Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (21 January 2026)
Published: Loading…
At a Glance
- Multiple prompt injection flaws in Anthropic’s official MCP Git server enabled arbitrary file access and potential remote code execution.
- Tudou Guarantee, a Telegram-based scam marketplace, halted public transactions after processing more than $12 billion in cryptocurrency linked to fraud services.
- Cloudflare fixed an ACME validation flaw allowing requests to bypass WAF rules and reach origin servers through the /.well-known/acme-challenge path.
- VoidLink emerged as an advanced cloud-targeting Linux malware framework built largely using artificial intelligence by a single threat actor.
- Hacktivist groups expanded attacks on industrial control systems during 2025, moving beyond DDoS into intrusions affecting energy and transport sectors.
Summary
Illicit online marketplaces faced disruption as Tudou Guarantee ceased Telegram-based transactions after handling over $12 billion tied to scam infrastructure and fraud services. The platform expanded rapidly following Huione Guarantee’s closure and hosted merchants selling stolen data and laundering services.
Web infrastructure security was impacted by flaws in Cloudflare ACME validation, where certificate challenge requests bypassed configured WAF rules. The issue allowed direct origin access via a maintenance path until uniform enforcement was restored with a platform fix.
Malware development showed increased automation with VoidLink, a modular Linux framework targeting cloud environments and generated largely through artificial intelligence. Development artefacts indicated rapid creation timelines previously associated with well-resourced threat groups.
Hacktivist operations intensified against industrial control systems, shifting from website disruption to intrusions affecting operational technology. Activity concentrated on government, energy, and transport environments, with repeated targeting across Europe and Asia.
AI toolchain security weaknesses were highlighted by Anthropic MCP Git server flaws exploitable through prompt injection. The vulnerabilities enabled file access, deletion, and code execution when combined with other MCP integrations.
Social engineering campaigns continued to diversify delivery channels, using social media phishing and trusted developer ecosystems to deploy malware via DLL sideloading. These campaigns leveraged legitimate open-source tools to reduce detection while targeting high-value users.
Highlights of the Day
AI-built VoidLink signals shift in malware development
Check Point Research reports that VoidLink is the first documented case of an advanced malware framework developed predominantly using artificial intelligence. Exposed development artefacts show a single actor used AI-driven planning and coding to build a sophisticated, modular platform within days, rather than months. The findings indicate AI can significantly lower the barrier to producing complex malware previously associated with well-resourced threat groups.
Hacktivists expand attacks on critical infrastructure in 2025
Cyble reports that hacktivist activity in 2025 increasingly targeted critical infrastructure, moving beyond disruption to intrusions affecting industrial control systems and operational technology. The research links this shift to greater technical sophistication and closer alignment with state interests, particularly across Europe and Asia. Hacktivist sightings rose sharply over the year, with government, energy and transportation sectors most affected.
Tudou Guarantee marketplace winds down after $12bn flow
Tudou Guarantee, a Telegram-based marketplace tied to Southeast Asia’s scam economy, has largely ceased transactions after processing more than $12 billion in cryptocurrency, according to blockchain analysis. The platform expanded rapidly after the shutdown of Huione Guarantee, hosting merchants selling fraud services, stolen data and scam infrastructure. Its decline appears linked to sanctions and arrests targeting the Prince Group, although some associated services, including gambling operations, remain active.
Flaws exposed in Anthropic’s official MCP Git server
Cyata researchers identified three vulnerabilities in Anthropic’s official mcp-server-git that can be triggered through prompt injection, without direct system access. The flaws enable arbitrary file access and deletion, and can lead to code execution when combined with other MCP servers. The findings highlight security risks in AI tool integrations that execute actions based on model-controlled inputs.
ReliaQuest researchers uncovered a phishing campaign using social media messages to deliver malware through DLL sideloading and a legitimate open-source Python script. The technique leverages trusted platforms and tools to bypass detection and deploy likely remote access trojans. The activity highlights how non-email channels are increasingly used for scalable, low-effort intrusion campaigns.
Cloudflare ACME path bypassed WAF protections worldwide
Researchers reported a zero-day flaw that allowed traffic to reach origin servers behind Cloudflare via the ACME certificate validation path, bypassing configured WAF rules. Requests to /.well-known/acme-challenge/ were served directly by applications even when other paths were blocked, exposing origins to unintended access. Cloudflare confirmed and fixed the issue in October 2025, restoring uniform WAF enforcement.
Daily Coverage