CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (28 January 2026)

Published: Loading…

At a Glance

  • Microsoft issued emergency out-of-band patches for actively exploited Office zero-day CVE-2026-21509, added to CISA’s KEV catalogue after targeted real-world attacks.
  • Fortinet confirmed attackers exploited FortiCloud SSO authentication bypass CVE-2026-24858, enabling administrative access to customer devices through an alternate SAML path.
  • China-linked HoneyMyte campaigns expanded CoolClient backdoor capabilities, deploying browser credential stealers and data theft scripts against government targets across Asia and Europe.
  • Threat actors continued exploiting WinRAR vulnerability CVE-2025-8088, using crafted archives for initial access in campaigns linked to state-backed and criminal groups.
  • A critical vm2 Node.js sandbox escape flaw CVE-2026-22709 enabled unauthenticated attackers to execute arbitrary code on host systems via Promise handling weaknesses.

Summary

Active exploitation of enterprise software vulnerabilities dominated the daily cybersecurity landscape, with CVE-2026-21509 affecting Microsoft Office and prompting emergency out-of-band updates. The flaw enabled security feature bypass through crafted documents and was formally listed in CISA’s Known Exploited Vulnerabilities catalogue.

Authentication and access control weaknesses also featured prominently following confirmation of CVE-2026-24858 in FortiCloud single sign-on. Attackers abused an alternate SAML authentication path to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices, including fully patched systems.

Previously disclosed vulnerabilities continued to see widespread abuse, notably CVE-2025-8088 in WinRAR. Multiple threat actors leveraged path traversal techniques in malicious archives to establish initial access and deliver varied malware payloads.

Open-source and application sandboxing risks were highlighted by CVE-2026-22709 in the vm2 Node.js library. The flaw allowed complete sandbox escape and arbitrary code execution on host systems, affecting versions up to 3.10.1 and exposing dependent applications to remote compromise.

Cyberespionage activity linked to Chinese-aligned actors remained active, with HoneyMyte expanding its toolset through updated CoolClient backdoors. Campaigns deployed browser credential stealers, clipboard monitoring, and modular plugins, continuing a focus on government entities across Asia and Europe.

Highlights of the Day

Microsoft Patches Actively Exploited Office Zero-Day

Microsoft has released emergency out-of-band updates for a high-severity Microsoft Office zero-day tracked as CVE-2026-21509, which has been actively exploited in the wild. The flaw allows a local attacker to bypass Office security features through a specially crafted document, with exploitation requiring user interaction. The vulnerability has also been added to the US CISA Known Exploited Vulnerabilities catalogue.

HoneyMyte Expands Espionage Toolset With Updated CoolClient

The HoneyMyte threat group has updated its CoolClient backdoor and deployed new browser credential stealers and data theft scripts in recent campaigns across Asia and parts of Europe. Analysis shows expanded capabilities including clipboard monitoring, proxy credential theft, and modular plugins for file management and remote command execution. The activity continues to focus largely on government targets and is linked to previously known HoneyMyte and LuminousMoth operations.

Phishing Networks Exploit Canadian Services Through PayTool Ecosystem

CloudSEK has identified a coordinated fraud ecosystem targeting Canadians through phishing campaigns impersonating government services and national brands. The activity reuses shared infrastructure and phishing kits linked to the PayTool ecosystem, spanning fake traffic fines, tax services, postal deliveries, and airline bookings. The campaigns rely on SMS lures, typosquatted domains, and staged payment pages to harvest personal and financial data at scale.

Source: CloudSEK

Outlook Add-ins Enable Stealthy Email Data Exfiltration

Researchers uncovered a technique that abuses Microsoft Outlook add-ins to silently exfiltrate email content without generating audit logs, particularly when add-ins are installed via Outlook Web Access. The method exploits gaps in Microsoft 365’s auditing, allowing minimally permissioned add-ins to persist and transmit sensitive data while remaining invisible to standard monitoring tools. Microsoft has reviewed the findings and classified the issue as low severity, with no immediate fix planned.

WinRAR Flaw Fuels Widespread Malware Campaigns

Threat actors are actively exploiting the critical WinRAR vulnerability CVE-2025-8088 to gain initial access and deploy malware, despite the flaw being patched months earlier. Research shows the exploit is used by both state-backed groups linked to Russia and China and financially motivated criminals, relying on crafted archives that abuse path traversal to achieve persistence.

vm2 Sandbox Flaw Enables Full Code Escape

A critical vulnerability in the vm2 Node.js sandbox library allows attackers to escape isolation and execute arbitrary code on the host system. Tracked as CVE-2026-22709, the flaw stems from improper sanitisation of Promise callbacks, enabling exploitation without authentication or user interaction. The issue affects vm2 versions up to 3.10.1.

Source: Endor Labs

Chinese-Language Networks Drive Crypto Laundering Growth

Chinese-language money laundering networks have emerged as a dominant force in the illicit crypto economy, accounting for around 20% of known laundering activity over the past five years. Analysis shows these networks processed an estimated $16.1 billion in 2025, using Telegram-based services, informal brokers, and on-chain techniques to rapidly move and disguise illicit funds.

crates.io Adds Security Visibility, Restricts Risky Publishing Paths

crates.io has introduced a new Security tab on crate pages, surfacing known vulnerabilities directly from RustSec advisories at the point where developers choose dependencies. The update also expands Trusted Publishing to GitLab CI/CD while removing support for higher-risk GitHub Actions triggers linked to past CI compromises. Additional changes improve registry data quality, including clearer publication timestamps, cleaner download statistics, and encrypted OAuth tokens.

Source: Socket

Fortinet Blocks Exploited FortiCloud SSO Zero-Day Attacks

Fortinet has confirmed an actively exploited critical vulnerability in FortiCloud single sign-on that allowed attackers to bypass authentication and gain administrative access to customer devices, even on fully patched systems. The flaw, tracked as CVE-2026-24858, was abused via an alternate SSO authentication path, prompting Fortinet to implement server-side mitigations that block vulnerable devices while patches are still in development. The issue affects FortiOS, FortiManager, and FortiAnalyzer, and has been observed in real-world attacks.

CISA Chief Flagged for Uploading Sensitive Files to ChatGPT

US cyber officials investigated after CISA security systems detected sensitive government files uploaded to the public version of ChatGPT by acting cyber chief Madhu Gottumukkala in mid-2025. The Department of Homeland Security conducted an internal review to assess potential security impact, while CISA said the usage was authorised, limited, and occurred under temporary controls.

Source: POLITICO

Daily Coverage

Developments
Office Zero-Day PatchForticloud Sso BypassHoneymyte EspionageWinrar Exploitation
Vulnerabilities
CVE-2026-24858Fortianalyzer 7.6.0 (Critical)CVE-2025-8088Winrar 7.13 (High)CVE-2026-22709CVE-2026-1470CVE-2025-64328Filestore >= 17.0.2.36, < 17.0.3 (High)CVE-2025-40551Web Help Desk 12.8.8 Hf1 And Below (Critical)CVE-2025-40553CVE-2026-21509Microsoft Office 2019 19.0.0 (High)CVE-2026-0975Diaview (High)CVE-2025-67685Fortisandbox 5.0.0 (Low)
Threat Groups
SilenceSilence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.EARTH PRETA[Also known as: Mustang Panda, TWILL TYPHOON, FIREANT] Mustang Panda is a Chinabased cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and nongovernmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.ELECTRUMSandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.LuminousMothLuminousMoth is a Chinesespeaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted highprofile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.