Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (14 January 2026)
Published: Loading…
At a Glance
- VoidLink is a modular Linux malware framework providing access in cloud and container environments through rootkits, credential theft, and multi-channel command control.
- CISA added CVE-2025-8110, an actively exploited Gogs path traversal flaw, to the Known Exploited Vulnerabilities catalogue affecting federal Git services.
- DeVixor Android banking malware targeted Iranian users via phishing sites, combining credential theft, device surveillance, ransomware functions, and Telegram-managed infrastructure.
- SHADOW#REACTOR delivered the Remcos remote access trojan using text-only staging, obfuscated scripts, in-memory execution, and MSBuild abuse on Windows.
- Microsoft January 2026 updates fixed 114 vulnerabilities, including three zero-days and one exploited flaw, across Windows, Office, and related components.
Summary
Cloud-focused malware activity expanded with VoidLink providing modular implants, rootkits, and adaptive behaviour across containerised Linux environments. Separately, the GoBruteforcer botnet targeted crypto and blockchain projects by exploiting weak credentials in AI-generated server deployments.
Active exploitation of software flaws prompted coordinated responses, as CVE-2025-8110 in Gogs was added to CISA’s exploited catalogue. In parallel, CVE-2025-25249 exposed FortiOS and FortiSwitchManager to unauthenticated remote code execution through the CAPWAP controller daemon.
Mobile-centric financial threats persisted, with DeVixor campaigns harvesting banking credentials and SMS data from Iranian users through malicious APK distribution. Concurrently, NFC relay attacks enabled real-time payment fraud by relaying card communications between compromised devices.
Windows systems faced layered intrusion techniques as SHADOW#REACTOR used script-based loaders and in-memory execution to deploy Remcos. Large-scale browser-in-the-browser Facebook phishing simultaneously harvested credentials via fake login pop-ups hosted on trusted cloud platforms.
Vendor patch cycles addressed broad attack surfaces, with Microsoft January 2026 updates remediating exploited and zero-day flaws across core platforms. The Node.js runtime also received fixes for eight vulnerabilities affecting denial-of-service, permission bypass, and memory exposure conditions.
Highlights of the Day
Cloud-Native VoidLink Linux Malware Framework Uncovered
Check Point Research has disclosed VoidLink, a highly modular Linux malware framework designed for long-term, stealthy access in cloud and container environments. The framework adapts its behaviour to major cloud platforms and Kubernetes or Docker deployments, combining credential harvesting, rootkit capabilities, and multiple command-and-control channels. Researchers assess it as an actively evolving platform likely intended for commercial use, with no confirmed real-world infections observed so far.
CISA Flags Exploited Gogs Vulnerability in Federal Catalogue
The US Cybersecurity and Infrastructure Security Agency has added CVE-2025-8110, a path traversal flaw in the Gogs Git service, to its Known Exploited Vulnerabilities Catalogue. The inclusion follows evidence of active exploitation and reflects the catalogue’s role as a continuously updated record of vulnerabilities posing significant risk to federal systems.
DeVixor Android Malware Targets Iranian Banking Users
Cyble researchers have analysed DeVixor, an evolving Android banking trojan that combines credential theft, device surveillance, and ransomware capabilities in a single platform. Distributed through phishing websites posing as automotive businesses, the malware targets Iranian users and banks, harvesting SMS-based financial data and injecting code into banking pages to steal credentials. Analysis of hundreds of samples indicates an ongoing, large-scale campaign managed through Telegram and cloud-based infrastructure.
ShadowReactor Malware Chain Deploys Remcos via Text Staging
Securonix researchers have uncovered SHADOW#REACTOR, a multi-stage Windows malware campaign that delivers the Remcos remote access trojan through an unusual text-only staging process. The attack chain combines obfuscated VBS and PowerShell loaders, in-memory .NET execution protected by .NET Reactor, and abuse of MSBuild to complete deployment. This layered approach reduces on-disk traces and complicates detection while enabling persistent remote control of compromised systems.
Palo Alto Networks researchers identified remote code execution vulnerabilities in three open-source AI Python libraries from NVIDIA, Salesforce, and Apple-linked researchers. The flaws allow malicious code embedded in model metadata to execute when affected models are loaded, impacting widely used formats distributed via Hugging Face. No active exploitation has been observed, and fixes have been released by all affected projects.
Target Confirms Authenticity of Leaked Internal Source Code
Current and former Target employees have confirmed that source code and documentation shared online by a threat actor match real internal systems and development environments. The leaked sample references proprietary platforms, project names, and infrastructure consistent with Target’s internal CI/CD and cloud tooling. Following disclosure, Target accelerated access restrictions to its internal Git server, while the origin and scope of the data exposure remain unconfirmed.
Facebook Phishing Adopts Fake Login Pop-Ups
Trellix researchers report a surge in Facebook phishing campaigns using the “browser-in-the-browser” technique to mimic legitimate login pop-ups and harvest credentials. The activity escalated in late 2025, combining social engineering themes with abuse of trusted cloud hosting services and URL shorteners. The campaigns target Facebook users at scale and reflect increasing sophistication in visual deception and delivery methods.
Fortinet Discloses RCE Flaw in FortiOS Products
Fortinet has disclosed CVE-2025-25249, a high-severity remote code execution vulnerability affecting FortiOS and FortiSwitchManager. The flaw resides in the CAPWAP Wireless Aggregate Controller daemon and could allow unauthenticated attackers to execute arbitrary code remotely. The issue was identified internally, with no evidence of active exploitation reported at the time of disclosure.
Node.js Patches Eight Flaws Across Active Releases
The Node.js project has released security updates fixing eight vulnerabilities across all supported versions, including three rated high severity. The issues span denial-of-service conditions, permission system bypasses, and a memory exposure flaw affecting specific runtime configurations. According to analysis by Endor Labs, most vulnerabilities have constrained exploitability but affect a wide range of Node.js use cases.
Microsoft Fixes Three Zero-Days in January Updates
Microsoft’s January 2026 security updates address 114 vulnerabilities, including three zero-day flaws, one of which was actively exploited. The fixes span Windows, Office, and other components, with eight issues rated critical, largely involving remote code execution and privilege escalation. The release also removes vulnerable third-party modem drivers previously linked to in-the-wild attacks.
Daily Coverage