Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (24 January 2026)
Published: Loading…
At a Glance
- Microsoft warned of multi-stage adversary-in-the-middle phishing and business email compromise campaigns abusing SharePoint file sharing to target energy sector organisations.
- CISA added four vulnerabilities, including a Zimbra Collaboration Suite flaw, to its Known Exploited Vulnerabilities catalogue citing active exploitation.
- Fortinet confirmed attackers are bypassing December patches to exploit a FortiCloud single sign-on authentication flaw on fully patched FortiGate firewalls.
- US courts convicted two Venezuelan nationals for ATM jackpotting attacks using malware to force cash withdrawals exceeding $400,000.
- Malicious Python packages on PyPI and npm supply-chain abuse campaigns delivered infostealers, remote access malware, and large-scale data distribution.
Summary
Credential theft and account takeover activity remained prominent, with adversary-in-the-middle phishing campaigns abusing SharePoint file-sharing to compromise energy sector organisations. Parallel activity targeted Okta, Microsoft, and Google SSO accounts using voice phishing and real-time authentication interception.
Enterprise software vulnerabilities continued to face active exploitation, as CISA added multiple flaws to the KEV catalogue, including issues affecting Zimbra, Versa, and development tooling. Separately, attackers exploited a long-standing PowerPoint vulnerability dating back to 2009 after its inclusion on active exploitation lists.
Network and perimeter devices were impacted by authentication bypass flaws, with Fortinet FortiGate firewalls compromised despite December patches for FortiCloud SSO. Exploitation reports confirmed attackers achieved unauthorised access on fully updated devices across multiple environments.
Malware-driven financial crime activity resulted in legal action after ATM jackpotting operations led to convictions of two Venezuelan nationals in the United States. The attackers installed malware directly onto ATM systems, enabling forced cash withdrawals and sustained financial losses.
Software supply-chain abuse expanded across developer ecosystems, with malicious PyPI and npm packages delivering Python remote access trojans, infostealers, and encrypted data payloads. Separate campaigns used npm infrastructure to host credential harvesting pages and distribute non-code data at scale.
Large-scale data exposure incidents continued to surface, including an unsecured database containing 149 million credentials linked to infostealer malware. Additional breaches affected consumer platforms and public institutions, including UK local councils and German cultural organisations.
Highlights of the Day
Two Venezuelans convicted over ATM cash theft scheme
US courts convicted two Venezuelan nationals for using malicious software to force cash withdrawals from ATMs, a technique known as jackpotting. The pair installed malware directly onto machines after opening their casings, enabling full cash payouts and causing losses exceeding $400,000. Both men were sentenced, ordered to pay restitution, and will be deported, as authorities link the case to a wider, long-running ATM crime network.
SmarterMail flaw exploited for remote code execution
Huntress researchers observed active exploitation of a SmarterMail vulnerability that allows attackers to take over privileged accounts and achieve remote code execution. The flaw, tracked as CVE-2026-23760, was abused through unauthenticated password resets, enabling malicious system events to run commands on affected servers. The activity was seen across multiple victims and appears distinct from earlier SmarterMail exploitation campaigns.
Massive infostealer database exposes 149 million credentials
Researchers identified a publicly accessible database containing nearly 150 million usernames and passwords harvested by infostealer malware. The records spanned social media, financial services, entertainment platforms and some government-linked accounts, with data stored unencrypted and without access controls. The database was later taken offline, but its ownership and the duration of exposure remain unclear.
Malicious PyPI packages hide remote access malware
Researchers uncovered two Python packages on PyPI that secretly installed a remote access tool when imported. The packages impersonated a legitimate spellchecking library and concealed a malicious payload inside language resource files, activating it only in later versions. Analysis links the campaign to earlier Python supply chain attacks using similar techniques and infrastructure.
Fake font packages flood npm with massive data transfers
Researchers found hundreds of npm packages posing as font libraries that were used to distribute vast amounts of non-code data through the registry. The files, disguised as WOFF2 fonts, contained encrypted or compressed data and drove an estimated 4.3 pebibytes of downloads in a month without delivering malicious payloads. The incident strained npm’s infrastructure and highlighted how registry abuse, rather than malware, can threaten the sustainability of open-source platforms.
Old PowerPoint flaw returns to active exploitation lists
A PowerPoint code execution vulnerability first disclosed in 2009 has re-emerged after being added to the US government’s Known Exploited Vulnerabilities catalogue. CVE-2009-0556 affects legacy versions of Microsoft PowerPoint and allows attackers to run arbitrary code using specially crafted files.
Oracle Fusion Middleware flaw allows unauthorised data access
Oracle has patched a maximum-severity vulnerability affecting components of its Fusion Middleware suite, including Oracle HTTP Server and the WebLogic Server Proxy Plug-in. Tracked as CVE-2026-21962, the flaw allows unauthenticated remote attackers to create, modify, or delete critical data due to improper request handling. No active exploitation has been reported, but similar products have previously been targeted in large-scale campaigns.
curl ends bug bounty after surge in low-quality reports
The curl project will close its bug bounty programme and stop accepting vulnerability reports via HackerOne from February 2026. Maintainers cited a sustained influx of low-quality and AI-generated submissions that consumed review time without yielding valid findings. Security reports will continue through curl’s own disclosure channels, without financial rewards.
Daily Coverage