THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
State-linked hijack of Notepad++ updates drops new ‘Chrysalis’ backdoor

Rapid7 researchers tied a months-long compromise of Notepad++’s update infrastructure to the China‑nexus APT “Lotus Blossom,” which used DLL sideloading and layered obfuscation to deliver a previously undocumented backdoor dubbed Chrysalis. The tool supports interactive shell, file ops, persistence, and encrypted C2, and investigators also observed loaders abusing Microsoft Warbird techniques and deploying Cobalt Strike. Organizations should validate Notepad++ update paths, hunt for sideloading artifacts (for example, rogue log.dll alongside legitimate binaries), and block related indicators.

Source: Rapid7


Russia’s APT28 rapidly weaponizes newly patched Microsoft Office flaw

CERT-UA and Zscaler observed APT28 exploiting CVE‑2026‑21509 in Microsoft Office within days of disclosure, targeting entities in Ukraine and across the EU. The bug enables bypass of mitigations around embedded content, facilitating execution chains for espionage. Patch immediately, enable Attack Surface Reduction rules where possible, and tighten Office macro/OLE policies.

Source: SecurityWeek


Microsoft begins phasing out NTLM, moving Windows toward Kerberos by default

Microsoft outlined a three‑stage plan to deprecate NTLM, with upcoming Windows and Windows Server releases disabling the legacy protocol by default. The shift aims to curb abuses like relay and pass‑the‑hash attacks, but will require enterprises to inventory and remediate NTLM dependencies across apps, services, and domains. Start testing Kerberos‑only modes and configure fallback carefully to avoid breaking legacy workflows.

Source: The Hacker News


GlassWorm supply-chain attack poisons Open VSX extensions

A hijacked Open VSX publisher account pushed malicious updates to established VS Code extensions, delivering a GlassWorm malware loader via trusted developer tooling. The incident underscores how attacker activity can blend into normal dev workflows, spreading quickly through automated updates. Lock down extension sources, pin and verify publishers, and monitor IDE extension update events in CI/CD.

Source: SecurityWeek


One‑click RCE in OpenClaw highlights AI agent ecosystem risk

A high‑severity flaw in OpenClaw (CVE‑2026‑25253) allowed remote code execution via crafted links by exfiltrating auth tokens; a fix shipped in version 2026.1.29. As AI agents aggregate credentials and actions across services, token theft and malicious “skills” can become a potent supply‑chain vector. Update immediately, rotate tokens, and restrict agent permissions to least privilege.

Source: The Hacker News


Polish energy facilities hit via default ICS credentials

CERT Polska detailed destructive attacks against energy infrastructure in late December, where adversaries leveraged default credentials on industrial control systems to pivot and disrupt operations. The report links activity to a known state‑sponsored cluster and provides new technical specifics on targeted ICS. OT operators should eliminate default passwords, enforce network segmentation, and deploy focused ICS monitoring for abnormal commands.

Source: SecurityWeek


ShinyHunters ramp up SaaS data theft using MFA social engineering

Threat actors operating under the ShinyHunters banner escalated extortion‑driven intrusions by vishing help desks, harvesting credentials, and enrolling unauthorized MFA to access cloud SaaS. Recent campaigns targeted high‑profile brands and leveraged evolved phishing to bypass identity controls. Enforce phishing‑resistant MFA, lock down help‑desk MFA resets with strong verification, and monitor for anomalous SSO/MFA enrollment events.

Source: SecurityWeek


You May Also Be Interested In...

The Notepad++ supply chain attack — unnoticed execution chains and new IoCs (Securelist)

Over 1,400 MongoDB Databases Ransacked by Threat Actor (SecurityWeek)

Mozilla Adds One‑Click Option to Disable Generative AI Features in Firefox (The Hacker News)

Cybersecurity — February 3, 2026 | Briefing24