Weaponised the same day: 2026 opens at exploit speed
A CVSS-10 HPE OneView flaw is botnet-weaponised the day CISA flags it. Ransomware takes down three quarters of a South Korean conglomerate's servers, putting 9.6 million accounts at risk. And a single phishing attack at a Canadian regulator ends with 750,000 investors exposed.
Executive summary
- The flag-to-weaponise window has hit zero. The RondoDox botnet began exploiting a CVSS-10 HPE OneView remote-code-execution flaw the same day CISA added it to the Known Exploited Vulnerabilities catalog.
- Encryption and pure exfiltration are running in parallel. A classic ransomware attack crippled ~600 of Kyowon's 800 servers in South Korea, while newer crews like Crimson Collective claimed a million-customer haul from a US broadband provider without deploying any payload at all.
- One phishing email can carry regulator-grade consequences. Canada's investment regulator CIRO confirmed 750,000 investors were exposed, including social insurance numbers and account data, from a single phishing intrusion.
Key findings
Ransomware cripples Kyowon Group; up to 9.6 million accounts at risk
South Korean conglomerate Kyowon confirmed a ransomware attack with data exfiltration after abnormal activity was detected on 10 January. Roughly 600 of its 800 servers were impacted, causing major service outages, and authorities estimate up to 9.6 million user accounts may be affected. One of South Korea's largest recent cyber incidents.
Canada's investment regulator confirms 750,000 investors exposed
The Canadian Investment Regulatory Organization completed its forensic investigation into an August 2025 phishing attack and confirmed roughly 750,000 investors were impacted. Compromised data includes social insurance numbers, government IDs, income and investment-account details. When the regulator itself is the victim, the trust cost lands on the whole sector.
CVSS-10 HPE OneView flaw botnet-weaponised the day CISA flags it
CISA added a perfect-score HPE OneView code-injection flaw to the KEV catalog on 7 January, and the RondoDox botnet began exploiting it the same day. Infrastructure-management planes are being industrialised as initial access at the speed of the advisory itself.
First Patch Tuesday of 2026: 114 flaws, one exploited zero-day
Microsoft's January update fixed 114 vulnerabilities including eight critical and an actively exploited Windows Desktop Window Manager information-disclosure zero-day used to enable follow-on exploitation, which CISA added to KEV the same day. A publicly disclosed Secure Boot bypass rounds out the priority list.
Fake Booking.com blue-screens turn hotel staff into initial access
The PHALT#BLYX campaign targets European hotel staff with fake reservation-cancellation emails that lead to a cloned Booking.com site, a fake captcha and a fake Windows blue-screen using the ClickFix technique to trick staff into running a PowerShell command, delivering the DCRat remote-access trojan via MSBuild abuse.
The broader pattern
- Same-day weaponisation is the new baseline. A KEV addition is not a planning input, it is an incident trigger: patch and hunt the day the entry lands.
- Pure data-extortion crews are scaling alongside encryptors. Crimson Collective claimed data on over a million Brightspeed customers with no ransomware payload; detection keyed on encryption events sees nothing.
- The boardroom mood has shifted. The WEF's Davos-week outlook found cyber-enabled fraud has overtaken ransomware as the top CEO concern, and only a minority of leaders are confident in national incident response.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Treat KEV additions as same-day patch-and-hunt triggers. The HPE OneView flaw was botnet-exploited the day it was flagged; assume exposure until hunted.
Patch January's Patch Tuesday set, prioritising the exploited DWM zero-day. 114 flaws, eight critical; the exploited information-disclosure bug is a link in privilege-escalation chains.
Extend detection beyond encryption events. Pure-exfiltration extortion produces no encryptor signature; baseline egress volume and cloud-storage access per identity.
Drill the phishing story with regulated-data custodians. One phishing intrusion at CIRO became 750,000 exposed investors; test your own escalation from single compromised mailbox to crown-jewel data.
Brief hospitality and front-line staff on ClickFix lures. If a web page asks anyone to run a command to fix an error, that is the compromise, not the fix.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
When a CVSS-10 flaw is weaponised the day it is flagged, defence has to move at the same speed. Blacklight correlates new KEV entries against your actual asset inventory the day they land, hunts retroactively across your telemetry for prior exploitation, and its agents investigate the behavioural signals that pure-exfiltration crews leave, anomalous egress, cloud-storage access and identity misuse, with every verdict carrying its full reasoning trail.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 7 and 13 January 2026) · Microsoft January 2026 Patch Tuesday release notes · public breach disclosures and security-press reporting (BleepingComputer, The Record, Korea Herald, CIRO), 5 – 18 January 2026 · Check Point Research weekly threat intelligence (12 and 19 January 2026) · Securonix PHALT#BLYX analysis · WEF Global Cybersecurity Outlook 2026 · UK Parliament, Cyber Security and Resilience Bill · MITRE ATT&CK v15 for technique mapping.