Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (30 January 2026)
Published: Loading…
At a Glance
- A romance-themed Android spyware campaign deployed GhostChat malware in Pakistan, disguising a chat application to exfiltrate data while routing messages through WhatsApp.
- Attackers compromised eScan antivirus update infrastructure on 20 January, distributing malware that blocked updates, established persistence, and contacted external control servers.
- Reconnaissance against Ivanti Connect Secure surged roughly 100-fold, with two parallel campaigns scanning for CVE-2025-0282 via a known authentication endpoint.
- North Korea-linked LABYRINTH CHOLLIMA split into three specialised groups, separating cryptocurrency operations from espionage targeting defence, manufacturing, and logistics sectors.
- npm ecosystem abuse escalated in 2025, with 1,241 malicious packages published through maintainer account takeovers affecting widely trusted developer dependencies.
Summary
Mobile and consumer-facing platforms were leveraged for covert surveillance and data exposure, including GhostChat Android spyware distributed through romance scams and an AI children’s toy leaking tens of thousands of private conversations. Both incidents involved misuse of trusted interfaces to collect sensitive personal data without user awareness.
Software supply chains remained a primary intrusion vector as attackers compromised eScan antivirus update servers and distributed trojanised EmEditor installers through manipulated MSI packages. In parallel, open-source ecosystems saw growing abuse through npm account takeovers, enabling malware distribution via highly trusted dependencies.
Enterprise infrastructure faced sustained pressure from vulnerability-driven activity, including a sharp increase in scanning for Ivanti Connect Secure CVE-2025-0282 and exploited zero-day flaws in Microsoft Office and Ivanti EPMM. These activities targeted exposed services and document workflows to gain initial access.
Nation-state and organised threat actors continued to refine tooling and structure, with LABYRINTH CHOLLIMA fragmenting into specialised units and UAT-8099 deploying region-specific IIS malware variants across Southeast Asia. These campaigns relied on web shells, PowerShell, and customised persistence mechanisms.
Cybercrime infrastructure disruptions and legal actions featured prominently, including the seizure of the RAMP forum, disruption of the IPIDEA residential proxy network, and convictions tied to Empire Market. At the same time, ransomware operations such as Interlock adapted tooling while maintaining established infrastructure overlap.
Highlights of the Day
DPRK hacking group splits into three specialised cyber units
CrowdStrike reports that the North Korea-linked LABYRINTH CHOLLIMA threat actor has evolved into three distinct adversaries with separate missions, malware toolsets, and targeting patterns. GOLDEN CHOLLIMA and PRESSURE CHOLLIMA now focus primarily on cryptocurrency and fintech operations, while the core LABYRINTH CHOLLIMA group concentrates on espionage against defence, manufacturing, logistics, and industrial sectors. Despite operating independently, the groups continue to share tools and infrastructure, indicating coordinated activity within the DPRK cyber ecosystem.
SQL injection flaw found in popular WordPress survey plugin
Patchstack has disclosed a high-severity SQL injection vulnerability in the Quiz and Survey Master WordPress plugin, affecting more than 40,000 active sites. The flaw allowed any logged-in user to manipulate database queries due to insufficient input validation in a REST API function. The issue has been assigned CVE-2025-67987 and was fixed in version 10.3.2.
Interlock ransomware adapts tools to bypass modern defences
Fortinet reports that the Interlock ransomware group continues to target organisations in the UK and US, with a particular focus on the education sector, while operating outside the common ransomware-as-a-service model. Recent investigations show the group adopting new tooling, including a process-killing utility abusing a vulnerable gaming driver, alongside established techniques for data theft and encryption. Despite these adaptations, Interlock activity still overlaps with previously documented infrastructure and malware ecosystems.
eScan antivirus update server abused in supply chain attack
Kaspersky reports that a supply chain attack compromised eScan antivirus updates, distributing previously unknown malware via a regional update server on 20 January. The malicious update deployed a multi-stage loader that blocked further updates, established persistence, and contacted external control servers. The incident was attributed to unauthorised access to update infrastructure rather than a software vulnerability and was contained within a day.
Popular AI assistant exposes credentials through insecure local storage
OX Security reports that the open-source AI assistant MoltBot stores credentials, API keys, and environment variables in cleartext on local systems, creating broad exposure if a device is compromised. Researchers also identified insecure coding patterns and a rapidly expanding contributor base, increasing supply chain and execution risks as adoption scales.
EmEditor installers tampered in coordinated supply chain attack
ReversingLabs analysis shows that EmEditor Windows installers were maliciously modified during a December 2025 supply chain compromise, with attackers embedding scripts into MSI packages to deploy PowerShell-based payloads. The investigation identified two distinct attack waves, reused command-and-control infrastructure, and forensic artefacts that clearly distinguish vendor-built installers from adversary-tampered versions. Findings indicate a sustained operation rather than an isolated incident.
AI toy exposed thousands of children’s private chat logs
An AI-powered children’s toy exposed around 50,000 chat logs after its cloud storage was misconfigured for public access, allowing anyone with a Gmail account to view the data. The logs included sensitive conversations ranging from schoolwork to personal and family matters, raising concerns about how children’s data is handled in connected products.
AI agents rival humans in targeted web hacking tests
Testing by Wiz found that autonomous AI agents successfully exploited 9 of 10 web security challenges when given clearly defined targets, often at very low cost and with high speed. Performance declined in broader, less directed scenarios, where the models struggled with prioritisation, creative pivots, and wide-scale enumeration.
Scanning for Ivanti Connect Secure surges across two campaigns
GreyNoise observed a roughly 100-fold increase in reconnaissance targeting Ivanti Connect Secure between 21 and 28 January, focused on CVE-2025-0282. Analysis identified two parallel campaigns: a high-volume operation concentrated in a single autonomous system and a quieter, widely distributed effort using thousands of IP addresses. Both targeted the same endpoint, indicating coordinated interest in a highly exploitable flaw.
npm account takeovers fuel rising open-source malware
Endor Labs reports a sharp rise in npm account takeovers during 2025, with 1,241 malicious packages confirmed, a 15-fold increase year on year. Attackers used compromised maintainer accounts to publish malware into trusted, widely downloaded projects, enabling rapid spread through developer environments and CI/CD pipelines. Several large campaigns showed how brief publication windows were sufficient to expose thousands of downstream users.
Daily Coverage