Isometric network nodes illustrating critical cybersecurity vulnerabilities and exploits.

Daily Cybersecurity News - January 16, 2026

Hackers Exploit Modular DS WordPress Plugin Flaw for Admin Access

Critical

Executive Summary

Hackers are actively exploiting a critical vulnerability, CVE-2026-23550, in the Modular DS WordPress plugin, allowing unauthenticated attackers to bypass authentication and gain admin-level privileges. This flaw is actively exploited in the wild.

Vulnerability Details

  • Affected Product: Modular DS WordPress plugin, versions up to and including 2.5.1
  • Identifier: CVE-2026-23550
  • CVSS Score: 10.0 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate update is crucial to prevent site compromise.
  • Attack Vector: By setting the specific parameter [origin equals mo] and any ‘type’ parameter, attackers bypass authentication via a flawed isDirectRequest() check, gaining access to sensitive routes.
  • Ease of Exploit: Trivial, requiring only a simple modification of the request to bypass authentication.

Action Plan

  • Immediate Action: Upgrade to Version 2.5.2 AND immediately regenerate WordPress salts in wp-config.php. Patching alone does not evict attackers who have already generated valid admin session cookies.
  • Workaround: Mitigation rules can be applied to block exploitation before patching.
  • Detection: Monitor for HTTP GET calls to the 'modular-connector' login endpoint (API route ending in /login/) and attempts to create new admin users. Check for suspicious admin accounts like "PoC Admin".

Relevant professional terms

Privilege Escalation
A type of security vulnerability where an attacker is able to obtain a higher level of access to a system than they are authorized for.
Authentication Bypass
A security flaw that allows an attacker to circumvent normal authentication mechanisms and gain unauthorized access to a system or application.

Cisco Patches AsyncOS Zero-Day Exploited Since November 2025

Critical

Executive Summary

Cisco has released a patch for a maximum severity zero-day vulnerability, CVE-2025-20393, in AsyncOS that has been actively exploited since November 2025, affecting Secure Email Gateway (SEG) appliances. The vulnerability allows for remote command execution with root privileges and has been exploited by a China-linked APT group.

Vulnerability Details

  • Affected Product: Cisco Secure Email Gateway (SEG) and Email and Web Manager running Cisco AsyncOS Software. Affected AsyncOS versions include 14.2 and earlier, 15.0, 15.5, and 16.0.
  • Identifier: CVE-2025-20393.
  • CVSS Score: 10.0 (Critical).
  • Exploitation Status: Actively Exploited.

Risk & Impact

  • Triage: Critical. Immediate patching or mitigation is required due to active exploitation and the potential for complete system compromise.
  • Attack Vector: The vulnerability stems from insufficient HTTP request validation in the Spam Quarantine feature, allowing attackers to send crafted requests to execute commands with root privileges.
  • Ease of Exploit: Exploitation is considered easy if the Spam Quarantine feature is enabled and exposed to the internet.

Action Plan

  • Immediate Action: Upgrade to fixed software releases: 15.0.5-016, 15.5.4-012, and 16.0.4-016 for Email Security Gateway; 15.0.2-007, 15.5.4-007, and 16.0.4-010 for Email and Web Manager.
  • Workaround: If patching is not immediately possible, disable the Spam Quarantine feature and restrict access to the appliance. Ensure the appliances are secured behind a firewall and monitor web log traffic for any unexpected activity.
  • Detection: Monitor for indicators of compromise (IOCs) related to the APT group UAT-9686, including the deployment of tools like AquaShell, AquaTunnel, and AquaPurge. Review logs for unauthorized access or tampering.

Relevant professional terms

Zero-Day Vulnerability
A software vulnerability that is known to the vendor but does not yet have a patch available, making it actively exploitable.
Secure Email Gateway (SEG)
A security solution that monitors email traffic to prevent malicious content from reaching user inboxes, acting as a barrier between an organization's email environment and the outside world.

CodeBreach: AWS CodeBuild Supply Chain Vulnerability

Executive Summary

Wiz Research discovered a critical supply chain vulnerability, dubbed CodeBreach, that abuses a CodeBuild misconfiguration to potentially take over key AWS GitHub repositories, including the JavaScript SDK powering the AWS Console. The vulnerability's CVE-ID and status are currently unknown.

Vulnerability Details

  • Affected Product: AWS CodeBuild, AWS GitHub repositories, JavaScript SDK powering the AWS Console
  • Identifier: AWS Security Bulletin 2026-002-AWS (No CVE).
  • CVSS Score: N/A (Architecture Flaw)
  • Exploitation Status: Proof of Concept (Internal)

Risk & Impact

  • Triage: High Urgency
  • Attack Vector: Abuse of CodeBuild misconfiguration to hijack AWS GitHub repositories.
  • Ease of Exploit: Assessment required based on specific misconfiguration details.

Action Plan

  • Immediate Action: Review and rectify CodeBuild configurations to prevent unauthorized repository access.
  • Workaround: Implement strict access controls and monitoring for CodeBuild projects.
  • Detection: Monitor CodeBuild activity for suspicious behavior and unauthorized access attempts.

Relevant professional terms

Supply Chain Vulnerability
A weakness in any element of the supply chain (software, hardware, or processes) that could be exploited to compromise the security of the final product or service.
CodeBuild
A fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy.

WhisperPair Exposes Bluetooth Earbuds and Headphones to Tracking and Eavesdropping

High

Executive Summary

The WhisperPair vulnerability (CVE-2025-36911) allows attackers to take control of Bluetooth earbuds and headphones without user interaction, potentially enabling eavesdropping and location tracking. This critical flaw affects devices using Google Fast Pair from various manufacturers.

Vulnerability Details

  • Affected Product: Bluetooth earbuds, headphones, and speakers using Google Fast Pair from vendors including Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, and Google
  • Identifier: CVE-2025-36911
  • CVSS Score: 7.1 (High)
  • Exploitation Status: No evidence of exploitation outside of lab settings

Risk & Impact

  • Triage: Critical. Immediate action is required due to the potential for unauthorized access and control of devices.
  • Attack Vector: An attacker within Bluetooth range (up to 14 meters) can force pairing with vulnerable devices, even without the device being in pairing mode. If the attacker is the first to pair the accessory, they can track the device's location via Google's Find Hub network.
  • Ease of Exploit: Easy. The attack can be performed using readily available hardware like a laptop or phone, requiring no user interaction.

Action Plan

  • Immediate Action: Android OS updates are insufficient. You must download the vendor-specific companion app (e.g., Sony Headphones Connect, JBL App) to manually push the firmware update to your accessory.
  • Workaround: While not a complete fix, avoid using vulnerable accessories in sensitive environments. Disabling Fast Pair scanning prompts on Android devices does not remove Fast Pair support from the accessory.
  • Detection: Monitor for unusual Bluetooth pairing activity and review tracking alerts.

Relevant professional terms

Bluetooth Eavesdropping
The unauthorized access and monitoring of Bluetooth communications, potentially leading to the interception of sensitive information or control of devices.
Bluetooth Tracker
A small electronic device that uses Bluetooth to help find misplaced items by connecting wirelessly to a mobile device.
Source: Malwarebytes

UAT-8837 Exploits Sitecore Zero-Day

Executive Summary

UAT-8837, a China-nexus APT, is targeting North American critical infrastructure to gain initial access to high-value organizations. The group exploits both n-day and zero-day vulnerabilities, including CVE-2025-53690 in Sitecore.

Key TTPs

  • Initial Access: Exploitation of Sitecore zero-day vulnerability (CVE-2025-53690) and compromised credentials.
  • Execution: Deploys open-source tools like Earthworm, SharpHound, and GoTokenTheft.
  • Defense Evasion: Disables RestrictedAdmin for RDP and cycles through tool variants to evade detection.

Campaign Analysis

UAT-8837 has been active since at least 2025, focusing on critical infrastructure in North America. The group exfiltrates DLL-based shared libraries, potentially leading to supply chain compromises.

Targeting & Infrastructure

  • Target Profile: High-value organizations within critical infrastructure sectors in North America.
  • Infrastructure: Utilizes attacker-owned remote infrastructure and internal endpoints.

Relevant Terms

  • APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign.
  • Zero-Day: A vulnerability that is unknown to the vendor and for which no patch is available.

Gootloader Uses Multi-Part Zip Archives

Executive Summary

Gootloader, a malware used for initial access, now employs malformed ZIP archives with up to 1,000 parts to evade detection. This technique aims to bypass security measures by concatenating numerous archives.

Key TTPs

  • Initial Access: SEO poisoning leads users to compromised websites hosting malicious ZIP archives.
  • Execution: Tricking users into executing a malicious script file contained within the ZIP archive.
  • Defense Evasion: Using malformed ZIP archives with up to 1,000 parts to evade detection.

Campaign Analysis

Gootloader's evolution involves adapting obfuscation techniques to bypass security measures. Unremoved infections can lead to data theft or ransomware.

Targeting & Infrastructure

  • Target Profile: Targets include users searching for business-related documents such as agreements, contracts, and templates.
  • Infrastructure: Compromised websites, often WordPress sites, are used to host malicious documents.

Relevant Terms

  • SEO Poisoning: A technique used to manipulate search engine results to direct users to malicious websites.
  • Cobalt Strike: A commercial, full-featured penetration testing and red team tool often used by attackers for command and control.

AI Coding Agents Struggle with Security Controls

Executive Summary

AI-driven "vibe coding" tools excel at basic coding practices but often fail to implement adequate security controls, leading to potential vulnerabilities. Tenzai's tests revealed that AI agents struggled with authorization and were prone to Server-Side Request Forgery (SSRF) vulnerabilities.

Key Findings

  • AI coding agents are generally proficient at avoiding issues where good coding practices are well-established, such as preventing SQL injection (SQLi) and Cross-Site Scripting (XSS).
  • Tenzai's testing of five AI coding agents found a total of 69 vulnerabilities in 15 generated apps, ranging from critical to low severity.
  • All five AI agents introduced an SSRF vulnerability in tests, allowing attackers to invoke requests to arbitrary URLs.

The Bottom Line

The increasing adoption of AI-assisted coding necessitates a shift towards "vibe testing" to identify and mitigate vulnerabilities introduced by AI-generated code. While AI can accelerate development and reduce costs, organizations must prioritize security by implementing robust validation processes and security-focused helper models. Addressing the security risks associated with vibe coding is crucial to prevent potential breaches and ensure the integrity of applications developed with AI assistance.

Relevant Terms

  • Vibe Coding: An AI-assisted software development technique where developers use natural language prompts to generate code.
  • SQL Injection (SQLi): A code injection technique used to attack data-driven applications by inserting malicious SQL statements into an entry field.
Source: SecurityWeek