Rapid7 researchers tied a months-long compromise of Notepad++’s update infrastructure to the China‑nexus APT “Lotus Blossom,” which used DLL sideloading and layered obfuscation to deliver a previously undocumented backdoor dubbed Chrysalis. The tool supports interactive shell, file ops, persistence, and encrypted C2, and investigators also observed loaders abusing Microsoft Warbird techniques and deploying Cobalt Strike. Organizations should validate Notepad++ update paths, hunt for sideloading artifacts (for example, rogue log.dll alongside legitimate binaries), and block related indicators.
Source: Rapid7
Russia’s APT28 rapidly weaponizes newly patched Microsoft Office flaw
CERT-UA and Zscaler observed APT28 exploiting CVE‑2026‑21509 in Microsoft Office within days of disclosure, targeting entities in Ukraine and across the EU. The bug enables bypass of mitigations around embedded content, facilitating execution chains for espionage. Patch immediately, enable Attack Surface Reduction rules where possible, and tighten Office macro/OLE policies.
Source: SecurityWeek
Microsoft begins phasing out NTLM, moving Windows toward Kerberos by default
Microsoft outlined a three‑stage plan to deprecate NTLM, with upcoming Windows and Windows Server releases disabling the legacy protocol by default. The shift aims to curb abuses like relay and pass‑the‑hash attacks, but will require enterprises to inventory and remediate NTLM dependencies across apps, services, and domains. Start testing Kerberos‑only modes and configure fallback carefully to avoid breaking legacy workflows.
Source: The Hacker News
GlassWorm supply-chain attack poisons Open VSX extensions
A hijacked Open VSX publisher account pushed malicious updates to established VS Code extensions, delivering a GlassWorm malware loader via trusted developer tooling. The incident underscores how attacker activity can blend into normal dev workflows, spreading quickly through automated updates. Lock down extension sources, pin and verify publishers, and monitor IDE extension update events in CI/CD.
Source: SecurityWeek
One‑click RCE in OpenClaw highlights AI agent ecosystem risk
A high‑severity flaw in OpenClaw (CVE‑2026‑25253) allowed remote code execution via crafted links by exfiltrating auth tokens; a fix shipped in version 2026.1.29. As AI agents aggregate credentials and actions across services, token theft and malicious “skills” can become a potent supply‑chain vector. Update immediately, rotate tokens, and restrict agent permissions to least privilege.
Source: The Hacker News
Polish energy facilities hit via default ICS credentials
CERT Polska detailed destructive attacks against energy infrastructure in late December, where adversaries leveraged default credentials on industrial control systems to pivot and disrupt operations. The report links activity to a known state‑sponsored cluster and provides new technical specifics on targeted ICS. OT operators should eliminate default passwords, enforce network segmentation, and deploy focused ICS monitoring for abnormal commands.
Source: SecurityWeek
ShinyHunters ramp up SaaS data theft using MFA social engineering
Threat actors operating under the ShinyHunters banner escalated extortion‑driven intrusions by vishing help desks, harvesting credentials, and enrolling unauthorized MFA to access cloud SaaS. Recent campaigns targeted high‑profile brands and leveraged evolved phishing to bypass identity controls. Enforce phishing‑resistant MFA, lock down help‑desk MFA resets with strong verification, and monitor for anomalous SSO/MFA enrollment events.
Source: SecurityWeek
You May Also Be Interested In...
The Notepad++ supply chain attack — unnoticed execution chains and new IoCs (Securelist)
Over 1,400 MongoDB Databases Ransacked by Threat Actor (SecurityWeek)
Mozilla Adds One‑Click Option to Disable Generative AI Features in Firefox (The Hacker News)