Summary & highlights
Microsoft NTLM Phase-Out: Detection & Migration Guidance. Global HYIP Investment Scam Campaign - 4,200+ Fake Trading Platforms. Microsoft NTLM Deprecation - Enterprise Migration Planning Required.
Highlights
- TL-2026-0005 — Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft Campaign
- TL-2026-0006 — Automated MongoDB Extortion Campaign Targeting Exposed Instances
- TL-2026-0007 — UAT-8099 (China) BadIIS Malware Campaign Targeting IIS Servers for SEO Fraud
- TL-2026-0008 — OpenClaw CVE-2026-25253: One-Click RCE via Token Exfiltration
- TL-2026-0010 — Microsoft Office Zero-Day CVE-2026-21509: OLE Security Bypass Under Active Exploitation
Theme of the day
- credential-theft
- social-engineering
- cwe-306
- cwe-287
- cwe-345
Threats published
47 threat lines in the 2026-02-02 debrief, most severe first. Each links to its full profile.
- Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy InfrastructureCRITICAL
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social EngineeringCRITICAL
- Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiperCRITICAL
- SolarWinds Access Rights Manager (ARM) Systemic Deserialization RCE — 17 CVEs, 6 Unauth SYSTEM RCE, Access Control ParadoxCRITICAL
- GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain Attack Hijacking eScan Antivirus HTTP Updates via AitMCRITICAL
- Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar FarmsCRITICAL
- eScan Antivirus Supply Chain Attack - Update Server CompromiseCRITICAL
- CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against UkraineCRITICAL
- CVE-2026-25253: OpenClaw One-Click RCE via Malicious LinkCRITICAL
- Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft CampaignHIGH
- Automated MongoDB Extortion Campaign Targeting Exposed InstancesHIGH
- UAT-8099 (China) BadIIS Malware Campaign Targeting IIS Servers for SEO FraudHIGH
- OpenClaw CVE-2026-25253: One-Click RCE via Token ExfiltrationHIGH
- Microsoft Office Zero-Day CVE-2026-21509: OLE Security Bypass Under Active ExploitationHIGH
- LLMJacking: 175,000 Exposed Ollama AI Servers Targeted for AbuseHIGH
- Malicious Chrome Extensions: Affiliate Hijacking and ChatGPT Token Theft CampaignHIGH
- Malicious OpenClaw/MoltBot Skills - 230+ Supply Chain PackagesHIGH
- CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)HIGH
- MongoDB Data Extortion Campaign - 1,400+ Databases RansackedHIGH
- GlassWorm VS Code Extension Supply Chain Attack - Open VSX HijackHIGH
- Hugging Face Abused for Android Malware Distribution - Credential Stealer CampaignHIGH
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential TheftHIGH
- GlassWorm macOS Attack via Compromised OpenVSX ExtensionsHIGH
- SLSH Extortion Group - Swatting and Executive Harassment TacticsHIGH
- MongoDB Database Extortion Campaign - 1,400+ Instances RansackedHIGH
- Microsoft NTLM Deprecation - Three-Stage Phase-Out PlanHIGH
- IPIDEA Residential Proxy Botnet Disruption by GoogleHIGH
- Malicious OpenClaw/MoltBot Skills - 230+ Password-Stealing PackagesHIGH
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO AttacksHIGH
- 175,000 Exposed Ollama LLM Hosts Enable AI Model AbuseHIGH
- Cyber Insights 2026: AI-Powered Malware and Attack EvolutionHIGH
- BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest Encryption (4m30s), DLL Sideloading via Cortex XDR, Direct Syscalls EDR Evasion, Autonomous AD GPO Propagation, 122K Students Affected, Millions-Euro RansomHIGH
- Microsoft NTLM Phase-Out: Detection & Migration GuidanceMEDIUM
- Global HYIP Investment Scam Campaign - 4,200+ Fake Trading PlatformsMEDIUM
- Microsoft NTLM Deprecation - Enterprise Migration Planning RequiredMEDIUM
- 175,000 Exposed Ollama Hosts Enabling LLM AbuseMEDIUM
- Cloud Storage Payment Scam Campaign - Fake Renewal PhishingMEDIUM
- Record $158 Billion Illicit Cryptocurrency Flows in 2025MEDIUM
- NationStates Gaming Platform Data BreachMEDIUM
- Panera Bread Data Breach - 5.1 Million Accounts ExposedMEDIUM
- White House Revokes Biden-Era Software Security MemorandumsMEDIUM
- Google Slides Presentation Abuse for Phishing and Malware DeliveryMEDIUM
- Anthropic API Scanning Campaign - Targeting Self-Hosted LLM InfrastructureMEDIUM
- Global Surge in HYIP (High-Yield Investment Platform) ScamsMEDIUM
- White House Revokes Biden-Era Software Security MemorandumsMEDIUM
- Active Scanning for Exposed Anthropic API EndpointsMEDIUM
- Japan-Britain Cybersecurity Cooperation Agreement Amid China ConcernsLOW
Techniques observed
214 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0800
- T0804
- T0809
- T0814
- T0827
- T0828
- T0829
- T0831
- T0836
- T0846
- T0851
- T0855
- T0856
- T0861
- T0866
- T0875
- T0879
- T0880
- T0889
- T1003
- T1003.001
- T1003.003
- T1005
- T1016
- T1018
- T1020
- T1021
- T1021.002
- T1027
- T1027.002
- T1033
- T1036
- T1036.003
- T1036.005
- T1037
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.005
- T1055
- T1056
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1068
- T1069
- T1070
- T1070.001
- T1071
- T1074
- T1078
- T1078.001
- T1078.002
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.002
- T1090.003
- T1095
- T1098
- T1098.001
- T1102
- T1105
- T1106
- T1110
- T1110.001
- T1110.003
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1129
- T1132
- T1133
- T1134
- T1135
- T1136
- T1137
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1218
- T1219
- T1221
- T1222
- T1482
- T1484
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1495
- T1496
- T1497
- T1498
- T1499
- T1505
- T1518
- T1525
- T1526
- T1528
- T1529
- T1530
- T1531
- T1534
- T1535
- T1537
- T1538
- T1539
- T1543
- T1546
- T1547
- T1548
- T1550
- T1550.002
- T1552
- T1553
- T1553.002
- T1554
- T1555
- T1556
- T1557
- T1557.001
- T1558
- T1559
- T1560
- T1561
- T1561.001
- T1562
- T1562.001
- T1562.003
- T1562.004
- T1564
- T1565
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1574
- T1574.002
- T1578
- T1580
- T1583
- T1583.004
- T1583.005
- T1584
- T1584.005
- T1585
- T1585.001
- T1586
- T1587
- T1588
- T1588.002
- T1589
- T1590
- T1591
- T1592
- T1593
- T1594
- T1595
- T1595.002
- T1596
- T1597
- T1598
- T1606
- T1608
- T1611
- T1614.001
- T1615
- T1619
- T1621
- T1648
- T1649
- T1656
- T1657
- T1665
Threat actors
12 named threat actors across the reports.
- crazzynoob (dominant — 98% of attacks)
- UAT-8099
- Hecker
- 10Xprofit / Unknown
- ShinyHunters
- GlassWorm
- Scattered Lapsus ShinyHunters (SLSH)
- IPIDEA Operators / Multiple Criminal Groups (550+)
- Femwar02 (BaBlock/Rorschach affiliate)
- Static Tundra
- Kimsuky
- Russian State-Sponsored
Nation-state attribution
- China
- North Korea (partial)
- United States
- China (referenced threat)
- Russia
- France
- North Korea
Threat categories
- ADVISORY
- FRAUD
- MISCONFIGURATION
- PHISHING
- THREAT_INTEL
- DATA_BREACH
- POLICY
- MALWARE
- RANSOMWARE
- APT
- CVE
- CAMPAIGN
- SUPPLY_CHAIN
- VULNERABILITY
- EXTORTION
- THREAT_ACTOR
- ICS_SCADA
Severity breakdown
- critical9
- high23
- medium14
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 1301
- network 580
- host 277
- file 61
- email 6
- financial 3