CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (14 January 2026)

Published: Loading…

At a Glance

  • VoidLink is a modular Linux malware framework providing access in cloud and container environments through rootkits, credential theft, and multi-channel command control.
  • CISA added CVE-2025-8110, an actively exploited Gogs path traversal flaw, to the Known Exploited Vulnerabilities catalogue affecting federal Git services.
  • DeVixor Android banking malware targeted Iranian users via phishing sites, combining credential theft, device surveillance, ransomware functions, and Telegram-managed infrastructure.
  • SHADOW#REACTOR delivered the Remcos remote access trojan using text-only staging, obfuscated scripts, in-memory execution, and MSBuild abuse on Windows.
  • Microsoft January 2026 updates fixed 114 vulnerabilities, including three zero-days and one exploited flaw, across Windows, Office, and related components.

Summary

Cloud-focused malware activity expanded with VoidLink providing modular implants, rootkits, and adaptive behaviour across containerised Linux environments. Separately, the GoBruteforcer botnet targeted crypto and blockchain projects by exploiting weak credentials in AI-generated server deployments.

Active exploitation of software flaws prompted coordinated responses, as CVE-2025-8110 in Gogs was added to CISA’s exploited catalogue. In parallel, CVE-2025-25249 exposed FortiOS and FortiSwitchManager to unauthenticated remote code execution through the CAPWAP controller daemon.

Mobile-centric financial threats persisted, with DeVixor campaigns harvesting banking credentials and SMS data from Iranian users through malicious APK distribution. Concurrently, NFC relay attacks enabled real-time payment fraud by relaying card communications between compromised devices.

Windows systems faced layered intrusion techniques as SHADOW#REACTOR used script-based loaders and in-memory execution to deploy Remcos. Large-scale browser-in-the-browser Facebook phishing simultaneously harvested credentials via fake login pop-ups hosted on trusted cloud platforms.

Vendor patch cycles addressed broad attack surfaces, with Microsoft January 2026 updates remediating exploited and zero-day flaws across core platforms. The Node.js runtime also received fixes for eight vulnerabilities affecting denial-of-service, permission bypass, and memory exposure conditions.

Highlights of the Day

Cloud-Native VoidLink Linux Malware Framework Uncovered

Check Point Research has disclosed VoidLink, a highly modular Linux malware framework designed for long-term, stealthy access in cloud and container environments. The framework adapts its behaviour to major cloud platforms and Kubernetes or Docker deployments, combining credential harvesting, rootkit capabilities, and multiple command-and-control channels. Researchers assess it as an actively evolving platform likely intended for commercial use, with no confirmed real-world infections observed so far.

CISA Flags Exploited Gogs Vulnerability in Federal Catalogue

The US Cybersecurity and Infrastructure Security Agency has added CVE-2025-8110, a path traversal flaw in the Gogs Git service, to its Known Exploited Vulnerabilities Catalogue. The inclusion follows evidence of active exploitation and reflects the catalogue’s role as a continuously updated record of vulnerabilities posing significant risk to federal systems.

DeVixor Android Malware Targets Iranian Banking Users

Cyble researchers have analysed DeVixor, an evolving Android banking trojan that combines credential theft, device surveillance, and ransomware capabilities in a single platform. Distributed through phishing websites posing as automotive businesses, the malware targets Iranian users and banks, harvesting SMS-based financial data and injecting code into banking pages to steal credentials. Analysis of hundreds of samples indicates an ongoing, large-scale campaign managed through Telegram and cloud-based infrastructure.

ShadowReactor Malware Chain Deploys Remcos via Text Staging

Securonix researchers have uncovered SHADOW#REACTOR, a multi-stage Windows malware campaign that delivers the Remcos remote access trojan through an unusual text-only staging process. The attack chain combines obfuscated VBS and PowerShell loaders, in-memory .NET execution protected by .NET Reactor, and abuse of MSBuild to complete deployment. This layered approach reduces on-disk traces and complicates detection while enabling persistent remote control of compromised systems.

AI Model Metadata Flaws Enable Remote Code Execution

Palo Alto Networks researchers identified remote code execution vulnerabilities in three open-source AI Python libraries from NVIDIA, Salesforce, and Apple-linked researchers. The flaws allow malicious code embedded in model metadata to execute when affected models are loaded, impacting widely used formats distributed via Hugging Face. No active exploitation has been observed, and fixes have been released by all affected projects.

Target Confirms Authenticity of Leaked Internal Source Code

Current and former Target employees have confirmed that source code and documentation shared online by a threat actor match real internal systems and development environments. The leaked sample references proprietary platforms, project names, and infrastructure consistent with Target’s internal CI/CD and cloud tooling. Following disclosure, Target accelerated access restrictions to its internal Git server, while the origin and scope of the data exposure remain unconfirmed.

Facebook Phishing Adopts Fake Login Pop-Ups

Trellix researchers report a surge in Facebook phishing campaigns using the “browser-in-the-browser” technique to mimic legitimate login pop-ups and harvest credentials. The activity escalated in late 2025, combining social engineering themes with abuse of trusted cloud hosting services and URL shorteners. The campaigns target Facebook users at scale and reflect increasing sophistication in visual deception and delivery methods.

Fortinet Discloses RCE Flaw in FortiOS Products

Fortinet has disclosed CVE-2025-25249, a high-severity remote code execution vulnerability affecting FortiOS and FortiSwitchManager. The flaw resides in the CAPWAP Wireless Aggregate Controller daemon and could allow unauthenticated attackers to execute arbitrary code remotely. The issue was identified internally, with no evidence of active exploitation reported at the time of disclosure.

Node.js Patches Eight Flaws Across Active Releases

The Node.js project has released security updates fixing eight vulnerabilities across all supported versions, including three rated high severity. The issues span denial-of-service conditions, permission system bypasses, and a memory exposure flaw affecting specific runtime configurations. According to analysis by Endor Labs, most vulnerabilities have constrained exploitability but affect a wide range of Node.js use cases.

Source: Endor Labs

Microsoft Fixes Three Zero-Days in January Updates

Microsoft’s January 2026 security updates address 114 vulnerabilities, including three zero-day flaws, one of which was actively exploited. The fixes span Windows, Office, and other components, with eight issues rated critical, largely involving remote code execution and privilege escalation. The release also removes vulnerable third-party modem drivers previously linked to in-the-wild attacks.

Daily Coverage

Developments
Voidlink FrameworkGogs ExploitationDevixor MalwareRemcos Delivery
Vulnerabilities
CVE-2026-20805Windows 10 Version 1809 10.0.17763.0 (Medium)CVE-2025-64155Fortisiem 7.4.0 (Critical)CVE-2025-25249Fortiswitchmanager 7.2.2 (High)CVE-2025-8110Improper Symbolic Link Handling In The Putcontents Api In Gogs Allows Local Execution Of Code.