Skip to content
All resources
Cybersecurity Intel · № 01 · 5 – 18 January 2026

Weaponised the same day: 2026 opens at exploit speed

A CVSS-10 HPE OneView flaw is botnet-weaponised the day CISA flags it. Ransomware takes down three quarters of a South Korean conglomerate's servers, putting 9.6 million accounts at risk. And a single phishing attack at a Canadian regulator ends with 750,000 investors exposed.

Published 19 January 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
114
Flaws fixed in Microsoft's January Patch Tuesday, one already exploited
9.6M
Accounts at risk after ransomware hit ~600 of Kyowon's 800 servers
750K
Canadian investors exposed by one phishing attack on their regulator
10.0
CVSS of the HPE OneView flaw botnet-exploited the day it was flagged

Executive summary

  • The flag-to-weaponise window has hit zero. The RondoDox botnet began exploiting a CVSS-10 HPE OneView remote-code-execution flaw the same day CISA added it to the Known Exploited Vulnerabilities catalog.
  • Encryption and pure exfiltration are running in parallel. A classic ransomware attack crippled ~600 of Kyowon's 800 servers in South Korea, while newer crews like Crimson Collective claimed a million-customer haul from a US broadband provider without deploying any payload at all.
  • One phishing email can carry regulator-grade consequences. Canada's investment regulator CIRO confirmed 750,000 investors were exposed, including social insurance numbers and account data, from a single phishing intrusion.

Key findings

10 – 14 January 2026 Ransomware · T1486

Ransomware cripples Kyowon Group; up to 9.6 million accounts at risk

South Korean conglomerate Kyowon confirmed a ransomware attack with data exfiltration after abnormal activity was detected on 10 January. Roughly 600 of its 800 servers were impacted, causing major service outages, and authorities estimate up to 9.6 million user accounts may be affected. One of South Korea's largest recent cyber incidents.

14 January 2026 ATT&CK T1566

Canada's investment regulator confirms 750,000 investors exposed

The Canadian Investment Regulatory Organization completed its forensic investigation into an August 2025 phishing attack and confirmed roughly 750,000 investors were impacted. Compromised data includes social insurance numbers, government IDs, income and investment-account details. When the regulator itself is the victim, the trust cost lands on the whole sector.

7 January 2026 CVE-2025-37164 · KEV

CVSS-10 HPE OneView flaw botnet-weaponised the day CISA flags it

CISA added a perfect-score HPE OneView code-injection flaw to the KEV catalog on 7 January, and the RondoDox botnet began exploiting it the same day. Infrastructure-management planes are being industrialised as initial access at the speed of the advisory itself.

13 January 2026 CVE-2026-20805 · KEV

First Patch Tuesday of 2026: 114 flaws, one exploited zero-day

Microsoft's January update fixed 114 vulnerabilities including eight critical and an actively exploited Windows Desktop Window Manager information-disclosure zero-day used to enable follow-on exploitation, which CISA added to KEV the same day. A publicly disclosed Secure Boot bypass rounds out the priority list.

6 – 7 January 2026 ATT&CK T1566 / T1204

Fake Booking.com blue-screens turn hotel staff into initial access

The PHALT#BLYX campaign targets European hotel staff with fake reservation-cancellation emails that lead to a cloned Booking.com site, a fake captcha and a fake Windows blue-screen using the ClickFix technique to trick staff into running a PowerShell command, delivering the DCRat remote-access trojan via MSBuild abuse.

The broader pattern

  • Same-day weaponisation is the new baseline. A KEV addition is not a planning input, it is an incident trigger: patch and hunt the day the entry lands.
  • Pure data-extortion crews are scaling alongside encryptors. Crimson Collective claimed data on over a million Brightspeed customers with no ransomware payload; detection keyed on encryption events sees nothing.
  • The boardroom mood has shifted. The WEF's Davos-week outlook found cyber-enabled fraud has overtaken ransomware as the top CEO concern, and only a minority of leaders are confident in national incident response.

Sector lens

Healthcare
A cyberattack on Belgium's AZ Monica hospital forced a full IT shutdown, cancelled surgeries and transferred seven critical patients. Availability is the clinical risk; containment speed is the control.
Financial services
The CIRO breach shows a regulator's own systems are part of your sector's attack surface, and DORA has just entered its first genuine enforcement year in the EU.
Education
Kyowon's education platforms sat at the centre of a 9.6-million-account incident; large student and subscriber databases are ransomware leverage.
Hospitality & travel
PHALT#BLYX is aimed squarely at hotel front desks. Booking-platform lures with urgent charges are the sector's phishing theme of the month; brief the staff who handle reservations.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Treat KEV additions as same-day patch-and-hunt triggers. The HPE OneView flaw was botnet-exploited the day it was flagged; assume exposure until hunted.

02

Patch January's Patch Tuesday set, prioritising the exploited DWM zero-day. 114 flaws, eight critical; the exploited information-disclosure bug is a link in privilege-escalation chains.

03

Extend detection beyond encryption events. Pure-exfiltration extortion produces no encryptor signature; baseline egress volume and cloud-storage access per identity.

04

Drill the phishing story with regulated-data custodians. One phishing intrusion at CIRO became 750,000 exposed investors; test your own escalation from single compromised mailbox to crown-jewel data.

05

Brief hospitality and front-line staff on ClickFix lures. If a web page asks anyone to run a command to fix an error, that is the compromise, not the fix.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

When a CVSS-10 flaw is weaponised the day it is flagged, defence has to move at the same speed. Blacklight correlates new KEV entries against your actual asset inventory the day they land, hunts retroactively across your telemetry for prior exploitation, and its agents investigate the behavioural signals that pure-exfiltration crews leave, anomalous egress, cloud-storage access and identity misuse, with every verdict carrying its full reasoning trail.

Book a Demo

Sources & methodology

Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 7 and 13 January 2026) · Microsoft January 2026 Patch Tuesday release notes · public breach disclosures and security-press reporting (BleepingComputer, The Record, Korea Herald, CIRO), 5 – 18 January 2026 · Check Point Research weekly threat intelligence (12 and 19 January 2026) · Securonix PHALT#BLYX analysis · WEF Global Cybersecurity Outlook 2026 · UK Parliament, Cyber Security and Resilience Bill · MITRE ATT&CK v15 for technique mapping.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 01 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.