Isometric network nodes highlighting global cyber threats and data breach risks.

Daily Cybersecurity News - January 20, 2026

Chainlit Vulnerabilities May Leak Sensitive Information

Executive Summary

Two high-severity vulnerabilities, CVE-2026-22218 and CVE-2026-22219, in Chainlit versions prior to 2.9.4, can be exploited without user interaction to leak credentials, databases, and other sensitive data. These vulnerabilities include an arbitrary file read and a Server-Side Request Forgery (SSRF) bug.

Vulnerability Details

  • Affected Product: Chainlit versions prior to 2.9.4
  • Identifier: CVE-2026-22218, CVE-2026-22219
  • CVSS Score: High Severity
  • Exploitation Status: No indications of in-the-wild exploitation observed

Risk & Impact

  • Triage: Immediate action recommended due to the potential for sensitive information disclosure.
  • Attack Vector: Exploitation can lead to the exfiltration of environment variables, API keys, credentials, internal file paths, and internal IPs. An attacker could also forge authentication tokens and take over accounts.
  • Ease of Exploit: Easy to exploit

Action Plan

  • Immediate Action: Upgrade to Version 2.9.4 or higher
  • Workaround: No specific workaround is mentioned, but ensure proper authorization checks and restrictions on file path handling.
  • Detection: Monitor for suspicious requests targeting file paths and internal network services.

Relevant professional terms

Server-Side Request Forgery (SSRF)
A vulnerability that allows an attacker to make requests to internal network services or cloud metadata endpoints from the server.
Arbitrary File Read
A vulnerability that allows an attacker to read any file on the server, potentially leading to sensitive information disclosure.
Source: SecurityWeek

Three Security Vulnerabilities Disclosed in Anthropic MCP Git Server

Medium

Executive Summary

Three security vulnerabilities have been discovered in Anthropic's mcp server git, potentially allowing attackers to read or delete arbitrary files and execute code under specific conditions.

Vulnerability Details

  • Affected Product: MCP server git (official Git Model Context Protocol MCP server)
  • Identifier: CVE-2025-68143, CVE-2025-68144, CVE-2025-68145
  • CVSS Score: 6.3 - 6.5 (Medium)
  • Exploitation Status: No indications of in-the-wild exploitation

Risk & Impact

  • Triage: High Urgency
  • Attack Vector: Exploitation through pull requests.
  • Ease of Exploit: Unknown

Action Plan

  • Immediate Action: Apply necessary patches.
  • Workaround: Implement strict input validation and sanitization.
  • Detection: Monitor for suspicious pull request activity.

Relevant professional terms

Git
A distributed version control system for tracking changes in source code during software development.
Code Execution
The ability to run arbitrary commands or code on a target system, often leading to system compromise.

Russian Hacktivists Target UK Infrastructure

Executive Summary

Russian-aligned hacktivist groups are actively targeting critical infrastructure and local government organizations in the UK. These groups employ disruptive DDoS attacks motivated by ideology rather than financial gain.

Key TTPs

  • Initial Access: Exploit minimally secured VNC connections.
  • Execution: Conduct DDoS attacks using tools like DDoSia.
  • Defense Evasion: Combine DDoS with credential leaks and ICS disruption.

Campaign Analysis

The attacks are ideologically driven, reflecting an evolution in the threat landscape. These groups often exaggerate claims to gain notoriety.

Targeting & Infrastructure

  • Target Profile: UK local government and critical infrastructure, including energy, water, and agriculture sectors.
  • Infrastructure: Telegram channels and GitHub repositories are used to share TTPs and host DDoS tools.

Relevant Terms

  • DDoS: A distributed denial-of-service attack floods a network with traffic, making it unavailable.
  • VNC: Virtual Network Computing, a desktop sharing system that uses the RFB protocol to remotely control another computer.

LinkedIn Phishing Campaign Targets Business Executives

Executive Summary

A phishing campaign is targeting high-value individuals, particularly finance executives, through LinkedIn messages. The attackers aim to compromise accounts by enticing users with fake board invitations and other lures.

Key TTPs

  • Initial Access: LinkedIn direct messages with malicious links.
  • Execution: DLL side-loading combined with a legitimate, open-source Python pen-testing script.
  • Defense Evasion: Attackers use lengthy redirect chains through trusted sites.

Campaign Analysis

Attackers are increasingly using LinkedIn to target business users, bypassing traditional email security measures. The campaign leverages social engineering and cloud abuse to steal credentials and session tokens.

Targeting & Infrastructure

  • Target Profile: Finance executives, sales leaders, and hiring managers.
  • Infrastructure: Utilizes Google Search, Firebase, and Microsoft Dynamics for redirects.

Actionable Intelligence

  • Domains:payrails-canaccord[.]icu, boardproposalmeet[.]com, sqexclusiveboarddirect[.]icu, login.kggpho[.]icu

Relevant Terms

  • DLL Side-Loading: A technique where a malicious DLL is loaded by a legitimate application to execute malicious code.
  • Phishing: A type of social engineering attack used to steal user data, including login credentials and credit card numbers.

CrashFix Campaign Delivers ModeloRAT via Fake Extension

Executive Summary

The KongTuke threat actor group is distributing a malicious Chrome extension, NexShield, disguised as an ad blocker. This extension crashes the victim's browser and uses social engineering to trick users into running malicious commands, ultimately deploying the ModeloRAT.

Key TTPs

  • Initial Access: Malicious advertisements redirect users to the Chrome Web Store to download the fake ad blocker.
  • Execution: Victims are tricked into executing malicious PowerShell commands via a fake "repair" prompt.
  • Defense Evasion: The extension delays malicious behavior for 60 minutes after installation to avoid immediate suspicion.

Campaign Analysis

The CrashFix campaign represents an evolution in KongTuke's tactics, utilizing a fake browser crash and social engineering to deploy ModeloRAT. The malware can perform system reconnaissance, execute PowerShell commands, and modify the Registry.

Targeting & Infrastructure

  • Target Profile: Corporate networks are targeted with the ModeloRAT payload.
  • Infrastructure: The extension uses attacker-controlled infrastructure at nexsnield[.]com.

Actionable Intelligence

  • IPs: 199.217.98[.]108
  • Domains: nexsnield[.]com

Relevant Terms

  • ClickFix: A social engineering technique where users are tricked into clicking or executing something they shouldn't, often under the guise of fixing a problem.
  • RAT (Remote Access Trojan): A type of malware that allows an attacker to remotely control an infected computer.
Source: Malwarebytes

AI Fuels Cybercrime's Fifth Wave

Executive Summary

Group-IB reports that weaponized AI is driving a new wave of cybercrime by offering inexpensive and readily available malicious tools, enabling more sophisticated and scalable attacks. This "fifth wave" marks a shift towards AI-driven cyber offenses.

Key Findings

  • AI is turning human skills into scalable services, making cybercrime cheaper and faster.
  • Synthetic identity kits, including AI video actors and cloned voices, are available for as little as $5.
  • Discussions about AI-powered tools for criminal purposes on dark web forums have surged from an average of below 50,000 messages between 2020-2022 to approximately 300,000 messages every year since 2023.

The Bottom Line

The increasing accessibility and affordability of AI tools are lowering the barrier to entry for cybercriminals, allowing even novices to execute sophisticated attacks. This industrialization of cybercrime, where AI transforms specialized skills into on-demand services, poses a significant threat to organizations. Security strategies must adapt to address AI-driven threats, including the use of AI for both offensive and defensive purposes.

Relevant Terms

  • Deepfake: Synthetic media in which a person in an existing image or video is replaced with someone else's likeness.
  • Weaponized AI: The use of artificial intelligence by malicious actors to enhance or automate cyberattacks.

Hacker Pleads Guilty to Breaching Government Systems

Executive Summary

Nicholas Moore pleaded guilty to hacking the U.S. Supreme Court's electronic filing system, as well as systems belonging to AmeriCorps and the Department of Veterans Affairs. Moore accessed these systems using stolen credentials and posted screenshots and personal data on Instagram.

The Scheme

  • TTP 1: Stole credentials from authorized users.
  • TTP 2: Accessed Supreme Court's electronic filing system, AmeriCorps, and VA systems.
  • TTP 3: Posted screenshots and personal data on Instagram.

The Players

  • Facilitators Arrested:Nicholas Moore

The Consequence

  • Outcome: Moore pleaded guilty to computer fraud and faces up to a year in prison and a $100,000 fine.

Strategic Takeaway

This incident highlights the risk of stolen credentials and the potential for sensitive data breaches across multiple government agencies.

Relevant Terms

  • Stolen Credentials: Illegally obtained login information, such as usernames and passwords, used to access systems without authorization.
  • Data Breach: A security incident where sensitive, protected, or confidential data is copied, transmitted, viewed, stolen, or used by an individual unauthorized to do so.