Floating servers depicting widespread ransomware attacks and cloud breaches.

Daily Cybersecurity News – February 6, 2026

SmarterMail Flaw Fuels Ransomware Attacks

Critical

Executive Summary

A critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-24423, in SmarterTools SmarterMail is being actively exploited in ransomware attacks. The flaw allows attackers to take control of email servers by sending malicious HTTP requests, prompting an urgent warning from CISA for immediate patching.

Vulnerability Details

  • Affected Product: SmarterMail versions prior to build 9511
  • Identifier: CVE-2026-24423
  • CVSS Score: 9.3 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Critical. Immediate patching is required due to active exploitation by ransomware groups.
  • Attack Vector: The vulnerability is exploited via the ConnectToHub API, which allows unauthenticated users to send malicious HTTP requests. An attacker can point the SmarterMail server to a malicious HTTP server, which then serves an OS command that gets executed by the application.
  • Ease of Exploit: Trivial. The flaw does not require authentication, allowing attackers to easily target any vulnerable internet-facing server.

Action Plan

  • Immediate Action: Upgrade to SmarterMail Build 9511 or later. This build, released on January 15, 2026, contains patches for this and other critical vulnerabilities.
  • Workaround: No specific workaround has been provided other than upgrading. Restricting access to the webmail interface from untrusted IP addresses may provide a layer of mitigation.
  • Detection: Monitor server logs for suspicious POST requests to the /api/v1/settings/sysadmin/connect-to-hub endpoint (the primary RCE vector). Additionally, watch for traffic to /api/v1/auth/force-reset-password, often used in chained attacks to bypass authentication. Look for newly created, unexpected .aspx files in system directories.

Relevant professional terms

Remote Code Execution (RCE)
A class of software vulnerability that allows a malicious actor to execute commands of their choosing on a remote machine over a network, such as the internet. This can lead to a full system compromise.
Unauthenticated Attack
An exploit that can be successfully performed without the attacker needing to provide valid login credentials (e.g., username and password). This makes the vulnerability particularly dangerous as it can be exploited by any remote attacker.
Source: SecurityWeek

Spanish Ministry Halts Services After Breach

Executive Summary

Spain's Ministry of Science, Innovation, and Universities shut down its IT systems following a claimed cyberattack, disrupting administrative procedures and online services for citizens, researchers, and companies. A threat actor has claimed responsibility and alleges the theft of sensitive data.

Attack Overview

  • Attack Path: The attacker allegedly exploited an Insecure Direct Object Reference (IDOR) vulnerability combined with previously leaked credentials to gain administrative access.
  • Attacker:GordonFreeman

Impact Assessment

  • Data Stolen: Allegedly includes passports, national ID scans, academic records, and financial information like IBANs.
  • Operational Impact: A partial shutdown of the Ministry's electronic headquarters, suspending all ongoing administrative procedures.

Strategic Takeaway

This incident highlights the critical risk of combined vulnerabilities, where a common web application flaw was reportedly leveraged with compromised credentials to achieve high-level system access.

Relevant professional terms

IDOR (Insecure Direct Object Reference)
A web application vulnerability where an attacker can access or modify data by simply changing the value of a parameter in a URL.
Threat Actor
An individual or group that performs malicious cyber activities.

Italian University Crippled By Ransomware

Executive Summary

La Sapienza University in Rome, one of Europe's largest universities, suffered a major ransomware attack that forced it to shut down its entire IT network. The incident caused widespread operational disruption, impacting systems like email and the main website.

Attack Overview

  • Attack Path: A ransomware variant known as BabLock (or Rorschach) was used to encrypt university systems.
  • Attacker: A previously unknown, pro-Russian group calling itself "Femwar02" has been linked to the attack.

Impact Assessment

  • Data Stolen: The attackers claim to have encrypted millions of data files and threatened a leak of personal data belonging to faculty, students, and staff.
  • Operational Impact: The university proactively took all computer systems offline, including its website and email servers, leading to a multi-day outage.

Strategic Takeaway

This attack highlights the severe operational risk that ransomware poses to large academic institutions, which often have complex networks and valuable data.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system or data, typically by encrypting it, until a sum of money is paid.
Cyberattack
A deliberate and malicious attempt by an individual or organization to breach the information system of another individual or organization.

Ransomware Gangs Abuse VM Infrastructure

Executive Summary

Ransomware operators are abusing virtual machines (VMs) from ISPsystem, a legitimate infrastructure provider, to host and deliver malicious payloads at scale. This tactic, observed in campaigns like 'WantToCry,' allows attackers to use legitimate infrastructure for stealthy operations.

Key TTPs

  • Defense Evasion: Attackers use VMs provisioned via ISPsystem's VMmanager, which often have identical, non-randomized hostnames from default templates, helping to conceal malicious servers among legitimate ones.
  • Command and Control: Malicious payloads are hosted on and delivered from this network of VMs, leveraging the reputation of a legitimate provider to evade detection.

Campaign Analysis

This campaign highlights a trend of threat actors leveraging legitimate services and bulletproof hosting providers to build resilient and hard-to-trace infrastructure. The use of default VM templates creates a digital fingerprint that ironically exposes the scale of the malicious operations.

Targeting & Infrastructure

  • Target Profile: The infrastructure is used by multiple major ransomware groups, including LockBit, Conti, and BlackCat, indicating a broad range of targets.
  • Infrastructure: Thousands of internet-exposed servers with identical hostnames, provisioned through ISPsystem's VMmanager, are used for payload delivery.

Relevant Terms

  • Payload: The component of a malware attack that performs the intended malicious action, such as encrypting files or stealing data.
  • Virtual Machine (VM): A software-based emulation of a physical computer that allows users to run separate operating systems and applications in an isolated environment.

Forensic Driver Weaponized to Kill EDR

Executive Summary

Threat actors are exploiting a legitimate, signed (but revoked) kernel driver from the EnCase forensic tool to disable Endpoint Detection and Response (EDR) and other security products. This "Bring Your Own Vulnerable Driver" (BYOVD) attack allows adversaries to gain kernel-level access and neutralize defenses before deploying ransomware or other malware.

Key TTPs

  • Initial Access: Compromised credentials for a SonicWall SSL VPN lacking multi-factor authentication were used.
  • Execution: A custom "EDR killer" executable loads the vulnerable EnCase driver 'EnPortv.sys'.
  • Defense Evasion: The BYOVD technique abuses the driver's kernel-level privileges to terminate processes associated with dozens of security products.

Campaign Analysis

This incident highlights a critical gap in Windows' Driver Signature Enforcement, which still loads the driver despite its certificate being revoked over a decade ago. The weaponization of trusted, albeit outdated, software demonstrates a persistent trend of attackers abusing legitimate tools to bypass modern security controls.

Relevant Terms

  • EDR (Endpoint Detection and Response): A cybersecurity solution that continuously monitors endpoint devices (like computers and servers) to detect, investigate, and respond to advanced threats.
  • BYOVD (Bring Your Own Vulnerable Driver): An attack where adversaries load a legitimate, but flawed, third-party driver on a target system to gain kernel-level privileges and disable security software.
Source: Dark Reading

Insiders and Impersonators Target Cloud Assets

Executive Summary

This week's threats reveal a focus on the human element, highlighted by a former Google engineer's conviction for AI espionage and threat actors using voice phishing (vishing) to bypass Single Sign-On (SSO) protections for SaaS application theft.

Key Findings

  • A former Google engineer, Linwei Ding, was convicted of stealing thousands of confidential files related to AI technology for Chinese companies.
  • Threat actors, including groups like ShinyHunters, are using vishing to impersonate IT staff, tricking employees into providing SSO credentials and MFA codes to access corporate SaaS platforms.
  • Hundreds of malicious plugins, called "skills," for the OpenClaw AI agent framework were found delivering infostealers like the Atomic Stealer.

The Bottom Line

The convergence of insider threats and sophisticated social engineering demonstrates that technical access controls like SSO and MFA are insufficient on their own. Security leaders must prioritize a defense-in-depth strategy that combines stringent employee vetting with continuous, context-aware security training and anomaly detection to counter attacks targeting the human layer.

Relevant Terms

  • Vishing: A type of cyberattack that uses voice calls or voicemails to deceive individuals into revealing sensitive personal or financial information.
  • Single Sign-On (SSO): An authentication service that allows a user to log in with a single set of credentials to access multiple, independent software systems.
Source: SentinelOne

Apple Lockdown Mode Thwarts FBI

Executive Summary

The FBI was unable to extract data from a Washington Post reporter's iPhone during a raid due to Apple's Lockdown Mode being enabled. This occurred as part of an investigation into a government contractor accused of leaking classified information.

The Scheme

  • TTP 1: A government contractor allegedly retained and leaked classified national defense materials.
  • TTP 2: The contractor allegedly provided this classified information to a journalist.

The Players

  • Facilitators Charged:Aurelio Perez-Lugones (Government Contractor)

The Consequence

  • Outcome: The FBI's Computer Analysis Response Team (CART) could not forensically extract data from the target iPhone.
  • Assets Seized/Forfeited: Reporter's iPhone, two laptops, and a smartwatch were seized during the raid.

Strategic Takeaway

Commercially available, high-security features on personal devices can effectively prevent data extraction, even by federal law enforcement forensic teams.

Relevant Terms

  • Lockdown Mode: An optional, extreme protection feature for Apple devices that strictly limits apps, websites, and features to reduce the attack surface for highly targeted cyberattacks.
  • Forensic Analysis: The process of collecting, examining, and preserving digital evidence from electronic devices to be used in legal proceedings.