CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (20 January 2026)

Published: Loading…

At a Glance

  • ETSI released EN 304 223, establishing baseline cybersecurity requirements for AI models and systems deployed in real-world operational environments.
  • Russian-aligned hacktivist groups continued denial-of-service attacks against UK local government and critical infrastructure organisations, prompting repeated warnings from the NCSC.
  • Ingram Micro confirmed a July 2025 ransomware attack exposed personal data of more than 42,000 employees and job applicants after widespread system disruption.
  • Malicious browser extensions posing as ad blockers deliberately crashed Chrome and Edge browsers to deliver ClickFix-style lures and deploy remote access trojans.
  • A hardware vulnerability dubbed StackWarp undermined AMD SEV-SNP protections, allowing host-level attackers to execute code inside confidential virtual machines.
  • A Tennessee man pleaded guilty to repeatedly accessing the U.S. Supreme Court’s restricted filing system using stolen credentials and leaking data online.

Summary

European regulators formalised security expectations for artificial intelligence with the release of ETSI EN 304 223, defining baseline controls for AI models and data pipelines. Separately, indirect prompt injection against Google Gemini demonstrated how calendar invites could bypass authorisation safeguards and expose private scheduling data.

Disruptive activity linked to Russian-aligned hacktivist groups persisted across UK public services and infrastructure. Denial-of-service attacks continued to affect local authorities and online services, reinforcing ongoing warnings from the UK National Cyber Security Centre.

Browser extension abuse remained a dominant intrusion vector, with multiple campaigns using fake ad blockers to trigger deliberate browser crashes. Variants such as CrashFix, NexShield, and KongTuke lures enabled deployment of previously undocumented remote access trojans on enterprise systems.

Ransomware impacts extended beyond immediate outages as Ingram Micro confirmed personal data exposure affecting over 42,000 individuals following a July 2025 intrusion. Law enforcement activity also progressed against Black Basta affiliates, with raids conducted in Ukraine linked to wider ransomware operations.

Low-level vulnerabilities featured prominently, including StackWarp, which weakened AMD SEV-SNP protections across Zen 1–5 CPUs. The flaw allowed privileged host attackers to compromise confidential virtual machines, eroding isolation guarantees.

Criminal access brokerage and unauthorised system access remained active enforcement priorities. A Jordanian national admitted selling access to 50 corporate networks, while a Tennessee defendant pleaded guilty to breaching U.S. Supreme Court, AmeriCorps, and VA systems using stolen credentials.

Highlights of the Day

Researchers Exploit Infostealer to Spy on Its Operators

CyberArk Labs uncovered a vulnerability in the StealC malware’s management panel that allowed researchers to monitor operators and steal their session cookies. The flaw exposed operational details, including campaign activity abusing hijacked YouTube accounts and indicators pointing to a single Eastern European-based operator. The findings highlight how weaknesses in criminal malware infrastructure can undermine large-scale credential theft operations.

Malicious Extension Crashes Browsers to Lure Corporate Victims

Huntress researchers uncovered a KongTuke campaign using a malicious Chrome extension disguised as an ad blocker to deliberately crash browsers and display fake security warnings. The scheme tricks users into executing hidden commands, deploying different payloads based on whether systems are domain-joined, including a newly identified Python-based remote access trojan targeting enterprise environments. The activity highlights continued abuse of browser extension ecosystems and social engineering techniques to gain access to corporate networks.

Source: Huntress

Malicious VS Code Extensions Deliver Evelyn Stealer to Developers

Trend Micro analysed the Evelyn Stealer campaign, which uses weaponised Visual Studio Code extensions to infect developer systems through a multi-stage malware chain. The malware steals browser credentials, system data, and cryptocurrency information, using process hollowing, encryption, and extensive anti-analysis techniques to evade detection. Compromised developer environments can also serve as entry points into wider organisational networks.

Ingram Micro Confirms Ransomware Breach Impacting 42,000 People

Ingram Micro disclosed that a ransomware attack in July 2025 led to the theft of personal data belonging to more than 42,000 individuals, primarily employees and job applicants. Stolen information included names, contact details, dates of birth, and government-issued identification numbers, with attackers also deploying ransomware that caused widespread system outages. The incident was later claimed by the SafePay ransomware group, according to public reporting and regulatory filings.

Tennessee Man Pleads Guilty to Hacking Federal Court Systems

A Tennessee man pleaded guilty to unauthorised access of the U.S. Supreme Court’s electronic filing system, as well as accounts linked to AmeriCorps and the Veterans Affairs health platform. Court records show he used stolen credentials to access sensitive personal and medical information, some of which he shared publicly on social media. The offences occurred across multiple federal systems between August and October 2023.

Calendar Invites Used to Bypass Google Gemini Safeguards

Security researchers demonstrated how a crafted Google Calendar invite could embed a prompt injection that Gemini later executed during routine schedule queries. The technique enabled unauthorised access to private meeting data and silently created deceptive calendar entries without user interaction. Google confirmed the issue after responsible disclosure and implemented mitigations.

Source: Miggo

Daily Coverage

Developments
Etsi Ai StandardUk Hacktivist DdosIngram Micro BreachClickfix Extensions
Vulnerabilities
CVE-2025-62581Diaview (Critical)CVE-2025-62582Diaview (Critical)
Threat Groups
Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.