Digital blue data streams highlighting global cybersecurity threats.

Daily Cybersecurity News - January 17, 2026

More Problems for Fortinet: Critical FortiSIEM Flaw Exploited

Executive Summary

A command injection vulnerability, CVE 2025-64155, in Fortinet FortiSIEM has been disclosed and is under active exploitation from various IP addresses.

Vulnerability Details

  • Affected Product: Fortinet FortiSIEM
  • Identifier: CVE-2025-64155
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate patching or mitigation is critical due to active exploitation.
  • Attack Vector: Command Injection.
  • Ease of Exploit: High, given active exploitation.

Action Plan

  • Immediate Action: Apply available patches or upgrade to a secure version.
  • Workaround: Implement network segmentation and access controls to limit potential damage.
  • Detection: Monitor network traffic for unusual command execution patterns and review FortiSIEM logs for suspicious activity.

Relevant professional terms

Command Injection
A type of security vulnerability that allows an attacker to execute arbitrary commands on a host operating system.
Exploitation
The act of leveraging a vulnerability to cause unintended or unanticipated behavior in a system or application.
Source: Dark Reading

StealC Malware Operators Hacked Through XSS Vulnerability

Executive Summary

Researchers discovered that a cross-site scripting (XSS) vulnerability in the web-based control panel used by StealC malware operators allowed them to observe active sessions and gather intelligence. This vulnerability ironically led to the theft of session cookies from the infrastructure designed for stealing credentials.

Vulnerability Details

  • Affected Product: StealC malware web-based control panel
  • Identifier: Non-CVE (Proprietary Malware Vulnerability)
  • CVSS Score: N/A (Severity not yet determined)
  • Exploitation Status: Actively Exploited by researchers

Risk & Impact

  • Triage: High - Immediate investigation and patching are required due to active exploitation.
  • Attack Vector: XSS vulnerability in the web-based control panel.
  • Ease of Exploit: Easy, given the publicly leaked panel code.

Action Plan

  • Immediate Action: Apply input validation and output encoding to prevent script injection.
  • Workaround: Implement a web application firewall (WAF) to detect and block malicious payloads.
  • Detection: Monitor for unusual activity and prepare to apply vendor patches once released.

Relevant professional terms

Cross-Site Scripting (XSS)
A type of web security vulnerability that allows an attacker to inject malicious scripts into the content of a website, which are then executed by other users.
Malware-as-a-Service (MaaS)
A business model where malware developers provide their malicious software to other cybercriminals in exchange for payment.

Cybersecurity Week 3: Threat Landscape Update

Executive Summary

This week's cybersecurity landscape saw setbacks for Black Axe and BreachForums, the exposure of a new Copilot attack, and PluggyApe malware targeting Ukraine's armed forces. These events highlight the diverse threats facing organizations and individuals.

Key TTPs

  • Initial Access: PluggyApe uses instant messaging (Signal, WhatsApp) masquerading as charity organizations to deliver malicious links.
  • Execution: PluggyApe deploys a PyInstaller executable leading to the installation of a Python-based backdoor.
  • Defense Evasion: PluggyApe uses obfuscation and anti-analysis checks to avoid execution in virtual environments.

Campaign Analysis

PluggyApe has evolved to use MQTT for C2 communications and retrieves C2 addresses from paste services, enhancing operational security. The BreachForums leak exposed nearly 324,000 users, potentially aiding law enforcement investigations.

Targeting & Infrastructure

  • Target Profile: PluggyApe targets Ukrainian defense forces.
  • Infrastructure: PluggyApe uses WebSocket and MQTT for C2, retrieving addresses from rentry[.]co and pastebin[.]com.

Actionable Intelligence

  • IPs: N/A
  • Domains:harthulp-ua[.]com, solidarity-help[.]org

Relevant Terms

  • C2: Command and Control, refers to the infrastructure and techniques used by attackers to communicate with and control compromised systems.
  • Mobile-First Social Engineering: A tactic where attackers leverage encrypted mobile apps (Signal, WhatsApp) to build rapport and bypass traditional email security gateways.
Source: SentinelOne

Uat 8837 Exploits Unpatched Sitecore Flaws (N-Day)

Executive Summary

UAT 8837, a China-linked APT, is targeting critical infrastructure in North America to gain initial access for espionage. The group is exploiting a Sitecore zero-day vulnerability (CVE-2025-53690) and using open-source tools.

Key TTPs

  • Initial Access: Exploitation of known Sitecore vulnerability (CVE-2025-53690) via exposed machine keys.
  • Execution: Utilizes open-source tools like Earthworm, SharpHound, and DWAgent for post-compromise activity.
  • Defense Evasion: Rapidly cycles through tool variants to evade security product detection and disables RestrictedAdmin for RDP.

Campaign Analysis

UAT 8837 has been active since at least 2025, demonstrating sophisticated tradecraft and likely possessing zero-day exploitation capabilities. The actor exfiltrates DLL-based shared libraries, raising concerns about potential supply chain compromises.

Targeting & Infrastructure

  • Target Profile: Critical infrastructure sectors in North America.
  • Infrastructure: Employs open-source tools and custom LOTL tooling for reconnaissance and lateral movement.

Relevant Terms

  • APT (Advanced Persistent Threat): A sophisticated, long-term cyberattack campaign targeting specific organizations.
  • Zero-Day Vulnerability: A software vulnerability that is unknown to the vendor and for which no patch is available.

GootLoader Uses Malformed ZIP Archives

Executive Summary

GootLoader, a JavaScript malware loader, employs malformed ZIP archives containing 500-1,000 concatenated archives to evade detection. This technique aims to bypass analysis by standard unarchiving tools, delivering malicious JavaScript payloads.

Key TTPs

  • Initial Access: SEO poisoning and malvertising to lure victims to compromised websites hosting malicious ZIP archives.
  • Execution: Exploits the default Windows unarchiver to extract and run the JavaScript malware.
  • Defense Evasion: Concatenates 500-1,000 ZIP archives and truncates the archive's end of central directory (EOCD) record to evade detection by common unarchiving tools.

Campaign Analysis

The malware uses sophisticated obfuscation mechanisms to evade detection, demonstrating a continuous evolution of delivery methods. Unremoved GootLoader infections can lead to data theft or ransomware deployment.

Targeting & Infrastructure

  • Target Profile: Users searching for legal templates and business-related documents.
  • Infrastructure: Compromised WordPress sites hosting malicious ZIP archives.

Actionable Intelligence

  • Domains:explorer[.]ee, fysiotherapie-panken[.]nl, devcxp2019.theclearingexperience[.]com

Relevant Terms

  • SEO Poisoning: A technique used to manipulate search engine results to lead users to malicious websites.
  • Malvertising: The use of online advertising to spread malware.

Man Pleads Guilty to Supreme Court Hack

Executive Summary

The DOJ announced that Nicholas Moore pleaded guilty to hacking the U.S. Supreme Court's filing system, as well as systems belonging to AmeriCorps and the Department of Veterans Affairs. Moore accessed these systems using stolen credentials.

The Scheme

  • TTP 1: Stole credentials to gain unauthorized access.
  • TTP 2: Accessed the Supreme Court's filing system on 25 different days.
  • TTP 3: Posted screenshots of accessed information on Instagram.

The Players

  • Facilitators Arrested:Nicholas Moore

The Consequence

  • Outcome: Moore pleaded guilty to one misdemeanor count of computer fraud.

Strategic Takeaway

This incident highlights the importance of securing credentials and monitoring access to sensitive systems.

Relevant Terms

  • Stolen Credentials: Illegally obtained login information, such as usernames and passwords, used to access systems without authorization.
  • Computer Fraud: A criminal act involving the use of computers to commit deceptive practices for financial or personal gain.
Source: SecurityWeek

Black Basta Leader Added to Interpol's Red Notice

Executive Summary

Law enforcement in Ukraine and Germany have identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware gang and added him to Interpol's wanted list. The Black Basta group is believed to be responsible for at least 600 ransomware incidents, data theft, and extortion targeting large organizations worldwide.

The Scheme

  • TTP 1: Gaining access to target networks.
  • TTP 2: Extracting passwords to accounts from information systems using specialized software.
  • TTP 3: Breaching internal corporate systems and increasing the privileges of the stolen accounts.

The Players

  • Threat Actor:Black Basta
  • Facilitators Arrested: Two individuals in Ukraine.

The Consequence

  • Outcome: Oleg Nefedov has been added to Europol's "Most Wanted" and Interpol's "Red Notice" lists.

Strategic Takeaway

The identification and pursuit of Black Basta's leader highlights international law enforcement's commitment to disrupting ransomware operations.

Relevant Terms

  • Ransomware-as-a-Service (RaaS): A business model where ransomware developers lease their ransomware tools to affiliates who conduct attacks.
  • Double Extortion: A tactic used in ransomware attacks where attackers both encrypt data and threaten to publish it if a ransom is not paid.