Isometric network nodes illustrating global cyber threats and critical vulnerabilities.

Daily Cybersecurity News - January 28, 2026

Fortinet Blocks Critical SSO Exploit

Critical

Executive Summary

Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, that was actively exploited in the wild. The company mitigated the attacks by temporarily disabling FortiCloud Single Sign-On (SSO) and has now re-enabled the service with protections that block logins from devices running vulnerable firmware.

Vulnerability Details

  • Affected Product: FortiOS, FortiManager, FortiAnalyzer, and FortiProxy. Specific vulnerable versions include various builds across the 7.0, 7.2, 7.4, and 7.6 branches.
  • Identifier: CVE-2026-24858
  • CVSS Score: 9.4 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate action is required due to active exploitation of a critical vulnerability.
  • Attack Vector: The vulnerability allows an attacker with a FortiCloud account to bypass SSO authentication on other devices where FortiCloud SSO is enabled, granting improper access control.
  • Ease of Exploit: The exploit allows a remote, unauthenticated attacker to gain access, suggesting a low level of complexity.

Action Plan

  • Immediate Action: Upgrade to a patched firmware version immediately. Patches have been released, including FortiOS 7.4.11, with more fixes forthcoming for other affected products.
  • Workaround: Fortinet's server-side mitigation prevents vulnerable devices from using the FortiCloud SSO feature until they are upgraded. Disabling "Allow administrative login using FortiCloud SSO" in the device GUI is also a potential client-side mitigation.
  • Detection: Hunt for local admin accounts with suspicious names (e.g., audit, backup, itadmin, secadmin) and review logs for SSO logins from malicious accounts like "cloud-noc@mail.io" and "cloud-init@mail.io" or associated IP addresses provided in Fortinet's advisory.

Relevant professional terms

Zero-Day Vulnerability
A flaw in software or hardware that is discovered and exploited by attackers before the vendor is aware of it or has released a patch to fix it.
Single Sign-On (SSO)
An authentication scheme that allows a user to log in with a single set of credentials to multiple independent software systems.

WinRAR Flaw Enables Code Execution

High

Executive Summary

A high-severity vulnerability, CVE-2023-38831, in WinRAR is being actively exploited by threat actors. This logical flaw allows for arbitrary code execution when a user opens a specially crafted ZIP archive, tricking the application into running a malicious script instead of the benign file the user intended to open.

Vulnerability Details

  • Affected Product: WinRAR versions prior to 6.23.
  • Identifier: CVE-2023-38831
  • CVSS Score: 7.8 (High).
  • Exploitation Status: Actively Exploited.

Risk & Impact

  • Triage: Immediate patching is required due to active exploitation in the wild since at least April 2023.
  • Attack Vector: An attacker crafts a malicious ZIP archive containing a benign-looking file (e.g., a JPG or PDF) and a folder with the same name. When the user double-clicks the benign file, the vulnerability causes a malicious executable within the folder to be run instead.
  • Ease of Exploit: The exploit is relatively simple to execute, relying on social engineering to convince a user to open a malicious archive file.

Action Plan

  • Immediate Action: Upgrade to WinRAR Version 6.23 or later, which was released in August 2023 to patch this vulnerability.
  • Workaround: Exercise extreme caution with ZIP or RAR files from untrusted sources. Avoid opening archives received in unsolicited emails.
  • Detection: Monitor for suspicious processes spawned by WinRAR.exe. Hunt for the creation of unexpected files in temporary directories following the opening of an archive.

Relevant professional terms

Path Traversal
An attack that manipulates file path variables to access files and directories stored outside of the intended web root folder. This allows an attacker to read or potentially write to sensitive files on the system.
Malicious Payload
The component of a cyberattack that performs the harmful action. In the context of this vulnerability, the payload is the arbitrary code or script that executes on the victim's machine.

Nike Probes Massive Data Leak

Executive Summary

Nike is investigating a major cybersecurity incident after the "World Leaks" extortion group claimed to have stolen 1.4 TB of internal corporate data and published it online. The breach appears to be focused on intellectual property rather than customer or employee personal information.

Attack Overview

  • Attack Path: The initial access vector has not been disclosed; however, some reports suggest a possible supply chain vulnerability.
  • Attacker: World Leaks, an extortion-only group believed to be a rebrand of the Hunters International ransomware operation.

Impact Assessment

  • Data Stolen: 1.4 TB of sensitive corporate data, including product schematics, design files, manufacturing processes, and factory training materials.

Strategic Takeaway

This incident highlights the trend of extortion-only attacks that forgo encryption to focus on high-value intellectual property theft for industrial espionage and competitive advantage.

Relevant professional terms

Extortion Gang
A cybercriminal group that steals sensitive data and threatens to publish it unless a ransom is paid, without necessarily encrypting the victim's files.
Data Exfiltration
The unauthorized copying, transfer, or retrieval of data from a computer or server.

Mustang Panda Deploys Advanced Infostealer

Executive Summary

The Chinese-linked espionage group Mustang Panda is deploying an updated CoolClient backdoor to steal browser login credentials and monitor clipboard data. This campaign targets government entities across Asia for intelligence-gathering purposes.

Key TTPs

  • Initial Access: Spear-phishing with malicious archives and lures related to current geopolitical events.
  • Execution: Abusing legitimate, signed software from companies like Sangfor, Bitdefender, and VLC Media Player to load the malware.
  • Defense Evasion: DLL side-loading is used to execute the malicious payload, and the malware achieves persistence through new Windows services and scheduled tasks.

Campaign Analysis

This campaign showcases the evolution of Mustang Panda's toolset, with the updated CoolClient backdoor enhancing their capability to steal sensitive credentials for espionage. The group continues to adapt its tactics to bypass security solutions and maintain long-term access to targets of strategic interest.

Targeting & Infrastructure

  • Target Profile: Government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan.

Relevant Terms

  • Backdoor: A covert method of bypassing normal authentication or security controls in a computer system to gain unauthorized access.
  • DLL Side-Loading: An attack where a legitimate application is tricked into loading a malicious DLL file, allowing the attacker's code to be executed in a trusted process.

Hackers Hijack Exposed AI Infrastructure

Executive Summary

A campaign dubbed "Bizarre Bazaar" targets publicly exposed Large Language Model (LLM) service endpoints. The operation's goal is to commercialize unauthorized access to AI infrastructure by reselling it on darknet markets.

Key TTPs

  • Initial Access: Scanning internet-wide for misconfigured and unauthenticated AI APIs and LLM endpoints using tools like Shodan and Censys.
  • Execution: Hijacking validated endpoints to steal computing resources, exfiltrate data from prompts, and resell API access.

Campaign Analysis

This campaign signifies a tactical shift from traditional data theft to monetizing the computational power of AI models. The proliferation of weakly protected AI APIs presents a significant and expanding attack surface for threat actors.

Targeting & Infrastructure

  • Target Profile: Self-hosted LLM setups, development environments with public IPs, and production chatbots without proper authentication.
  • Infrastructure: A criminal supply chain resells access to compromised endpoints via Discord and Telegram, using bulletproof infrastructure in the Netherlands.

Relevant Terms

  • LLM (Large Language Model): An artificial intelligence model trained on vast amounts of text data to understand and generate human-like language.
  • API Endpoint: A specific digital location, like a URL, where a service can be accessed to perform a function or exchange data.

Cyberattacks Propel Latin America to Top Risk Zone

Executive Summary

Recent data reveals a dramatic surge in cyberattacks, positioning Latin America as the world's most at-risk region for cyber threats. Organizations in the area now face nearly 40% more weekly attacks than the global average, driven by AI-powered tools and data extortion tactics.

Key Findings

  • Organizations in Latin America experienced an average of 2,716 attacks per week in the first half of 2025, a significant jump from previous years.
  • Ransomware and extortion attacks in the region have increased by 15%, with Brazil, Mexico, and Argentina being the most targeted countries.
  • The most common attack vector is email, with 62% of malicious files delivered this way, while information disclosure is the top vulnerability, affecting 75% of organizations.

The Bottom Line

The escalation of cyber threats in Latin America signals a critical need for technical leaders to reassess regional security strategies. The focus on financially motivated attacks, combined with a deficit in local cybersecurity talent, creates a fertile ground for adversaries. Standard security measures are no longer sufficient, requiring enhanced investment in threat intelligence, employee training for phishing and social engineering, and advanced defenses to counter AI-driven and extortion-focused campaigns.

Relevant Terms

  • Edge Device Exploitation: Gaining unauthorized access to a network by compromising peripheral devices like routers, IoT sensors, or security cameras.
  • Data Leak Extortion: A cyberattack where criminals steal sensitive data and threaten to publish it online unless a ransom is paid.
Source: Dark Reading

US Indicts Gang in ATM Jackpotting Spree

Executive Summary

A Nebraska federal grand jury has charged 31 additional individuals for their roles in a nationwide ATM "jackpotting" scheme. This brings the total number of defendants to 87, many of whom are allegedly members of the Venezuelan transnational gang Tren de Aragua (TdA).

The Scheme

  • TTP 1: Physically compromising ATMs to install Ploutus malware via USB drives or by replacing hard drives.
  • TTP 2: Conducting reconnaissance and testing alarm responses before deploying the malware.
  • TTP 3: Using the malware to force ATMs to dispense all their cash, then laundering the stolen millions.

The Players

  • Threat Actor: Tren de Aragua (TdA)

The Consequence

  • Outcome: The 31 new defendants face a 32-count indictment for conspiracy to commit bank fraud, bank burglary, and computer fraud.

Strategic Takeaway

This large-scale indictment signals a significant U.S. effort to dismantle the financial operations of transnational criminal organizations that use cybercrime to fund other illicit activities.

Relevant Terms

  • ATM Jackpotting: A type of cyberattack where malware is installed on an ATM to force it to dispense large amounts of cash on command.
  • Transnational Criminal Organization: A structured group that operates across national borders to engage in illegal activities, such as trafficking, fraud, and terrorism.