
Daily Cybersecurity News - February 4, 2026
Google Looker Flaws Allow Total Takeover
MediumExecutive Summary
Tenable Research discovered two critical vulnerabilities in Google Looker, collectively dubbed "LookOut," which could lead to remote code execution and theft of sensitive database credentials. Tracked as CVE-2025-12743, these vulnerabilities have been patched by Google, and self-hosted customers are urged to update immediately.
Vulnerability Details
- Affected Product: Google Looker (Self-Hosted/On-Premises)
- Identifier: CVE-2025-12743
- CVSS Score: 6.0 (Medium)
- Exploitation Status: No evidence of exploitation in the wild.
Risk & Impact
- Triage: Urgent for organizations with self-hosted Looker instances.
- Attack Vector: One vector involves a Remote Code Execution (RCE) chain allowing full server control. The second is an error-based SQL injection that allows an attacker to intercept HTTP requests and modify parameters to connect to and exfiltrate data from Looker's internal database.
- Ease of Exploit: The attack requires technical effort but could grant an attacker the "keys to the kingdom," enabling data theft, manipulation, and lateral movement within the network.
Action Plan
- Immediate Action: Self-hosted instances should be upgraded to a patched version: 25.12.30+, 25.10.54+, 25.6.79+, 25.0.89+, or 24.18.209+. Releases 25.14 and higher are not affected.
- Workaround: No workaround is available; upgrading is the only mitigation.
- Detection: Monitor for unusual connections or queries to the internal Looker database and unexpected processes originating from the Looker server.
Relevant professional terms
- Remote Code Execution (RCE)
- A class of software vulnerability that allows a malicious actor to execute arbitrary commands or code on a target machine or in a target process over a network.
- On-Premises (On-Prem)
- A software and hardware delivery model where the infrastructure is installed and runs on the private property of an organization, rather than in a remote facility such as a cloud provider's data center.
Source: Tenable
SolarWinds Flaw Sparks Urgent Patching
CriticalExecutive Summary
CISA has flagged a new critical vulnerability, CVE-2025-40551, in SolarWinds Web Help Desk as actively exploited. This "Untrusted Data Deserialization" flaw allows unauthenticated remote command execution. Federal agencies have been ordered to patch by February 6, 2026, creating an immediate 3-day remediation window for all sectors.
Vulnerability Details
- Affected Product: SolarWinds Web Help Desk (versions prior to 2026.1)
- Identifier: CVE-2025-40551 (New)
- CVSS Score: 9.8 (Critical)
- Exploitation Status: Actively Exploited (Added to CISA KEV Feb 3, 2026)
Risk & Impact
- Triage: Critical. The short 3-day federal deadline indicates imminent, high-impact targeting.
- Attack Vector: Unauthenticated attackers can exploit a Java deserialization weakness to run arbitrary commands on the host machine.
- Ease of Exploit: High. Researcher Jimi Sebree (Horizon3[.]ai) confirmed the flaw allows remote command execution without credentials.
Action Plan
- Immediate Action: Upgrade to the newly released Web Help Desk 2026.1. This version uses a modern framework designed to eliminate these legacy vulnerabilities.
- Alternative: If full migration is impossible, check for emergency hotfixes, but 2026.1 is the primary fix.
- Detection: Monitor logs for unusual child processes or unexpected command execution originating from the Web Help Desk service.
Relevant professional terms
- Deserialization
- The process of reconstructing data objects from a stream of bytes. Vulnerabilities here allow attackers to inject malicious objects that execute code upon reconstruction.
- CISA (Cybersecurity and Infrastructure Security Agency)
- A U.S. federal agency responsible for improving cybersecurity and infrastructure protection across all levels of government, coordinating cybersecurity programs with U.S. states, and improving the government's protections against cyberattacks.
Source: BleepingComputer
AI Toy Exposes Private Children's Chats
Executive Summary
Bondu, the creator of an AI-powered plush toy, exposed approximately 50,000 private chat transcripts between children and their toys. The data was left accessible on a web console that allowed anyone with a standard Google account to log in and view sensitive information.
Attack Overview
- Attack Path: The exposure stemmed from an unsecured web administration panel (console[.]bondu[.]com) that lacked proper authentication, allowing access with any Google account. This was not a hack but a severe security misconfiguration.
- Attacker: The vulnerability was discovered by security researchers Joseph Thacker and Joel Margolis.
Impact Assessment
- Data Stolen: Exposed data included over 50,000 chat transcripts, children's names, birth dates, and family details.
Strategic Takeaway
This incident highlights the critical failure of implementing basic authentication controls on administrative portals, especially for products handling sensitive data from children.
Relevant professional terms
- Authentication
- The process of verifying the identity of a user or process to allow access to a system. In this case, it was improperly configured.
- Data Exposure
- An incident where sensitive information is unintentionally left accessible to the public, often due to misconfiguration, rather than being stolen through a cyberattack.
Source: Malwarebytes
Step Finance Rocked by $40M Crypto Heist
Executive Summary
Step Finance, a Solana-based DeFi platform, lost approximately $40 million in digital assets after attackers compromised the personal devices of company executives. The breach allowed threat actors to gain privileged access and drain funds from several of the platform's treasury wallets.
Attack Overview
- Attack Path: Attackers gained initial access by compromising the personal devices of senior executives, which led to unauthorized access to the platform's treasury wallets. This was not a smart contract exploit but a breach of operational security.
Impact Assessment
- Data Stolen: Approximately $40 million in various digital assets, primarily SOL tokens, were stolen from treasury wallets.
- Operational Impact: The platform halted some operations to reinforce security and advised users not to interact with the STEP token. The breach caused the native STEP token's value to plummet by over 80%.
Strategic Takeaway
This incident highlights the critical risk of targeting personnel with high-level privileges, demonstrating that human operational security is as crucial as protocol-level defenses.
Relevant professional terms
- DeFi (Decentralized Finance)
- A blockchain-based form of finance that does not rely on central financial intermediaries like brokerages, exchanges, or banks to offer traditional financial instruments.
- Treasury Wallets
- Digital wallets used by a project or company to store its own funds and assets, separate from user-deposited funds.
Source: BleepingComputer
Amaranth Dragon Escalates Regional Espionage
Executive Summary
The China-linked threat actor Amaranth Dragon is conducting targeted cyber-espionage campaigns against government and law enforcement agencies in Southeast Asia. The group leverages software vulnerabilities to gain initial access for long-term intelligence collection.
Key TTPs
- Initial Access: Exploiting vulnerabilities like CVE-2025-8088 in WinRAR with malicious archive files.
- Execution: Using legitimate tools and custom loaders to run encrypted payloads from C2 servers.
- Defense Evasion: Employing geofencing on attack infrastructure to interact only with specific target countries, minimizing exposure.
Campaign Analysis
This campaign demonstrates a tightly scoped and stealthy operation, with attacks timed to coincide with sensitive political events to increase engagement. The rapid weaponization of a publicly disclosed vulnerability shows the actor's efficiency and focus on establishing persistent access for geopolitical espionage.
Targeting & Infrastructure
- Target Profile: Government and law enforcement agencies in Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines.
- Infrastructure: Command-and-control (C2) servers are often placed behind Cloudflare infrastructure to mask their origin.
Relevant Terms
- C2 (Command and Control): An infrastructure of servers and software used by an attacker to communicate with and manage compromised devices.
- Geofencing: A technique to restrict access to infrastructure or services based on the geographical location of a user or device, used here to avoid detection.
Source: Check Point Research
Actors Disable Defenses With Revoked Driver
Executive Summary
Threat actors are deploying a malicious tool that abuses a legitimate, signed kernel driver from EnCase forensic software to disable security products. This "EDR Killer" is designed to terminate dozens of security tools, allowing attackers to operate undetected after an initial compromise.
Key TTPs
- Execution: The tool is typically deployed after initial access has been achieved, often as a precursor to ransomware.
- Defense Evasion: It uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique, loading a revoked but signed EnCase driver to gain kernel-level privileges needed to terminate EDR and antivirus processes.
Campaign Analysis
This tool marks a continuing trend of attackers abusing legitimate and signed drivers to bypass security controls. By disabling endpoint defenses, these EDR killers enable threat actors to deploy further payloads like ransomware with a higher chance of success.
Relevant Terms
- EDR (Endpoint Detection and Response): A cybersecurity solution that continuously monitors endpoint devices (like laptops and servers) to detect and respond to advanced threats.
- Signed Kernel Driver: A low-level software component with a trusted digital signature that allows it to operate with the highest privileges within the operating system's core (kernel).
Source: BleepingComputer
Generative AI Doubles Phishing Threat
Executive Summary
According to cybersecurity firm Cofense, generative AI is dramatically increasing the scale and sophistication of phishing, doubling the rate of malicious emails detected in the past year. Attackers are now leveraging AI to create flawless, personalized campaigns that bypass traditional security filters.
Key Findings
- The rate of detected phishing emails has more than doubled, from one every 42 seconds in 2024 to one every 19 seconds in 2025.
- Business Email Compromise (BEC) attacks have surged, with "conversational" phishing emails that contain no malicious links or attachments accounting for 18% of the total.
- AI enables polymorphic attacks, where threat actors dynamically alter email content, URLs, and logos to evade detection for each specific victim.
The Bottom Line
The rise of AI-driven phishing marks a strategic shift from volume to quality at scale. Security leaders must assume that automated, context-aware, and grammatically perfect attacks can now target any employee, rendering traditional training that relies on spotting errors less effective. This necessitates a greater emphasis on behavior-based email security solutions and a zero-trust mindset that verifies unusual requests, even from seemingly legitimate internal and external sources.
Relevant Terms
- Business Email Compromise (BEC): A sophisticated scam where an attacker impersonates a trusted executive or vendor to trick an employee into transferring funds or revealing sensitive data.
- Polymorphic Attack: A type of cyberattack that constantly changes its identifiable features, such as code or content, to evade detection by signature-based security tools.
Source: Infosecurity Magazine