
Daily Cybersecurity News - January 9, 2026
Trend Micro Patches Critical RCE Vulnerability in Apex Central
CriticalExecutive Summary
Trend Micro has addressed a critical security vulnerability, CVE-2025-69258, in its Apex Central on-premise product that could allow unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges. The vulnerability has been patched with the release of Critical Patch Build 7190.
Vulnerability Details
- Affected Product: Trend Micro Apex Central (on-premise versions below Build 7190)
- Identifier: CVE-2025-69258
- CVSS Score: 9.8 (Critical)
- Exploitation Status: No active exploitation reported.
Risk & Impact
- Triage: Immediate patching is highly recommended due to the critical nature of the vulnerability.
- Attack Vector: An unauthenticated remote attacker can load an attacker-controlled DLL into a key executable by sending a specially crafted message to the MsgReceiver.exe process.
- Ease of Exploit: Low complexity, no user interaction required.
Action Plan
- Immediate Action: Upgrade to Critical Patch Build 7190.
- Workaround: Review remote access to critical systems and ensure policies and perimeter security are up-to-date.
- Detection: Monitor for suspicious messages (0x0a8d) to the MsgReceiver.exe process on TCP port 20001.
Relevant professional terms
- Remote Code Execution (RCE)
- A vulnerability that allows an attacker to execute arbitrary code on a target system from a remote location.
- DLL Injection
- A technique used to run code within the address space of another process by forcing it to load a dynamic-link library.
Source: Bleeping Computer
Maximum Severity HPE OneView Flaw Exploited in the Wild
CriticalExecutive Summary
A maximum severity vulnerability, CVE-2025-37164, exists in HPE OneView, which can lead to remote code execution and has been actively exploited in the wild. CISA has added this flaw to its Known Exploited Vulnerabilities catalog.
Vulnerability Details
- Affected Product: HPE OneView versions prior to 11.0
- Identifier: CVE-2025-37164
- CVSS Score: 10.0 (Critical)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Immediate application of security updates or hotfixes is critical.
- Attack Vector: Remote, unauthenticated code execution via an unsecured REST API endpoint.
- Ease of Exploit: Exploitation is made easier due to the public availability of a Proof-of-Concept (PoC) exploit code and a Metasploit module.
Action Plan
- Immediate Action: Upgrade to Version 11.0 or apply the appropriate hotfixes for OneView versions 5.20 through 10.20.
- Workaround: There are no known workarounds or mitigations other than upgrading or applying hotfixes.
- Detection: Review access paths and segmentation, and treat this as an assumed breach scenario.
Relevant professional terms
- Remote Code Execution (RCE)
- The ability to execute arbitrary code on a remote device or server.
- Proof of Concept (PoC)
- A demonstration that a vulnerability can be exploited, often used to illustrate the potential impact.
Source: Dark Reading
Esxi Zero-Day Exploit Via Sonicwall Vpn
Executive Summary
A Chinese-speaking threat actor exploited a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit. The toolkit targeted zero-day vulnerabilities, potentially developed over a year before public disclosure, to compromise ESXi hypervisors.
Key TTPs
- Initial Access: Compromised SonicWall VPN appliance
- Execution: Exploitation of VMware ESXi zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226)
- Defense Evasion: Modifying Windows firewall rules to block external outbound connections
Campaign Analysis
The threat actor chained three vulnerabilities to achieve VM escape, compromising the hypervisor infrastructure. The attack involved deploying a backdoor on the ESXi hypervisor after escaping the VM.
Targeting & Infrastructure
- Target Profile: Organizations using VMware ESXi, particularly those with unpatched or end-of-life versions
- Infrastructure: VMware ESXi hypervisors
Actionable Intelligence
- IPs: N/A
- Domains: N/A
Relevant Terms
- Zero-Day: A vulnerability that is unknown to the vendor and may be actively exploited.
- Hypervisor: Software that creates and runs virtual machines, allowing multiple operating systems to share a single hardware resource.
Source: Bleeping Computer
Kimwolf Botnet Exploits Android Devices
Executive Summary
The Kimwolf botnet, an Android variant of Aisuru, has infected over two million devices, primarily Android TV boxes, by exploiting vulnerabilities in residential proxy networks. The botnet is used for DDoS attacks, app installs, and selling proxy bandwidth.
Key TTPs
- Initial Access: Exploitation of exposed Android Debug Bridge (ADB) service via residential proxies.
- Execution: Installation of malware through unauthenticated root access via ADB.
- Defense Evasion: Tunneling into private home networks by altering DNS records to point to local IP addresses.
Campaign Analysis
Kimwolf spreads by exploiting weaknesses in residential proxy networks, allowing attackers to gain access to devices that are unknowingly exposed through poorly secured proxy services. The botnet is also used to launch extremely high-volume distributed denial-of-service attacks while simultaneously generating revenue through the sale of residential proxy access.
Targeting & Infrastructure
- Target Profile: Primarily low-cost, unofficial Android TV boxes and streaming devices in Vietnam, Brazil, India, and Saudi Arabia.
- Infrastructure: Leverages residential proxy networks, particularly those with weak configurations, to tunnel into private networks.
Actionable Intelligence
- Domains:
14emeliaterracewestroxburyma02132[.]su
Relevant Terms
- ADB (Android Debug Bridge): A command-line tool used to communicate with an Android device, often used for debugging and development purposes.
- DDoS (Distributed Denial of Service): A type of cyberattack where multiple compromised systems are used to flood a target with traffic, making it unavailable to legitimate users.
Source: KrebsOnSecurity
UAT-7290 Espionage Campaign Expands to Europe
Executive Summary
UAT-7290, a China-linked threat actor, is targeting telecommunications providers, expanding operations from South Asia to include organizations in Southeastern Europe. The group focuses on cyber-espionage and establishing operational relay box (ORB) infrastructure for other China-aligned actors.
Key TTPs
- Initial Access: Exploiting one-day vulnerabilities in edge network devices and SSH brute force.
- Execution: Utilizes custom and open-source Linux-based malware such as RushDrop, DriveSwitch, and SilentRaid.
- Defense Evasion: Transforms compromised devices into relay infrastructure using the Bulbature implant.
Campaign Analysis
UAT-7290 establishes deep, persistent access to strategically significant networks, acting as both an intelligence collector and initial access facilitator. The group shares overlaps in victimology, infrastructure, and tooling with groups like APT10 and Red Foxtrot.
Targeting & Infrastructure
- Target Profile: Telecommunications providers in South Asia and Southeastern Europe.
- Infrastructure: Uses compromised edge devices and the Bulbature implant to create operational relay box (ORB) infrastructure.
Actionable Intelligence
- IPs: Associated with malware families such as SuperShell, GobRAT, and Cobalt Strike beacons.
- Domains: Bulbature TLS certificate found on 141 China- and Hong Kong-based hosts.
Relevant Terms
- Cyber Espionage: The act of using computer networks to gain secret information about an adversary.
- Initial Access: The first step an attacker takes to gain entry into a target network or system.
Source: Bleeping Computer
Deepfake Tools Bypassing Security Protections
Executive Summary
Researchers at the World Economic Forum have demonstrated that readily available deepfake tools can be exploited by malicious actors to circumvent corporate security measures. This highlights a growing need for enhanced detection and prevention strategies.
Key Findings
- Deepfake fraud attempts surged by 3,000%.
- Financial losses from deepfake-enabled fraud exceeded $200 million in the first quarter of 2025.
- Generative AI fraud losses are expected to reach $40 billion by 2027.
The Bottom Line
The increasing sophistication and accessibility of deepfake technology pose a significant threat to organizations. As threat actors leverage these tools to bypass existing security protocols, businesses must prioritize investment in advanced detection mechanisms, employee training, and robust verification processes to mitigate potential financial and reputational damage. The shift towards "never trust, always verify" security cultures is becoming increasingly critical in an AI-powered world.
Relevant Terms
- Deepfake: AI-generated media convincingly altered to misrepresent someone doing or saying something they did not.
- Corporate Security: Measures and protocols implemented by organizations to protect their assets, employees, and information from threats.
Source: Infosecurity Magazine
Illinois Man Indicted for Snapchat Phishing Scheme
Executive Summary
The DOJ has charged Kyle Svara of Illinois with orchestrating a phishing campaign targeting Snapchat users. Svara allegedly hacked nearly 600 accounts to steal private photos, some of which were sold online.
The Scheme
- TTP 1: Social engineering to impersonate Snapchat support.
- TTP 2: Tricking victims into providing one-time security codes.
- TTP 3: Accessing accounts using obtained codes to steal and sell intimate photos.
The Players
- Facilitators Arrested:Kyle Svara
The Consequence
- Outcome: Svara is scheduled to appear in federal court on Feb. 4, 2026, and faces charges including aggravated identity theft and wire fraud.
Strategic Takeaway
This incident highlights the ongoing threat of social engineering and the importance of verifying requests for sensitive information, even from seemingly legitimate sources.
Relevant Terms
- Phishing: A cybercrime where individuals are deceived into revealing sensitive information, like usernames or passwords, often through deceptive emails or websites.
- Social Engineering: The act of manipulating people into divulging confidential information, which can then be used for fraudulent purposes.
Source: Bleeping Computer