The European Commission disclosed that attackers gained access to its mobile device management platform on January 30, 2026, with CERT‑EU detecting and helping contain the intrusion within nine hours. No mobile devices were found compromised, but staff names and phone numbers may have been accessed. The incident comes as Ivanti EPMM/CSA zero‑days are being widely exploited, underscoring the need to audit MDM exposure, apply vendor mitigations, and review authentication and logging around device enrollment.
Source: Help Net Security
BeyondTrust patches critical pre-auth RCE in Remote Support and PRA (CVE-2026-1731)
BeyondTrust fixed a 9.9 CVSS pre-authentication remote code execution flaw affecting Remote Support and older Privileged Remote Access releases that can be exploited via crafted requests. Cloud-hosted instances are already remediated; self-hosted customers should patch immediately, restrict external access until updated, and review logs for anomalous requests to /login and API endpoints.
Source: SecurityWeek
Fortinet warns: FortiClientEMS critical SQLi enables unauthenticated code execution (CVE-2026-21643)
Fortinet released fixes for a critical SQL injection vulnerability in FortiClientEMS that allows unauthenticated attackers to execute arbitrary code. Organizations should upgrade to the fixed versions without delay, block direct internet exposure of EMS, and hunt for unusual process launches or service changes on affected Windows servers.
Source: The Hacker News
Singapore: China-linked UNC3886 targeted all four telcos with rootkits and zero-day
Singapore’s authorities said espionage group UNC3886 conducted a “deliberate, targeted” campaign against the country’s four major telecom operators, leveraging stealthy rootkits and at least one zero-day. No service disruptions or customer data access were reported, but the operation highlights rising risks to edge devices and appliances that often lack EDR visibility.
Source: SecurityWeek
Attackers exploited SolarWinds Web Help Desk for initial access and credential theft
Microsoft observed multi-stage intrusions in December where internet‑exposed SolarWinds Web Help Desk instances were exploited to gain footholds, move laterally, and steal high‑privilege credentials. It’s unclear which specific CVEs were used, but defenders should patch to current versions, remove public exposure, enforce MFA for admin access, and hunt for lateral movement tied to WHD service accounts.
Source: SecurityWeek
Ransomware gang hit SmarterTools via unpatched SmarterMail server
SmarterTools confirmed the Warlock (Storm‑2603) group breached its network by exploiting a recently fixed SmarterMail flaw on an overlooked, unpatched VM. The incident disrupted a QC data center and affected customers, underscoring the danger of shadow IT and the urgency of complete asset inventories, rapid patching, and external surface monitoring.
Source: SecurityWeek
Officials warn of Signal account takeovers targeting politicians and journalists
European authorities are sounding the alarm about state‑sponsored phishing on Signal, with attackers impersonating “support” chatbots to hijack high‑profile accounts. Targets are tricked into sharing codes or linking devices, enabling silent interception of messages; users should enable Registration Lock PINs, scrutinize any “support” DMs, and verify device‑link prompts out of band.
Source: G DATA Security Blog
You May Also Be Interested In... - Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact Data - Discord to require video selfies or government IDs to verify all users’ ages - LLMs Are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days