Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (26 January 2026)
Published: Loading…
At a Glance
- CISA added the actively exploited VMware vCenter Server heap overflow CVE-2024-37079 to the KEV catalog after confirmed in-the-wild attacks.
- Sandworm attempted to deploy DynoWiper destructive malware during a late-December 2025 cyberattack targeting Poland’s national power grid infrastructure.
- A multi-stage phishing campaign in Russia delivered Amnesia RAT and ransomware through business-themed documents without exploiting software vulnerabilities.
- The KONNI threat group targeted blockchain developers using AI-generated PowerShell backdoors distributed via weaponised Windows shortcut files.
- Pwn2Own Automotive 2026 disclosed seventy-six zero-day vulnerabilities affecting vehicle infotainment systems, electric vehicle chargers, and related automotive software.
Summary
Active exploitation of enterprise software featured prominently, with CVE-2024-37079 added to the KEV catalog and widespread zero-days revealed in automotive systems. The issues affected VMware vCenter Server, vehicle infotainment platforms, and electric vehicle charging infrastructure.
State-aligned operations continued to target critical infrastructure, highlighted by Sandworm activity against Poland’s power grid using DynoWiper wiper malware. The attempted attack followed established patterns of disruptive operations against national energy systems.
Phishing-led intrusion chains remained a common delivery mechanism, with campaigns in Russia deploying Amnesia RAT alongside ransomware through routine business-themed documents. These attacks relied on user interaction rather than software exploitation to establish access.
Developer ecosystems also faced targeted campaigns, as KONNI used AI-generated PowerShell backdoors against blockchain engineers. Weaponised shortcut files and project-themed lures were used to reach development environments across the Asia-Pacific region.
Corporate and consumer exposure to cyber risk persisted alongside public-sector activity, with Nike investigating a potential data breach and password-manager software adding phishing URL warnings. Separately, government security posture remained in focus through expanded UK border surveillance technology spending and changes in US and Chinese security leadership engagement.
Highlights of the Day
CISA flags exploited VMware vCenter Server flaw
The US Cybersecurity and Infrastructure Security Agency has added a Broadcom VMware vCenter Server out-of-bounds write vulnerability to its Known Exploited Vulnerabilities Catalog. Tracked as CVE-2024-37079, the flaw has been observed in active exploitation and is described as a common attack vector with potential impact on government environments.
Sandworm linked to attempted attack on Poland’s power grid
ESET Research has attributed a late-2025 cyberattack targeting Poland’s energy sector to the Russia-aligned Sandworm group with medium confidence. The incident involved data-wiping malware, dubbed DynoWiper, though researchers said they are not aware of any successful disruption to power supply. The operation aligns with Sandworm’s established pattern of targeting critical infrastructure, particularly in Eastern Europe.
Multi-stage Windows malware blends espionage and ransomware
FortiGuard Labs has analysed a sophisticated multi-stage malware campaign targeting Windows users, primarily in Russia, that relies on social engineering rather than software exploits. The attack chain disables Microsoft Defender, conducts surveillance and data theft via Amnesia RAT, and culminates in ransomware and system lockout. The campaign makes extensive use of trusted cloud services such as GitHub, Dropbox and Telegram to host payloads and manage command-and-control activity.
KONNI uses AI-written PowerShell backdoors against developers
Check Point Research has identified a phishing campaign linked to the North Korea–aligned KONNI group that targets software developers working with blockchain technologies. The operation delivers an AI-generated, heavily obfuscated PowerShell backdoor via weaponised shortcut files disguised as project documentation. Researchers observed expanded targeting across the Asia-Pacific region, marking a shift from KONNI’s historically South Korea–focused activity.
Daily Coverage