Digital data pipelines exposing critical vulnerabilities and widespread breaches.

Daily Cybersecurity News - February 5, 2026

VMware Flaw Fuels Ransomware Attacks

High

Executive Summary

CISA has confirmed that a high-severity 2024 use-after-free vulnerability in VMware ESXi (CVE-2024-22252) has resurfaced and is now being actively exploited by ransomware gangs. The flaw allows attackers to escape the virtual machine's sandbox, leading to code execution on the host system and enabling hypervisor-level attacks.

Vulnerability Details

  • Affected Product: VMware ESXi (versions 7.0, 8.0), Workstation (17.x), and Fusion (13.x).
  • Identifier: CVE-2024-22252
  • CVSS Score: 8.4 (High) for ESXi, 9.3 (Critical) for Workstation/Fusion.
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate patching is required due to active exploitation by ransomware groups.
  • Attack Vector: An attacker with local administrative privileges on a guest virtual machine can exploit a use-after-free vulnerability in the XHCI USB controller. This allows them to execute code within the VMX process on the host, escaping the sandbox.
  • Ease of Exploit: The vulnerability requires an attacker to first gain administrative privileges on a guest VM, but once achieved, it can lead to a full VM escape.

Action Plan

  • Immediate Action: Upgrade to patched versions, including ESXi 8.0U2sb, ESXi 7.0U3p, Workstation 17.5.1, and Fusion 13.5.1.
  • Workaround: If immediate patching is not possible, temporarily remove the USB controller from virtual machines to mitigate the threat.
  • Detection: Monitor for unauthorized or suspicious activity within the VMX process and unusual access patterns from guest VMs to the host hypervisor.

Relevant professional terms

Sandbox Escape
A type of exploit where an attacker breaks out of a restricted virtual environment (the "sandbox") to gain access to the underlying host operating system and its resources.
Use-After-Free
A memory corruption vulnerability that occurs when a program attempts to use a pointer after the memory it points to has been deallocated. This can lead to unpredictable behavior, including code execution.

VS Code Configs Create Codespaces Risk

Executive Summary

Multiple attack vectors in GitHub Codespaces allow for remote code execution when a user opens a malicious repository or pull request. The issue stems from how VS Code-integrated configuration files are automatically processed, which Microsoft has currently deemed to be "by design." As this is considered intended functionality, no CVE has been assigned.

Vulnerability Details

  • Affected Product: GitHub Codespaces
  • Identifier: None Assigned (Considered "by design")
  • Exploitation Status: Proof of concept exists

Risk & Impact

  • Triage: High (Immediate user awareness required)
  • Attack Vector: An adversary can achieve remote code execution by tricking a user into opening a malicious repository or pull request in GitHub Codespaces. This is accomplished by abusing VS Code-integrated configuration files, specifically the devcontainer definition (via post-creation command injection), settings files, and task definitions.
  • Ease of Exploit: Simple. Requires user interaction with a malicious repository but leverages automated, intended functionality.

Action Plan

  • Immediate Action: Since this is considered intended behavior by Microsoft, there is no patch. User education is the primary defense.
  • Workaround: Only open and work within repositories from trusted sources. If a repository is untrusted, open it in the browser and ensure features like Settings Sync are disabled.
  • Detection: Monitor for suspicious commands being executed within Codespaces environments, especially those initiated from configuration files like `devcontainer.json`.

Relevant professional terms

GitHub Codespaces
A cloud-based development environment hosted by GitHub, which allows developers to code from a browser or a local IDE. It uses containerization to provide pre-configured and repeatable development setups.
devcontainer.json
A configuration file that defines the development container environment for a project. It specifies settings such as the Docker image, extensions to install, ports to forward, and commands to run after the container is created (`postCreateCommand`).
Source: SecurityWeek

Faulty Redactions Expose Epstein Secrets

Executive Summary

A failure in the document redaction process led to the public release of sensitive, unredacted data related to the Jeffrey Epstein case. Thousands of records were subsequently retracted after the error exposed personal and financial information of victims and other involved parties.

Attack Overview

  • Attack Path: The data exposure was not a cyberattack but a procedural failure. Sensitive text was hidden with superficial black boxes instead of being properly removed, allowing the underlying data to be copied and pasted.

Impact Assessment

  • Data Stolen: Exposed data included victim names, nude photos, emails, banking information, and Social Security numbers. It also contained credentials for online accounts and Epstein's full credit card details.
  • Operational Impact: Thousands of official court records were retracted by U.S. authorities to mitigate further data exposure.

Strategic Takeaway

This incident underscores the critical need for robust, technically sound redaction methods to permanently remove data, rather than merely obscuring it, before public document release.

Relevant professional terms

Redaction
The process of removing or obscuring sensitive information from a document before it is published or shared.
Personally Identifiable Information (PII)
Any data that can be used to identify a specific individual, such as names, Social Security numbers, or email addresses, which were exposed in this leak.

Ivy League Universities Suffer Data Breach

Executive Summary

The cybercrime group ShinyHunters has claimed responsibility for data breaches at Harvard and the University of Pennsylvania, publishing stolen data on its extortion website after the universities refused to pay a ransom. The attack exposed the personal and financial information of donors, alumni, and prospective students.

Attack Overview

  • Attack Path: The breaches originated from social engineering and voice phishing ("vishing") attacks that targeted the universities' alumni and development systems.
  • Attacker: ShinyHunters

Impact Assessment

  • Data Stolen: Over 2.2 million records, including personally identifiable information (PII), donation histories, and contact details for high-profile donors.

Strategic Takeaway

This incident underscores the vulnerability of academic institutions to sophisticated social engineering campaigns targeting valuable donor and alumni data for extortion.

Relevant professional terms

Cybercrime Group
An organized group of individuals who use computers and networks to commit criminal activities, often for financial gain.
Vishing (Voice Phishing)
A type of cyber attack where criminals use phone calls and social engineering tactics to trick individuals into revealing sensitive personal or financial information.
Source: TechCrunch

Asia-Linked APT Strikes Global Infrastructure

Executive Summary

A suspected state-aligned espionage group operating from Asia has compromised government and critical infrastructure organizations in 37 countries. The campaign, dubbed "Shadow Campaigns," involved extensive reconnaissance against 155 nations, primarily targeting government ministries for intelligence gathering.

Key TTPs

  • Initial Access: Sophisticated phishing emails with malicious links intended to trick users into installing a malware loader.
  • Execution: Exploitation of known vulnerabilities in a wide range of common software products.
  • Defense Evasion: Use of a previously unknown Linux kernel rootkit, tracked as ShadowGuard, to maintain stealth and control.

Campaign Analysis

This operation signifies a large-scale, coordinated cyberespionage effort focused on entities involved in economic, trade, and diplomatic functions. The actor's alarming scale and methods pose a long-term risk to national security and critical services globally.

Targeting & Infrastructure

  • Target Profile: National-level law enforcement, border control, ministries of finance, and departments related to trade and natural resources.
  • Infrastructure: The operational infrastructure is primarily located in Asia.

Relevant Terms

  • Reconnaissance: The initial phase of an attack where adversaries gather information about their targets to plan their operations.
  • Rootkit: A type of malicious software designed to gain unauthorized access to a computer and conceal its presence.
Source: Unit 42

DEAD VAX Campaign Delivers RAT via Fake PDFs

Executive Summary

The DEAD VAX campaign targets users with phishing emails containing links to virtual hard disk (VHD) files disguised as PDF documents. The goal is to install AsyncRAT, a remote access trojan, allowing attackers to monitor and assume full control of the victim's computer.

Key TTPs

  • Initial Access: Phishing emails link to VHD files hosted on the InterPlanetary File System (IPFS).
  • Execution: Users who double-click the fake PDF mount the VHD, which contains a malicious Windows Script File (WSF) that executes via user interaction.
  • Defense Evasion: The campaign uses obfuscated scripts and injects the final AsyncRAT payload directly into trusted Windows processes to execute in-memory, avoiding disk-based detection.

Campaign Analysis

This multi-stage attack abuses legitimate Windows features, like auto-mounting VHD files, to bypass security controls. The use of decentralized IPFS hosting makes the malicious payload more resilient to takedowns.

Relevant Terms

  • AsyncRAT: A remote access trojan that allows an attacker to covertly control and monitor an infected computer, enabling data theft and surveillance.
  • Virtual Hard Disk (VHD): A file format that represents a virtual hard drive. Windows can mount these files, making them appear as a physical disk to the system.
Source: Malwarebytes

Cyberattacks Target Common Workflows

Executive Summary

Recent threat intelligence reveals a strategic shift by attackers, who are now targeting routine developer workflows, remote access tools, and cloud identity paths to initiate intrusions and establish persistence.

Key Findings

  • Attackers can abuse GitHub Codespaces by exposing public ports on the cloud development environment to serve malware.
  • As of January 2026, researchers are tracking 57 active Command-and-Control (C2) servers for AsyncRAT, a popular remote access trojan.
  • "Bring Your Own Vulnerable Driver" (BYOVD) attacks have escalated significantly, with threat actors using legitimate, flawed drivers to gain kernel-level system access and disable security tools.

The Bottom Line

The modern attack surface has expanded beyond traditional perimeters to include the very tools that enable productivity. Security leaders must prioritize visibility and controls within developer environments, cloud identity systems, and remote access pathways, as these are the new front lines for initial compromise.

Relevant Terms

  • BYOVD (Bring Your Own Vulnerable Driver): An attack where an adversary loads a legitimate but flawed driver onto a system to exploit its vulnerabilities, typically to gain high-level permissions and disable security software.
  • C2 (Command and Control): The server infrastructure that attackers use to send commands to compromised systems and receive stolen data from them.