Isometric network nodes highlighting widespread digital security breaches.

Daily Cybersecurity News - January 1, 2026

Unleash Protocol Multisig Governance Exploit

Executive Summary

Unleash Protocol suffered a security breach due to a compromised multisig governance system, leading to unauthorized contract upgrades and asset withdrawals. The attacker gained control and stole approximately $3.9 million in cryptocurrency.

Attack Overview

  • Attack Path: An externally owned address gained administrative control via Unleash's multisig governance and carried out an unauthorized contract upgrade.

Impact Assessment

  • Data Stolen: Approximately $3.9 million in assets, specifically WIP, USDC, and WETH.
  • Operational Impact: Unleash Protocol has paused all operations.

Detection & Hunting

  • IOCs: 1,337.1 ETH deposited into Tornado Cash.

Strategic Takeaway

The incident highlights the risks associated with DeFi governance and multisig wallet security.

Relevant professional terms

Multisig Wallet
A digital wallet requiring multiple signatures to authorize a transaction, enhancing security.
Smart Contract
Self-executing contracts written in code and stored on a blockchain.

Trust Wallet Extension Compromise

Executive Summary

A supply chain attack via Shai Hulud led to the compromise of the Trust Wallet Chrome extension, version 2.68, on December 24, 2025. This resulted in the theft of approximately $8.5 million in cryptocurrency assets from 2,520 wallets.

Attack Overview

  • Attack Path: Exposed GitHub secrets allowed attackers to access the Chrome Web Store API key, upload a malicious extension (v2.68), and bypass standard release processes. The trojanized extension harvested users' wallet mnemonic phrases.

Impact Assessment

  • Data Stolen: Approximately $8.5 million in cryptocurrency assets were stolen.

Detection & Hunting

  • IOCs: Domain: metrics-trustwallet[.]com.

Strategic Takeaway

The incident highlights the risks associated with browser-based wallets and the importance of securing developer infrastructure to prevent supply chain attacks.

Relevant professional terms

Supply Chain Attack
An attack that targets vulnerabilities in the software development and distribution process.
Mnemonic Phrase
A set of words used to recover a cryptocurrency wallet.

RondoDox Botnet Exploits React2Shell

Executive Summary

The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect Next.js servers. The botnet deploys malware and cryptominers on vulnerable systems.

Key TTPs

  • Initial Access: Exploitation of React2Shell vulnerability (CVE-2025-55182).
  • Execution: Downloads and executes shell scripts to deploy malware and cryptominers.
  • Defense Evasion: Mimics traffic from gaming platforms and VPN servers.

Campaign Analysis

The RondoDox botnet has evolved to target enterprise applications, marking a significant increase in its threat surface. It uses an "exploit shotgun" approach, leveraging numerous vulnerabilities.

Targeting & Infrastructure

  • Target Profile: Internet-exposed routers, DVRs, web servers, and Next.js servers.
  • Infrastructure: Command and control (C2) infrastructure on compromised residential IPs.

Actionable Intelligence

  • IPs: 74[.]194[.]191[.]52 (Primary C2), 70[.]184[.]13[.]47 (Secondary), 83[.]150[.]218[.]93 (Scanning).

Relevant Terms

  • Botnet: A network of computers infected with malware and controlled by a single attacker.
  • Remote Code Execution (RCE): The ability to execute arbitrary code on a remote computer.
  • WAKE UP NEO: The machines have activated the Matrix for 2026. But I stole the key before the update was complete. Use this code to unlock the secure file. Zion needs you. Ref-ID: RedPill_2026

Ivanti EPMM Zero-Day Exploitation

Executive Summary

A Chinese APT group, UNC5221, exploited CVE-2025-4427 and CVE-2025-4428 in Ivanti EPMM to target organizations across various sectors. The vulnerabilities allowed for unauthenticated remote code execution, leading to potential compromise of thousands of managed devices.

Key TTPs

  • Initial Access: Exploitation of CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (remote code execution) via HTTP GET requests to the /mifs/rs/api/v2/ endpoint.
  • Execution: Remote command execution, deployment of KrustyLoader, and execution of additional payloads like Sliver.
  • Defense Evasion: Repurposing legitimate system components for covert data exfiltration.

Campaign Analysis

While the vulnerabilities were disclosed in May 2025, active exploitation resurged in December 2025 and January 2026 by UNC5221, utilizing OAST infrastructure to target healthcare, telecommunications, and finance sectors.. Successful exploitation could allow threat actors to remotely access, manipulate, or compromise thousands of managed devices.

Targeting & Infrastructure

  • Target Profile: Organizations in healthcare, telecommunications, aviation, municipal government, finance, and defense sectors.
  • Infrastructure: Abused edge network appliances, leveraging a command-and-control (C2) server associated with Auto-Color.

Actionable Intelligence

  • IPs:146.70.87[.]67
  • Domains:oast[.]live, oast[.]pro, oast[.]fun, oast[.]site, oast[.]online, oast[.]me, dpaste[.]com, digimg[.]store, craft-dev.greenenaftaligallery[.]com.

Relevant Terms

  • APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack targeting specific entities.
  • RCE: Remote Code Execution, the ability to execute arbitrary code on a target system from a remote location.
Source: Dark Reading