Digital shields breached by critical software flaws and AI threats.

Daily Cybersecurity News - February 4, 2026

Google Looker Flaws Allow Total Takeover

Medium

Executive Summary

Tenable Research discovered two critical vulnerabilities in Google Looker, collectively dubbed "LookOut," which could lead to remote code execution and theft of sensitive database credentials. Tracked as CVE-2025-12743, these vulnerabilities have been patched by Google, and self-hosted customers are urged to update immediately.

Vulnerability Details

  • Affected Product: Google Looker (Self-Hosted/On-Premises)
  • Identifier: CVE-2025-12743
  • CVSS Score: 6.0 (Medium)
  • Exploitation Status: No evidence of exploitation in the wild.

Risk & Impact

  • Triage: Urgent for organizations with self-hosted Looker instances.
  • Attack Vector: One vector involves a Remote Code Execution (RCE) chain allowing full server control. The second is an error-based SQL injection that allows an attacker to intercept HTTP requests and modify parameters to connect to and exfiltrate data from Looker's internal database.
  • Ease of Exploit: The attack requires technical effort but could grant an attacker the "keys to the kingdom," enabling data theft, manipulation, and lateral movement within the network.

Action Plan

  • Immediate Action: Self-hosted instances should be upgraded to a patched version: 25.12.30+, 25.10.54+, 25.6.79+, 25.0.89+, or 24.18.209+. Releases 25.14 and higher are not affected.
  • Workaround: No workaround is available; upgrading is the only mitigation.
  • Detection: Monitor for unusual connections or queries to the internal Looker database and unexpected processes originating from the Looker server.

Relevant professional terms

Remote Code Execution (RCE)
A class of software vulnerability that allows a malicious actor to execute arbitrary commands or code on a target machine or in a target process over a network.
On-Premises (On-Prem)
A software and hardware delivery model where the infrastructure is installed and runs on the private property of an organization, rather than in a remote facility such as a cloud provider's data center.
Source: Tenable

SolarWinds Flaw Sparks Urgent Patching

Critical

Executive Summary

CISA has flagged a new critical vulnerability, CVE-2025-40551, in SolarWinds Web Help Desk as actively exploited. This "Untrusted Data Deserialization" flaw allows unauthenticated remote command execution. Federal agencies have been ordered to patch by February 6, 2026, creating an immediate 3-day remediation window for all sectors.

Vulnerability Details

  • Affected Product: SolarWinds Web Help Desk (versions prior to 2026.1)
  • Identifier: CVE-2025-40551 (New)
  • CVSS Score: 9.8 (Critical)
  • Exploitation Status: Actively Exploited (Added to CISA KEV Feb 3, 2026)

Risk & Impact

  • Triage: Critical. The short 3-day federal deadline indicates imminent, high-impact targeting.
  • Attack Vector: Unauthenticated attackers can exploit a Java deserialization weakness to run arbitrary commands on the host machine.
  • Ease of Exploit: High. Researcher Jimi Sebree (Horizon3[.]ai) confirmed the flaw allows remote command execution without credentials.

Action Plan

  • Immediate Action: Upgrade to the newly released Web Help Desk 2026.1. This version uses a modern framework designed to eliminate these legacy vulnerabilities.
  • Alternative: If full migration is impossible, check for emergency hotfixes, but 2026.1 is the primary fix.
  • Detection: Monitor logs for unusual child processes or unexpected command execution originating from the Web Help Desk service.

Relevant professional terms

Deserialization
The process of reconstructing data objects from a stream of bytes. Vulnerabilities here allow attackers to inject malicious objects that execute code upon reconstruction.
CISA (Cybersecurity and Infrastructure Security Agency)
A U.S. federal agency responsible for improving cybersecurity and infrastructure protection across all levels of government, coordinating cybersecurity programs with U.S. states, and improving the government's protections against cyberattacks.

AI Toy Exposes Private Children's Chats

Executive Summary

Bondu, the creator of an AI-powered plush toy, exposed approximately 50,000 private chat transcripts between children and their toys. The data was left accessible on a web console that allowed anyone with a standard Google account to log in and view sensitive information.

Attack Overview

  • Attack Path: The exposure stemmed from an unsecured web administration panel (console[.]bondu[.]com) that lacked proper authentication, allowing access with any Google account. This was not a hack but a severe security misconfiguration.
  • Attacker: The vulnerability was discovered by security researchers Joseph Thacker and Joel Margolis.

Impact Assessment

  • Data Stolen: Exposed data included over 50,000 chat transcripts, children's names, birth dates, and family details.

Strategic Takeaway

This incident highlights the critical failure of implementing basic authentication controls on administrative portals, especially for products handling sensitive data from children.

Relevant professional terms

Authentication
The process of verifying the identity of a user or process to allow access to a system. In this case, it was improperly configured.
Data Exposure
An incident where sensitive information is unintentionally left accessible to the public, often due to misconfiguration, rather than being stolen through a cyberattack.
Source: Malwarebytes

Step Finance Rocked by $40M Crypto Heist

Executive Summary

Step Finance, a Solana-based DeFi platform, lost approximately $40 million in digital assets after attackers compromised the personal devices of company executives. The breach allowed threat actors to gain privileged access and drain funds from several of the platform's treasury wallets.

Attack Overview

  • Attack Path: Attackers gained initial access by compromising the personal devices of senior executives, which led to unauthorized access to the platform's treasury wallets. This was not a smart contract exploit but a breach of operational security.

Impact Assessment

  • Data Stolen: Approximately $40 million in various digital assets, primarily SOL tokens, were stolen from treasury wallets.
  • Operational Impact: The platform halted some operations to reinforce security and advised users not to interact with the STEP token. The breach caused the native STEP token's value to plummet by over 80%.

Strategic Takeaway

This incident highlights the critical risk of targeting personnel with high-level privileges, demonstrating that human operational security is as crucial as protocol-level defenses.

Relevant professional terms

DeFi (Decentralized Finance)
A blockchain-based form of finance that does not rely on central financial intermediaries like brokerages, exchanges, or banks to offer traditional financial instruments.
Treasury Wallets
Digital wallets used by a project or company to store its own funds and assets, separate from user-deposited funds.

Amaranth Dragon Escalates Regional Espionage

Executive Summary

The China-linked threat actor Amaranth Dragon is conducting targeted cyber-espionage campaigns against government and law enforcement agencies in Southeast Asia. The group leverages software vulnerabilities to gain initial access for long-term intelligence collection.

Key TTPs

  • Initial Access: Exploiting vulnerabilities like CVE-2025-8088 in WinRAR with malicious archive files.
  • Execution: Using legitimate tools and custom loaders to run encrypted payloads from C2 servers.
  • Defense Evasion: Employing geofencing on attack infrastructure to interact only with specific target countries, minimizing exposure.

Campaign Analysis

This campaign demonstrates a tightly scoped and stealthy operation, with attacks timed to coincide with sensitive political events to increase engagement. The rapid weaponization of a publicly disclosed vulnerability shows the actor's efficiency and focus on establishing persistent access for geopolitical espionage.

Targeting & Infrastructure

  • Target Profile: Government and law enforcement agencies in Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines.
  • Infrastructure: Command-and-control (C2) servers are often placed behind Cloudflare infrastructure to mask their origin.

Relevant Terms

  • C2 (Command and Control): An infrastructure of servers and software used by an attacker to communicate with and manage compromised devices.
  • Geofencing: A technique to restrict access to infrastructure or services based on the geographical location of a user or device, used here to avoid detection.

Actors Disable Defenses With Revoked Driver

Executive Summary

Threat actors are deploying a malicious tool that abuses a legitimate, signed kernel driver from EnCase forensic software to disable security products. This "EDR Killer" is designed to terminate dozens of security tools, allowing attackers to operate undetected after an initial compromise.

Key TTPs

  • Execution: The tool is typically deployed after initial access has been achieved, often as a precursor to ransomware.
  • Defense Evasion: It uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique, loading a revoked but signed EnCase driver to gain kernel-level privileges needed to terminate EDR and antivirus processes.

Campaign Analysis

This tool marks a continuing trend of attackers abusing legitimate and signed drivers to bypass security controls. By disabling endpoint defenses, these EDR killers enable threat actors to deploy further payloads like ransomware with a higher chance of success.

Relevant Terms

  • EDR (Endpoint Detection and Response): A cybersecurity solution that continuously monitors endpoint devices (like laptops and servers) to detect and respond to advanced threats.
  • Signed Kernel Driver: A low-level software component with a trusted digital signature that allows it to operate with the highest privileges within the operating system's core (kernel).

Generative AI Doubles Phishing Threat

Executive Summary

According to cybersecurity firm Cofense, generative AI is dramatically increasing the scale and sophistication of phishing, doubling the rate of malicious emails detected in the past year. Attackers are now leveraging AI to create flawless, personalized campaigns that bypass traditional security filters.

Key Findings

  • The rate of detected phishing emails has more than doubled, from one every 42 seconds in 2024 to one every 19 seconds in 2025.
  • Business Email Compromise (BEC) attacks have surged, with "conversational" phishing emails that contain no malicious links or attachments accounting for 18% of the total.
  • AI enables polymorphic attacks, where threat actors dynamically alter email content, URLs, and logos to evade detection for each specific victim.

The Bottom Line

The rise of AI-driven phishing marks a strategic shift from volume to quality at scale. Security leaders must assume that automated, context-aware, and grammatically perfect attacks can now target any employee, rendering traditional training that relies on spotting errors less effective. This necessitates a greater emphasis on behavior-based email security solutions and a zero-trust mindset that verifies unusual requests, even from seemingly legitimate internal and external sources.

Relevant Terms

  • Business Email Compromise (BEC): A sophisticated scam where an attacker impersonates a trusted executive or vendor to trick an employee into transferring funds or revealing sensitive data.
  • Polymorphic Attack: A type of cyberattack that constantly changes its identifiable features, such as code or content, to evade detection by signature-based security tools.