-windows-dll-that-triggered-security-alerts/
#CyberSecurity #ThreatIntelligence #DataBreach #Ransomware #Vulnerability #ZeroDay #APT #Malware #AI #CloudSecurity #OTSecurity #GDPR #InfoSec #PatchTuesday #IncidentResponse