Isometric network nodes illustrating critical Fortinet, n8n vulnerabilities and tech outages.

Daily Cybersecurity News - January 15, 2026

FortiSIEM Critical Exploit Now Public

Executive Summary

Exploit code has been released for CVE 2025 64155, a critical command injection vulnerability affecting Fortinet FortiSIEM devices, and is considered actively exploitable.

Vulnerability Details

  • Affected Product: Fortinet FortiSIEM
  • Identifier: CVE-2025-64155
  • Exploitation Status: Exploit Code Released

Risk & Impact

  • Triage: High Urgency
  • Attack Vector: OS Command Injection
  • Ease of Exploit: High, due to public exploit code

Action Plan

  • Immediate Action: Upgrade to the latest version of FortiSIEM
  • Workaround: Implement strict input validation and sanitization to prevent command injection
  • Detection: Monitor for suspicious command execution patterns and unauthorized system access

Relevant professional terms

Command Injection
A type of security vulnerability that allows an attacker to execute arbitrary commands on the host operating system.
Exploit Code
A piece of software, a chunk of data, or a sequence of commands that takes advantage of a bug or vulnerability to cause unintended or unanticipated behavior to occur on computer hardware, software, or something electronic.

Critical RCE Hits n8n Automation

Critical

Executive Summary

A critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2026-21858, has been discovered in n8n, potentially impacting an estimated 100,000 servers globally. There are currently no official workarounds available, and users are advised to upgrade to the latest version.

Vulnerability Details

  • Affected Product: n8n versions prior to 1.121.0
  • Identifier: CVE-2026-21858
  • CVSS Score: 10.0 (Critical)
  • Exploitation Status: Proof of concept (PoC) exploit code is publicly available.

Risk & Impact

  • Triage: Immediate upgrade is required due to the potential for complete compromise of automation infrastructure.
  • Attack Vector: The vulnerability stems from a Content-Type confusion flaw in n8n's webhook and file-handling logic, allowing attackers to send crafted HTTP requests to bypass authentication and achieve remote code execution.
  • Ease of Exploit: Easy, due to low attack complexity and no required privileges.

Action Plan

  • Immediate Action: Upgrade n8n to version 1.121.0 or later.
  • Workaround: Restrict or disable publicly accessible webhook and form endpoints as a temporary mitigation.
  • Detection: Monitor for unusual file access patterns, unexpected workflow executions, and path traversal attempts in server logs.

Relevant professional terms

Remote Code Execution (RCE)
A vulnerability that allows an attacker to execute arbitrary code on a target system.
CVSS Score
A numerical representation of the severity of a security vulnerability, with a score of 10.0 being the most critical.
Source: schneier.com

Bluspark Exposes Plaintext Passwords

Executive Summary

Shipping tech company Bluspark exposed its platform and customer data due to multiple vulnerabilities, including plaintext password storage. This exposure could lead to unauthorized access and potential compromise of sensitive shipping and customer information.

Attack Overview

  • Attack Path: Unauthenticated API access, plaintext password storage.

Impact Assessment

  • Data Stolen: User credentials and shipment records dating back to 2007.

Strategic Takeaway

Storing sensitive credentials in plaintext poses a significant risk, emphasizing the need for robust encryption and authentication mechanisms.

Relevant professional terms

Plaintext Password
Storing passwords in an unencrypted format, making them easily readable if accessed.
Unauthenticated API
An API that does not require authentication, allowing anyone to access its data and functionality.
Source: TechCrunch

Kimwolf Botnet Infrastructure Neutralized

Executive Summary

The Black Lotus Labs team null routed traffic to over 550 command and control nodes associated with the AISURU Kimwolf botnet since early October 2025. These botnets have emerged as significant threats, compromising millions of devices.

Key TTPs

  • Initial Access: Exploiting vulnerabilities in residential proxy networks and pre-installed malware on Android devices.
  • Execution: Uses NDK to compile botnet with DDoS, proxy forwarding, reverse shell, and file management functions.
  • Defense Evasion: Employs Stack XOR encryption, DNS over TLS (DoT), and EtherHiding technology.

Campaign Analysis

The Kimwolf botnet is an Android variant of AISURU and has infected over 1.8 million devices. It has been used to launch DDoS attacks and generate revenue through proxy services.

Targeting & Infrastructure

  • Target Profile: Primarily Android TV boxes and other IoT devices in residential networks.
  • Infrastructure: Utilizes over 550 C2 servers and a network of compromised devices across multiple global time zones.

Actionable Intelligence

  • IPs: 190.123.46[.]21, 190.123.46[.]55, 95.214.52[.]167, 162.220.163[.]14
  • Domains: xlabresearch[.]ru, xlabsecurity[.]ru, foxthreatnointel[.]africa

Relevant Terms

  • Botnet: A network of computers infected with malware that are controlled by a single attacker.
  • DDoS: A type of cyberattack where a malicious actor floods a server with traffic to make a website or online service unavailable.

Sicarii Ransomware Fakes Israeli Origin

Executive Summary

The Sicarii group emerged in December 2025 as a Ransomware-as-a-Service (RaaS) operation, advertising its services on underground platforms. The group uses Israeli symbolism and messaging, but technical analysis suggests possible false-flag behavior.

Key TTPs

  • Initial Access: Likely via phishing or exploiting exposed services.
  • Execution: Data encryption using AES-GCM.
  • Defense Evasion: Anti-VM checks and geo-fencing to avoid Israeli systems.

Campaign Analysis

Sicarii is distinguished by its explicit use of Israeli symbolism, which deviates from established ransomware norms. The group focuses on small businesses to reduce scrutiny.

Targeting & Infrastructure

  • Target Profile: Small to mid-sized organizations across various sectors.

Actionable Intelligence

  • Hashes: [4104542714022cb6ef34e9ee5affca07b9a38dbee49748f8630c5f50a26db8b2, cce3821939b7cb77b9da3d59bbcb5978818d4937dd330d820102b012ffcebe4d]

Relevant Terms

  • RaaS: Ransomware as a Service, a business model where ransomware developers lease their ransomware to affiliates.
  • AES-GCM: Advanced Encryption Standard - Galois/Counter Mode, a widely used symmetric-key encryption algorithm providing confidentiality and data integrity.

Verizon Outage Triggers SOS Mode

Executive Summary

A widespread Verizon Wireless outage on January 14, 2026, left customers across the US without cellular service, with many phones stuck in SOS mode. The outage, which impacted voice and data services, prompted the company to offer account credits to affected users.

Key Findings

  • The outage began around noon ET, with Downdetector logging over 171,000 reports.
  • Many iPhone users saw their devices switch to SOS mode, indicating a lack of cellular network connection.
  • The outage affected major cities across the US, including New York City, Chicago, and Washington D.C..

The Bottom Line

The Verizon outage highlights the critical importance of reliable cellular service for both daily communication and emergency situations. The incident underscores the need for robust network infrastructure and redundancy to minimize disruptions and ensure continuous connectivity. Businesses and individuals should consider diversifying their communication channels and having backup plans in place to mitigate the impact of potential outages.

Relevant Terms

  • SOS Mode: A state in which a mobile device cannot connect to its primary cellular network but can still make emergency calls.
  • Network Outage: A period during which a network is unavailable or experiences significant disruptions in service.

RedVDS Cybercrime Service Seized

Executive Summary

Microsoft, along with international law enforcement, disrupted the RedVDS cybercrime service, which enabled cybercriminals to conduct various attacks. The RedVDS infrastructure and associated domains were seized, hindering the platform's ability to facilitate fraud.

The Scheme

  • TTP 1: Providing access to disposable virtual computers for as little as $24 a month.
  • TTP 2: Facilitating phishing, BEC attacks, account takeovers, and fraud.
  • TTP 3: Pairing the service with GenAI tools to enhance attacks.

The Players

  • Threat Actor: Storm-2470

The Consequence

  • Outcome: Infrastructure seized and marketplace taken offline.
  • Assets Seized/Forfeited: $40 million in reported fraud losses since March 2025.

Strategic Takeaway

Disrupting cybercrime-as-a-service platforms like RedVDS is crucial to hinder large-scale cyberattacks and protect potential victims.

Relevant Terms

  • BEC (Business Email Compromise): A type of fraud where attackers gain access to email accounts to intercept communications and redirect payments.
  • Phishing: A type of online fraud where attackers send deceptive emails or messages to trick individuals into revealing sensitive information.
Source: SecurityWeek