Daily Drop (1225)
01-14-26
Wednesday, Jan 14, 2025 // (IG): BB // GITHUB // SN R&D
Trump Weighs U.S. Response to Iran Crackdown Amid Historic Unrest
Bottom Line Up Front (BLUF): The United States is actively considering a broad spectrum of responses—including military strikes, cyber operations, sanctions, and support for dissidents—in reaction to Iran’s ongoing brutal crackdown on mass protests. President Trump has announced a 25% tariff on all nations doing business with Iran, escalating economic pressure. Meanwhile, Iran acknowledges ongoing backchannel communication with U.S. envoys, even as it blames the unrest on “U.S.-Israeli terrorism.” Despite rising casualties and arrests, there are no current signs of fracture within the Iranian regime or security services.
Analyst Comments: Trump’s public posture suggests high-risk escalation, while private diplomacy continues. Expect the U.S. to pursue deniable, non-kinetic options first (e.g., cyber ops, information warfare) before committing to overt strikes. Watch for pressure campaigns on Iranian oil exports and Chinese firms to widen the economic vise. The deployment of Starlink as a censorship-bypass tool is strategically significant—Tehran’s inability to fully suppress communications despite a national blackout highlights both the power and fragility of satellite-based circumvention. Iran’s threats to U.S. bases and Israel remain boilerplate, but escalation risk is real if Trump takes kinetic action before diplomatic channels play out.
READ THE STORY: Reuters
EU Weighs Harsher Sanctions Amid Iran Crackdown and Human Rights Violations
Bottom Line Up Front (BLUF): The European Union is considering tightening sanctions on Iran in response to the regime's violent crackdown on mass protests and its support for Russia’s war in Ukraine. German and French officials are pushing for new restrictive measures targeting Iranian security forces, surveillance tech suppliers, and drone manufacturers. However, EU cohesion remains fragile, with some member states hesitant to further escalate economic pressure.
Analyst Comments: While designations on IRGC-linked entities and drone suppliers signal intent, Iran’s hardline behavior hasn’t shifted. The bigger lever—designation of the IRGC as a terrorist group across the EU bloc—remains politically blocked, largely over legal and diplomatic concerns. With Iran deploying drones in Ukraine, brutally suppressing domestic unrest, and deepening ties with Moscow and Beijing, the EU faces mounting pressure to act more decisively. But real leverage is limited unless Brussels unites around stricter economic tools—like banking restrictions, energy-related sanctions, or tech export bans targeting surveillance and repression infrastructure.
READ THE STORY: DW
Inside Iran’s Internet Blackout: Starlink Smuggling, Digital Resistance, and a Test of Regime Control
Bottom Line Up Front (BLUF): Tehran has executed one of the most comprehensive and sophisticated internet blackouts in modern history, according to Financial Times reporting. Amid nationwide protests and regime violence, the Islamic Republic cut nearly all access to the global internet, including previously privileged “white SIM” users. While Iran’s National Information Network (NIN) was built to keep domestic systems running during such shutdowns, even core services briefly went offline. In response, a digital resistance—powered by smuggled Starlink terminals, covert software tools, and diaspora coordination—is helping Iranians pierce the regime’s communications blackout.
Analyst Comments: Iran’s move marks a shift from reactive censorship to full-spectrum, infrastructure-level control—with the ability to selectively restore “whitelisted” services while blocking all external communications. It also exposes a critical vulnerability: Iran’s single-point-of-failure architecture, deliberately designed to simplify kill-switch activation. Yet despite the technical chokehold, the regime is facing growing signal leakage from a determined network of exiled technologists, covert actors, and ordinary citizens leveraging off-grid satellite internet. Starlink access—legalized under 2022 U.S. sanctions exemptions—is now an ungoverned vector of communication, and Tehran is reportedly using military-grade jamming and aerial surveillance to detect and neutralize these uplinks.
READ THE STORY: FT
China Still Applying Military Pressure in Asia Despite US-China Diplomatic Stability
Bottom Line Up Front (BLUF): Despite a temporary thaw in diplomatic relations between the US and China, Beijing continues military pressure on Southeast Asian nations, particularly in disputed waters. US Indo-Pacific Commander Admiral Samuel Paparo warns that Chinese military actions remain aggressive, with increased PLA activity near the Philippines and Japan. The US is reaffirming its military commitments in the Indo-Pacific amid concerns over a shift in Trump’s strategic priorities.
Analyst Comments: While the Trump-Xi summit in October may have dialed down rhetorical hostilities, the PLA hasn’t paused its gray-zone tactics. The mismatch between high-level diplomacy and tactical aggression is by design. From harassing Philippine vessels near Scarborough Shoal to ramping up sorties around the Senkaku /Diaoyu Islands, China is pushing the envelope while the US refocuses on hemispheric priorities. The concern is that the administration’s shift toward “stability” risks diluting allied cohesion, especially when Japan signals it views a Taiwan contingency as existential. Former Pentagon official Ely Ratner put it bluntly: Washington may be getting played.
READ THE STORY: FT
Congressman Calls for Stronger U.S. Cyber Offense to Deter Global Adversaries
Bottom Line Up Front (BLUF): Rep. Andy Ogles (R-TN) is urging Congress to prioritize offensive cyber capabilities as a core pillar of U.S. national defense strategy. In a Washington Examiner op-ed, Ogles argues that deterrence through strength—especially in cyberspace—is critical to countering threats from China, Russia, Iran, and North Korea. He calls for increased funding, legal clarity, and doctrinal readiness to support preemptive and retaliatory cyber operations.
Analyst Comments: Cyberattacks on U.S. critical infrastructure, elections, and private industry have proven that adversaries view American digital restraint as exploitable. Ogles joins a growing chorus advocating for clearer rules of engagement and a more aggressive posture, particularly in response to state-sponsored APTs. There’s long been ambiguity around Title 10 vs. Title 50 authorities, cyber rules of engagement, and attribution thresholds. If the Hill moves to streamline offensive cyber authorization, expect friction among the DoD, NSA, and State, as diplomats worry about escalation or unintended consequences. But from a threat perspective—especially in light of Iranian cyber reprisals and Russian hybrid warfare—investing in scalable, persistent access operations (PAOs) and advanced capabilities like AI-driven intrusion sets is not just logical; it’s overdue.
READ THE STORY: Washington Examiner
Microsoft Patches Exploited Windows Zero-Day and 111 Other Vulnerabilities
Bottom Line Up Front (BLUF): Microsoft’s January 2026 Patch Tuesday update fixes 112 vulnerabilities, including one actively exploited zero-day (CVE-2024-21338) in the Windows Kernel that could allow privilege escalation. The update spans critical flaws across Windows, Office, Exchange Server, and Azure components. Threat actors are reportedly exploiting CVE-2024-21338 in the wild, making immediate patching a priority for enterprise environments.
Analyst Comments: The standout here is CVE-2024-21338, a Windows Kernel Elevation of Privilege (EoP) vulnerability with confirmed in-the-wild exploitation. While Microsoft has not released full details of the exploit, the flaw enables local privilege escalation—a common step in post-exploitation chains, particularly after initial access via phishing or malware. This batch is large, but not unusual. Notably, the volume of critical-rated vulnerabilities in network-facing components, including Exchange Server, remains high, making it a popular target for APTs and ransomware groups. Admins should prioritize kernel-level patches, Exchange, and any externally exposed systems.
READ THE STORY: SecurityWeek
Taipei Faces Escalating Cyber Pressure as Chinese Operations Intensify Ahead of Elections
Bottom Line Up Front (BLUF): Taiwan’s government is reporting a marked increase in cyberattacks and influence operations linked to China in the weeks leading up to its 2026 general elections. According to Taiwanese officials, the campaigns range from DDoS attacks and phishing to disinformation campaigns and data leaks—all designed to destabilize public trust, spread pro-Beijing narratives, and interfere with electoral processes.
Analyst Comments: Expect a mix of technical intrusions and cognitive warfare, with PLA-linked APT groups likely behind the more sophisticated intrusions and bot-driven propaganda. Of note: Taiwan’s Ministry of Digital Affairs flagged increased use of AI-generated deepfakes and synthetic media, adding a new layer of complexity to attribution and detection. If these operations undermine confidence in election integrity, expect China to amplify narratives about Taiwanese political instability to justify future actions. For defenders, this is a real-world testbed for hybrid threat response—and a preview of what U.S. and EU elections may face. Organizations with Taiwanese infrastructure or personnel should be on alert for spearphishing, supply chain tampering, and DNS manipulation.
READ THE STORY: DarkReading
n8n Supply Chain Attack Abuses npm Dependency to Deliver Malware
Bottom Line Up Front (BLUF): The workflow automation tool n8n was compromised in a supply chain attack targeting its npm package. Threat actors gained unauthorized access to the project’s npm account and published a malicious version that included a post-install script to exfiltrate system data and install additional payloads. The attack went undetected for several hours before being detected and remediated, affecting users who installed or updated n8n during that period.
Analyst Comments: The rogue package included a postinstall A script that executed code to download and run a remote binary, potentially granting attackers persistent access. The compromise was detected within hours, and n8n quickly revoked the credentials and published clean versions. GitHub and npm are investigating, and early telemetry shows limited but global exposure. Security teams are advised to audit systems for suspicious activity associated with recent n8n installations.
READ THE STORY: THN
Browser-in-the-Browser (BitB) Phishing Attacks Surge, Exploiting UI Trust Assumptions
Bottom Line Up Front (BLUF): Security researchers warn that the Browser-in-the-Browser (BitB) phishing technique is rapidly gaining traction among cybercriminals, enabling highly convincing spoofed login popups that mimic legitimate SSO and OAuth dialogs. The method leverages front-end frameworks to simulate browser windows within browser tabs, reducing user skepticism and defeating traditional phishing cues.
Analyst Comments: Attackers don’t need to compromise infrastructure or break TLS—they just exploit the UI layer and user trust. Targets see a realistic-looking login box for services like Microsoft 365, Google, or Okta—but it’s all HTML/CSS. This technique sidesteps URL verification (users don’t see the actual URL) and defeats many “look for the lock icon” training tips. While BitB phishing has been around since 2020, recent improvements in JavaScript libraries and social engineering tactics have pushed it into mainstream criminal use, particularly in credential-harvesting campaigns targeting enterprises.
READ THE STORY: Techzine
Root-Level Aruba VPN Flaw Goes Public: PoC Released for High-Severity VIA Vulnerability
Bottom Line Up Front (BLUF): A critical vulnerability in Aruba Networks’ VIA VPN client has been publicly disclosed, with proof-of-concept (PoC) exploit code now available. The flaw allows local privilege escalation to root on affected Linux systems. Tracked as CVE-2023-46455, the vulnerability poses a significant risk to enterprise environments using Aruba’s remote access solution.
Analyst Comments: The flaw, now weaponized via a public PoC, is trivial to exploit: an attacker with access to a system running VIA can escalate privileges by abusing how the software executes system commands. No kernel-level exploit required. While this isn’t a remote exploit, any foothold gained via phishing, USB drives, or browser-based attacks can be leveraged with this vulnerability. As the exploit requires only local access, defenders may downplay urgency—but they shouldn’t. APT groups and ransomware affiliates commonly combine privilege escalation flaws like this one with social engineering to gain domain-level control.
READ THE STORY: Daily Cyber Security
New ‘VoidLink’ Malware Targets Linux Servers with Rootkits and Custom Exfiltration Framework
Bottom Line Up Front (BLUF): Security researchers have uncovered VoidLink, a newly identified malware framework targeting Linux systems. Deployed by a likely state-aligned threat actor, VoidLink includes kernel-mode rootkits, evasive data theft tools, and custom backdoors designed for long-term persistence and stealthy exfiltration. The campaign appears to be focused on high-value targets in the telecom, cloud infrastructure, and government sectors across Asia and Europe.
Analyst Comments: The use of kernel rootkits for process hiding and the custom data exfiltration protocols suggest APT-level capabilities. Researchers note that VoidLink’s payloads avoid off-the-shelf C2 frameworks in favor of bespoke components, making detection and attribution harder. Notably, the malware evades common Linux EDR solutions by using direct syscalls and hiding from userland tools like ps or netstat. If your team is only looking for bash one-liners and crypto miners on Linux hosts, you’ll miss this entirely. Assume compromise if your Linux servers were exposed without eBPF monitoring or kernel module integrity checks.
READ THE STORY: THN
Google Moves Premium Pixel Phone Development to China and Vietnam, Raising Security Flags
Bottom Line Up Front (BLUF): Google is reportedly shifting parts of its Pixel smartphone development and manufacturing—including premium models—to China and Vietnam, according to internal sources cited by CyberNews. The move is aimed at optimizing costs and logistics but introduces new supply chain security concerns, particularly as U.S.–China tensions over tech sovereignty deepen.
Analyst Comments: While Vietnam is a common diversification target for U.S. tech firms, bringing premium device development—especially hardware prototyping and software integration—back into China would reverse the post-2019 Huawei-era decoupling. From a security standpoint, this raises red flags. Proximity to Chinese state-aligned subcontractors, shared facility use, and lack of full-stack oversight could expose devices to tampering at the firmware or SoC level. If Google is moving confidential development operations into jurisdictions with active state surveillance programs, that risk compounds. While there’s no public evidence of compromise, threat actors—both state and criminal—have previously exploited OEM supply chains. Think Supermicro, CCleaner, or the XCodeGhost incident. For enterprises adopting Pixel devices, the key question is the extent of end-to-end control Google retains over the build and testing environments.
READ THE STORY: CyberNews
Beijing Steel Exports and Iron Ore Imports Hit Record Highs Amid Global Supply Chain Shifts
Bottom Line Up Front (BLUF): China has set new records for both steel exports and iron ore imports, according to Baird Maritime. The surge reflects shifting global supply chains, recovering industrial demand, and strategic stockpiling amid geopolitical and economic uncertainty. Steel exports rose over 36% year-over-year, while iron ore imports hit their highest annual volume on record in 2025—signaling Beijing’s intent to maintain industrial dominance despite trade headwinds and growing international scrutiny.
Analyst Comments: Beijing appears to be hedging against future disruption—securing critical raw materials (like iron ore) while flooding export markets with price-competitive steel, potentially undermining Western and allied industrial bases. These moves could pressure global steel prices, complicate green steel transition goals in Europe, and weaken regional competitors’ margins. From a maritime and supply chain security perspective, this also reinforces China’s dependence on vulnerable seaborne raw material corridors—especially from Australia and Brazil—and may drive continued investment in port infrastructure, shipbuilding, and naval escort capabilities along key routes such as the Indian Ocean and South Pacific.
READ THE STORY: Baird Maritime
Items of interest
China’s Everbright Shipbuilding Resumes Operations Post-Restructuring
Bottom Line Up Front (BLUF): China’s Everbright Shipbuilding has resumed operations following a comprehensive restructuring, according to Baird Maritime. The state-linked yard, specializing in offshore support and maintenance vessels, had paused activities amid financial and operational headwinds. The relaunch signals renewed government backing and aligns with Beijing’s broader strategy to bolster maritime industrial capacity in support of both commercial and strategic objectives.
Analyst Comments: Everbright’s revival reflects China’s dual-use maritime strategy, where civilian shipyards can support military logistics, gray zone operations, and infrastructure for offshore claims enforcement. As tensions rise in the South and East China Seas, shipyards like Everbright will play a role beyond commercial builds—servicing maritime militia fleets, dual-use vessels, and expanding undersea and offshore ISR infrastructure. The restructuring also shows China’s willingness to prop up industrial assets deemed vital to long-term national security and power projection, particularly as global shipbuilding competition tightens and Western countries re-shore naval production.
READ THE STORY: Baird Maritime
How To Buy And Sell Ships In 2026? Frontline CEO Explains (Video)
FROM THE MEDIA: Frontline CEO Lars Barstad shares why John Fredriksen can order ships easily from shipyards, and how a company can defend buying and selling ships in 2026. We also cover why China is the best place to order VLCCs at the moment.
The Illicit Shipping Trade Hiding in Plain Sight (Video)
FROM THE MEDIA: An armada of vessels operating near Asia’s maritime thoroughfares moves hundreds of millions of barrels of sanctioned oil. Called the “dark fleet,” the ships also pose a risk of environmental catastrophe.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don't hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


