Isometric network nodes illustrating diverse cybersecurity vulnerabilities and attacks.

Daily Cybersecurity News - January 19, 2026

New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections

Medium

Executive Summary

A new hardware vulnerability called StackWarp (CVE-2025-29943) affects AMD processors, potentially allowing attackers with privileged host server control to execute malicious code within confidential virtual machines (CVMs). AMD has released patches and considers the issue a low severity.

Vulnerability Details

  • Affected Product: AMD Zen 1 through Zen 5 processors, including AMD EPYC 7003, 8004, 9004, and 9005 series
  • Identifier: CVE-2025-29943
  • CVSS Score: 4.6 (Medium)
  • Exploitation Status: No evidence of active exploitation in the wild

Risk & Impact

  • Triage: Apply available patches and consider disabling Simultaneous Multithreading (SMT) in sensitive environments
  • Attack Vector: Attackers with privileged access to the host server can manipulate the guest VM's stack pointer by exploiting a synchronization failure in the stack engine.
  • Ease of Exploit: Requires privileged control over the host server, making it potentially exploitable by malicious insiders or sophisticated threat actors.

Action Plan

  • Immediate Action: Install microcode and firmware updates from hardware vendors. Upgrade to patched versions.
  • Workaround: Disable Simultaneous Multithreading (SMT) to mitigate the risk, though this may impact performance.
  • Detection: Monitor for unauthorized manipulation of the stack pointer within virtual machines.

Relevant professional terms

SEV-SNP
AMD Secure Encrypted Virtualization - Secure Nested Paging, a technology that provides strong memory integrity protection to prevent hypervisor-based attacks and create isolated execution environments for virtual machines.
Stack Pointer
A register in the CPU that tracks the location of the top of the stack in memory, used for managing function calls, local variables, and return addresses.

Security Bug in StealC Malware Panel Exposes Threat Actor Operations

Executive Summary

A cross-site scripting (XSS) vulnerability was discovered in the web-based control panel of the StealC information stealer, allowing researchers to gain insights into threat actor operations. By exploiting this flaw, researchers could observe active sessions, collect system fingerprints, and even steal session cookies.

Vulnerability Details

  • Affected Product: StealC malware web-based control panel
  • Identifier: CVE not available
  • CVSS Score: Score not available (Severity not available)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: High - Exposure of sensitive information and potential for unauthorized access.
  • Attack Vector: Exploitation of the XSS vulnerability in the StealC web panel.
  • Ease of Exploit: Easy, due to the nature of XSS vulnerabilities and the lack of proper input validation.

Action Plan

  • Strategic Takeaway: This vulnerability highlights that malware infrastructure often lacks standard security controls (SDLC), providing opportunities for researchers to gather threat intelligence.
  • Defense Strategy: Focus on detecting StealC infection vectors (often "cracked software" YouTube videos) rather than the panel vulnerability itself.
  • Detection: Monitor network traffic for StealC-specific C2 communication patterns and unauthorized data exfiltration (browser cookies/wallets).

Relevant professional terms

Cross-Site Scripting (XSS)
A type of web security vulnerability that allows an attacker to inject malicious scripts into websites viewed by other users.
Information Stealer
A type of malware designed to steal sensitive information, such as login credentials, financial data, and personal information, from infected systems.

Sleeper Extensions Target Browsers

Executive Summary

Researchers have discovered malicious "sleeper" browser extensions targeting Firefox, Chrome, and Edge users, which can track browsing behavior and execute malicious code. These extensions can monitor visited sites, search queries, and shopping behavior, potentially leading to credential theft and session hijacking.

Key TTPs

  • Initial Access: Malicious browser extensions.
  • Execution: Download and run malicious JavaScript inside the browser.
  • Defense Evasion: Hiding JavaScript code inside image logos (steganography).

Campaign Analysis

The DarkSpectre group is believed to be behind the ShadyPanda, GhostPoster, and Zoom Stealer campaigns, which use malicious browser extensions. These extensions initially appear benign, but after a delayed period, they update to track browsing behavior and run malicious code.

Targeting & Infrastructure

  • Target Profile: Users of Firefox, Chrome, and Edge browsers.
  • Infrastructure: Extensions are published in each browser's web store as seemingly useful tools.

Relevant Terms

  • Steganography: The practice of concealing a file, message, image, or video within another file, message, image, or video.
  • Backdoor: A means of bypassing normal authentication or encryption in a system, inserted for malicious purposes.
Source: Malwarebytes

SolyxImmortal: Python-Based Information Stealer

Executive Summary

SolyxImmortal is a Python-based information stealer targeting Windows systems. It combines credential theft, document harvesting, keylogging, and screen surveillance, exfiltrating data to attacker-controlled Discord webhooks.

Key TTPs

  • Initial Access: Distributed via underground Telegram channels.
  • Execution: Executes as a packaged Python application on Windows, establishing persistence via registry-based autorun configuration.
  • Defense Evasion: Abuses legitimate system APIs and Discord's HTTPS security to evade detection.

Campaign Analysis

SolyxImmortal emphasizes stealth and long-term access, operating continuously in the background. It focuses on maximizing data collection from a single compromised endpoint rather than self-propagation.

Targeting & Infrastructure

  • Target Profile: Targets Windows systems, focusing on continuous monitoring and alerting for high-value user actions.
  • Infrastructure: Uses hardcoded Discord webhooks for command and control and data exfiltration.

Relevant Terms

  • Information Stealer: Malware designed to steal sensitive information like credentials and financial data from compromised systems.
  • Webhook: Automated HTTP callbacks used to send data between applications in real-time.
Source: SecurityWeek

Mobile Fortify's Misidentification Issues Highlighted

Executive Summary

ICE's Mobile Fortify facial recognition app incorrectly identified a woman twice during an immigration raid, raising concerns about its reliability. The app's misidentification issues underscore the risks associated with using facial recognition technology in high-stakes situations.

Key Findings

  • Mobile Fortify provided two different names after scanning a woman's face.
  • ICE considers the app's results a "definitive" determination of immigration status.

The Bottom Line

The demonstrated inaccuracies of Mobile Fortify, coupled with ICE's reliance on it for definitive immigration status determinations, pose significant risks. Erroneous identifications can lead to wrongful detentions and deportations, disproportionately affecting vulnerable populations. This highlights the urgent need for greater oversight and regulation of biometric surveillance technologies to protect civil liberties and ensure fair treatment under the law.

Relevant Terms

  • Facial Recognition: A biometric technology that identifies or verifies a person's identity by analyzing and comparing patterns in their facial features.
  • Biometric Surveillance: The use of biometric technologies, such as facial recognition or fingerprint scanning, to monitor and track individuals.
Source: 404 Media

Jordanian Man Pleads Guilty to Network Access Sales

Executive Summary

The DOJ announced that Feras Khalil Ahmad Albashiti pleaded guilty to selling unauthorized access to at least 50 company networks. Albashiti acted as an access broker, selling access obtained by exploiting vulnerabilities.

The Scheme

  • TTP 1: Exploited vulnerabilities in commercial firewall products.
  • TTP 2: Sold malware capable of disabling EDR solutions.
  • TTP 3: Offered tools for privilege escalation.

The Players

  • Facilitators Arrested:Feras Khalil Ahmad Albashiti

The Consequence

  • Outcome: Guilty plea for fraud and related activity.
  • Assets Seized/Forfeited: Maximum penalty of $250,000 fine.

Strategic Takeaway

The arrest and guilty plea highlight law enforcement's focus on disrupting the access-broker ecosystem.

Relevant Terms

  • Access Broker: A cybercriminal who specializes in gaining unauthorized access to computer networks and systems, and then selling that access to other threat actors.
  • Corporate Network: An interconnected system of computers, servers, and other digital devices within an organization that facilitates communication, data sharing, and resource access.

Black Basta Ransomware Group Targeted

Executive Summary

Law enforcement in Ukraine and Germany targeted members of the Black Basta ransomware group. Searches were conducted and the alleged leader, a Russian national, was placed on an international wanted list.

The Scheme

  • TTP 1: Password extraction from protected systems using specialized software.
  • TTP 2: Gaining access to internal corporate systems using stolen credentials.
  • TTP 3: Escalating account privileges to compromise internal infrastructure.

The Players

  • Threat Actor:Black Basta.
  • Facilitators Arrested: Two Ukrainian nationals.

The Consequence

  • Outcome: Hundreds of organizations were impacted between 2022 and 2025.
  • Assets Seized/Forfeited: Hundreds of millions of euros in losses.

Strategic Takeaway

International cooperation is crucial in dismantling ransomware groups that inflict significant financial damage.

Relevant Terms

  • Ransomware: A type of malware that encrypts a victim's files, demanding a ransom to restore access.
  • Hash Cracking: A method of recovering passwords from stolen data using specialized software.