← Carolina Clear Tech

Cyber Threat Brief

2026-02-09

Listen to this brief (15:20)

Download MP3
Show Notes

Show Notes - 2026-02-09

Stories Covered

CVEs Referenced

CVE-2019-19006, CVE-2021-39935, CVE-2024-40766, CVE-2025-40536, CVE-2025-40537, CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554, CVE-2025-64328, CVE-2026-1281, CVE-2026-1340, CVE-2026-23760, CVE-2026-24423

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-02-09

Collected: 2026-02-09 Generated by: Claude Code (Opus 4.6)


Critical Alerts

SolarWinds Web Help Desk: Multiple Critical RCEs Actively Exploited (CISA KEV)

CISA added CVE-2025-40551 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog. This is an unauthenticated deserialization-to-RCE flaw in SolarWinds Web Help Desk. Microsoft confirmed exploitation of CVE-2025-40551 and CVE-2025-40536 (CVSS 8.1) can lead to full domain compromise. SecurityWeek reports evidence of exploitation dating back to December 2025, meaning these were likely used as zero-days before patches shipped.


Ivanti EPMM Zero-Days: 86+ Confirmed Compromises, Dutch Government Breached

Two Ivanti Endpoint Manager Mobile vulnerabilities, CVE-2026-1281 and CVE-2026-1340 (both CVSS 9.8), are being mass-exploited following disclosure on January 29. Shadowserver has identified 86 compromised instances so far, with hundreds of exploitation attempts from 130+ unique IPs hitting Rapid7's honeypot in a single 24-hour window. The Dutch Data Protection Authority and Council for the Judiciary confirmed breaches exposing staff names, emails, and phone numbers. The European Commission also reported an attack on its mobile device management infrastructure.


Vulnerability Disclosures

SmarterMail Auth Bypass and RCE Exploited by Warlock Ransomware (Storm-2603)

CVE-2026-23760 is an authentication bypass in SmarterMail (before Build 9518) that allows resetting admin passwords and gaining full privileges. CVE-2026-24423 is a separate RCE flaw added to CISA's KEV last week. The Warlock ransomware gang, linked to Chinese nation-state actor Storm-2603, is actively chaining these flaws. SmarterTools confirmed its own network was breached through an unpatched SmarterMail VM; attackers moved laterally via Active Directory and compromised 12 Windows servers before SentinelOne blocked the final encryption payload.


CISA KEV: Sangoma FreePBX and GitLab Flaws Added

Three additional vulnerabilities were added to CISA KEV alongside the SolarWinds flaw. CVE-2019-19006 (CVSS 9.8) is an auth bypass in Sangoma FreePBX exploited since 2020 by the INJ3CTOR3 VoIP fraud operation. CVE-2025-64328 (CVSS 8.6) is a command injection in FreePBX being used since December 2025 to deploy the EncystPHP webshell, which creates backdoor accounts, resets passwords, and modifies SSH keys. CVE-2021-39935 (CVSS 7.5) is a GitLab SSRF being exploited as part of a broader SSRF surge across multiple platforms.


React Server Components RCE Under Active Exploitation (React2Shell)

A critical vulnerability in React Server Components is being actively exploited by multiple Chinese threat actors. Recorded Future is urging immediate patching.


Ransomware & Extortion

Black Basta Embeds BYOVD Directly in Ransomware Payload

Black Basta is now bundling "bring your own vulnerable driver" capability directly into the ransomware binary rather than deploying it as a separate pre-encryption tool. The signed vulnerable driver runs in kernel mode to terminate security processes before encryption begins. This was observed alongside typical Black Basta TTPs: shadow copy deletion via WMI, event log clearing, and lateral movement.


Obscura: New Ransomware Variant Found on Domain Controller

Huntress discovered a previously unseen ransomware variant called "Obscura" deployed on a victim's domain controller. Details are limited, but finding ransomware directly on a DC indicates the attacker had full domain admin access.


Ransomware Groups Pivoting Back to Encryption as Data Theft ROI Drops

Ransomware operators made less money in 2025 despite a 47% increase in attacks. Data-theft-only extortion is delivering diminishing returns, pushing groups back toward file encryption for leverage. New tactics emerging for 2026 include bundled DDoS services, insider recruitment at target companies, and exploitation of gig workers.


SLSH Extortion Crew Uses Swatting and Personal Harassment

An extortion group combining ShinyHunters and Scattered Spider tactics is pairing data theft with personal harassment of executives and their families, including direct threats and swatting. The behavior is less predictable than traditional ransomware groups and escalates quickly.


MSP / SMB Threats

SonicWall VPN Exploitation Continues, Linked to Akira Ransomware

Active exploitation of SonicWall seventh-generation firewalls continues, with Huntress tracking at least 28 incidents. The activity is linked to CVE-2024-40766 (improper access control in SonicOS management/SSL VPN), primarily affecting organizations that migrated from Gen 6 to Gen 7 firewalls without resetting local passwords. Akira ransomware operators are using BYOVD (rwdrv.sys, hlpdrv.sys) to disable security tools before encryption.


Romania Oil Pipeline Operator Hit by Qilin Ransomware

Conpet, Romania's national oil pipeline operator, reported a cyberattack that disrupted IT infrastructure and took its website offline. Qilin ransomware group claimed nearly 1 TB of data theft. OT/SCADA systems were unaffected due to IT-OT segmentation.


General Security News

DEAD#VAX Campaign Delivers AsyncRAT via IPFS-Hosted VHD Files

A phishing campaign is delivering AsyncRAT through IPFS-hosted virtual hard disk (VHD) attachments with heavily obfuscated scripts. The attack chain uses in-memory execution and injection into trusted Windows processes to minimize disk artifacts.


CrashFix: New ClickFix Variant Crashes Browsers to Deploy Python RAT

Microsoft describes a ClickFix evolution where attackers intentionally crash a victim's browser, then social-engineer them into running "fix" commands that install a Python-based remote access trojan. Reduces reliance on traditional exploit chains by abusing user trust.


LLMs Now Finding Zero-Days in Well-Tested Codebases

Schneier highlights Claude Opus 4.6 discovering high-severity vulnerabilities in codebases that had years of fuzzing coverage. Unlike fuzzers, the model reads and reasons about code, identifying patterns and logic flaws rather than throwing random inputs. This signals a shift in the vulnerability discovery landscape that will accelerate both offensive and defensive capabilities.


Trends & Context

Today's articles paint a clear picture: edge devices and on-premises software remain the primary attack surface for ransomware operators targeting MSP/SMB environments. SolarWinds WHD, Ivanti EPMM, SmarterMail, and SonicWall VPNs were all exploited through unpatched internet-facing services, with multiple incidents leading to Active Directory compromise and ransomware deployment. The BYOVD technique (Black Basta, Akira) embedding kernel drivers inside ransomware payloads is an escalation that directly targets endpoint protection, making driver-level defenses and vulnerable driver blocklists increasingly important for every managed environment.


Carolina Clear Tech, LLC - carolinacleartech.com