Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (28 January 2026)
Published: Loading…
At a Glance
- Microsoft issued emergency out-of-band patches for actively exploited Office zero-day CVE-2026-21509, added to CISA’s KEV catalogue after targeted real-world attacks.
- Fortinet confirmed attackers exploited FortiCloud SSO authentication bypass CVE-2026-24858, enabling administrative access to customer devices through an alternate SAML path.
- China-linked HoneyMyte campaigns expanded CoolClient backdoor capabilities, deploying browser credential stealers and data theft scripts against government targets across Asia and Europe.
- Threat actors continued exploiting WinRAR vulnerability CVE-2025-8088, using crafted archives for initial access in campaigns linked to state-backed and criminal groups.
- A critical vm2 Node.js sandbox escape flaw CVE-2026-22709 enabled unauthenticated attackers to execute arbitrary code on host systems via Promise handling weaknesses.
Summary
Active exploitation of enterprise software vulnerabilities dominated the daily cybersecurity landscape, with CVE-2026-21509 affecting Microsoft Office and prompting emergency out-of-band updates. The flaw enabled security feature bypass through crafted documents and was formally listed in CISA’s Known Exploited Vulnerabilities catalogue.
Authentication and access control weaknesses also featured prominently following confirmation of CVE-2026-24858 in FortiCloud single sign-on. Attackers abused an alternate SAML authentication path to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices, including fully patched systems.
Previously disclosed vulnerabilities continued to see widespread abuse, notably CVE-2025-8088 in WinRAR. Multiple threat actors leveraged path traversal techniques in malicious archives to establish initial access and deliver varied malware payloads.
Open-source and application sandboxing risks were highlighted by CVE-2026-22709 in the vm2 Node.js library. The flaw allowed complete sandbox escape and arbitrary code execution on host systems, affecting versions up to 3.10.1 and exposing dependent applications to remote compromise.
Cyberespionage activity linked to Chinese-aligned actors remained active, with HoneyMyte expanding its toolset through updated CoolClient backdoors. Campaigns deployed browser credential stealers, clipboard monitoring, and modular plugins, continuing a focus on government entities across Asia and Europe.
Highlights of the Day
Microsoft Patches Actively Exploited Office Zero-Day
Microsoft has released emergency out-of-band updates for a high-severity Microsoft Office zero-day tracked as CVE-2026-21509, which has been actively exploited in the wild. The flaw allows a local attacker to bypass Office security features through a specially crafted document, with exploitation requiring user interaction. The vulnerability has also been added to the US CISA Known Exploited Vulnerabilities catalogue.
HoneyMyte Expands Espionage Toolset With Updated CoolClient
The HoneyMyte threat group has updated its CoolClient backdoor and deployed new browser credential stealers and data theft scripts in recent campaigns across Asia and parts of Europe. Analysis shows expanded capabilities including clipboard monitoring, proxy credential theft, and modular plugins for file management and remote command execution. The activity continues to focus largely on government targets and is linked to previously known HoneyMyte and LuminousMoth operations.
Phishing Networks Exploit Canadian Services Through PayTool Ecosystem
CloudSEK has identified a coordinated fraud ecosystem targeting Canadians through phishing campaigns impersonating government services and national brands. The activity reuses shared infrastructure and phishing kits linked to the PayTool ecosystem, spanning fake traffic fines, tax services, postal deliveries, and airline bookings. The campaigns rely on SMS lures, typosquatted domains, and staged payment pages to harvest personal and financial data at scale.
Outlook Add-ins Enable Stealthy Email Data Exfiltration
Researchers uncovered a technique that abuses Microsoft Outlook add-ins to silently exfiltrate email content without generating audit logs, particularly when add-ins are installed via Outlook Web Access. The method exploits gaps in Microsoft 365’s auditing, allowing minimally permissioned add-ins to persist and transmit sensitive data while remaining invisible to standard monitoring tools. Microsoft has reviewed the findings and classified the issue as low severity, with no immediate fix planned.
WinRAR Flaw Fuels Widespread Malware Campaigns
Threat actors are actively exploiting the critical WinRAR vulnerability CVE-2025-8088 to gain initial access and deploy malware, despite the flaw being patched months earlier. Research shows the exploit is used by both state-backed groups linked to Russia and China and financially motivated criminals, relying on crafted archives that abuse path traversal to achieve persistence.
vm2 Sandbox Flaw Enables Full Code Escape
A critical vulnerability in the vm2 Node.js sandbox library allows attackers to escape isolation and execute arbitrary code on the host system. Tracked as CVE-2026-22709, the flaw stems from improper sanitisation of Promise callbacks, enabling exploitation without authentication or user interaction. The issue affects vm2 versions up to 3.10.1.
Chinese-Language Networks Drive Crypto Laundering Growth
Chinese-language money laundering networks have emerged as a dominant force in the illicit crypto economy, accounting for around 20% of known laundering activity over the past five years. Analysis shows these networks processed an estimated $16.1 billion in 2025, using Telegram-based services, informal brokers, and on-chain techniques to rapidly move and disguise illicit funds.
crates.io Adds Security Visibility, Restricts Risky Publishing Paths
crates.io has introduced a new Security tab on crate pages, surfacing known vulnerabilities directly from RustSec advisories at the point where developers choose dependencies. The update also expands Trusted Publishing to GitLab CI/CD while removing support for higher-risk GitHub Actions triggers linked to past CI compromises. Additional changes improve registry data quality, including clearer publication timestamps, cleaner download statistics, and encrypted OAuth tokens.
Fortinet Blocks Exploited FortiCloud SSO Zero-Day Attacks
Fortinet has confirmed an actively exploited critical vulnerability in FortiCloud single sign-on that allowed attackers to bypass authentication and gain administrative access to customer devices, even on fully patched systems. The flaw, tracked as CVE-2026-24858, was abused via an alternate SSO authentication path, prompting Fortinet to implement server-side mitigations that block vulnerable devices while patches are still in development. The issue affects FortiOS, FortiManager, and FortiAnalyzer, and has been observed in real-world attacks.
CISA Chief Flagged for Uploading Sensitive Files to ChatGPT
US cyber officials investigated after CISA security systems detected sensitive government files uploaded to the public version of ChatGPT by acting cyber chief Madhu Gottumukkala in mid-2025. The Department of Homeland Security conducted an internal review to assess potential security impact, while CISA said the usage was authorised, limited, and occurred under temporary controls.
Daily Coverage