Daily Drop (1237)
02-03-26
Tuesday, Feb 03, 2025 // (IG): BB // GITHUB // SN R&D
Palantir Stock Surges on AI-Fueled U.S. Government and Commercial Growth
Bottom Line Up Front (BLUF): Palantir reported a 56% revenue jump in 2025—driven largely by U.S. government contracts and a 137% increase in domestic commercial sales. The company projects a further 61% growth in 2026, fueled by rising demand for AI-powered data platforms. Its stock climbed as much as 9% after earnings, reversing a 16% YTD slide.
Analyst Comments: Palantir continues to embed itself deeper into the U.S. public sector and defense-industrial base. Its work with agencies like ICE and the Department of Defense, including a recent $10B Army contract and a $448M Navy deal, signals long-term entrenchment. However, the company remains controversial—especially in Europe, where uptake is lagging due to trust and sovereignty concerns. From a cybersecurity perspective, Palantir’s expansion in defense and surveillance applications raises the stakes for adversarial targeting, insider threats, and geopolitical backlash. The tighter the integration into sensitive systems, the bigger the surface—and consequences—of compromise.
READ THE STORY: FT
Trump and Modi Reach Trade Deal, Cut Indian Tariffs to 18%
Bottom Line Up Front (BLUF): President Donald Trump and Indian Prime Minister Narendra Modi have finalized a bilateral trade agreement reducing India’s average tariffs on U.S. goods to 18%. The deal aims to boost U.S. exports and deepen strategic economic ties, with key sectors like agriculture, tech, and pharmaceuticals expected to benefit.
Analyst Comments: The lowered tariff barrier is a win for U.S. exporters long frustrated by India’s protectionist policies, while India gains preferred access to advanced U.S. tech and defense components. The timing—amid global realignment around supply chains and semiconductor access—underscores a broader decoupling from China. For cybersecurity professionals, deeper U.S.-India tech collaboration could also expand joint initiatives in cyber defense, threat intelligence, and AI governance.
READ THE STORY: StraitsTimes
Iran’s Starlink Crackdown and Ukraine’s Drone War Signal New Frontiers in Digital Conflict
Bottom Line Up Front (BLUF): Iran’s recent crackdown on unauthorized Starlink terminals and Ukraine’s continued success in drone warfare highlight a critical shift in modern conflict: space-based internet and unmanned systems are now central to tactical and strategic operations. These developments mark a convergence of satellite connectivity, electronic warfare, and open-source tech in next-gen battlespaces.
Analyst Comments: Iranian authorities are confiscating Starlink terminals smuggled into the country, viewing them as tools for both foreign influence and internal dissent. Meanwhile, Ukraine has built one of the world’s most advanced drone warfare programs by leveraging commercial drones, open-source intelligence, and AI-driven software. Analysts say this blend of low-cost, high-impact tools—enabled by reliable satellite internet—demonstrates how nontraditional actors can level the playing field in modern warfare. The report warns that as drone and satellite technology proliferates, adversaries will increasingly seek to disrupt or exploit them.
READ THE STORY: Military.com
Germany Arrests Five in $30M Illegal Export Scheme Supporting Russian Arms Industry
Bottom Line Up Front (BLUF): German federal prosecutors have arrested five individuals accused of running a covert export network that sent over 16,000 shipments—worth more than $30 million—to Russia in violation of EU sanctions. The goods reportedly went to at least 24 Russian arms manufacturers, undermining restrictions imposed after the invasion of Ukraine.
Analyst Comments: Export circumvention like this directly fuels Russia’s defense production while publicly undermining Western sanctions policy. The use of shell companies, fake end-users, and front firms reflects the level of planning and state-linked facilitation likely involved. Germany’s move to arrest key players signals a shift toward more aggressive enforcement, but it also highlights how vulnerable Europe remains to internal exploitation. Expect broader crackdowns, especially as the EU moves on its 20th sanctions package.
READ THE STORY: The Washington Post
SCADA System Flaw Enables DoS Attacks on Industrial Automation Devices
Bottom Line Up Front (BLUF): A newly disclosed vulnerability in Schneider Electric's SCADA software could allow unauthenticated attackers to trigger denial-of-service (DoS) conditions on industrial control systems (ICS). The flaw affects the EcoStruxure Control Expert platform and is tracked as CVE-2023-29464 with a CVSS score of 7.5. Exploitation could disrupt critical infrastructure operations.
Analyst Comments: ICS and SCADA systems often prioritize uptime over security, which makes even a simple DoS vulnerability a significant operational risk. In environments like energy, water, or manufacturing, crashing a controller or engineering workstation—even temporarily—can halt production or endanger safety. The fact that this vulnerability can be triggered remotely and without authentication raises the risk level. While there’s no sign of exploitation in the wild yet, threat actors—including ransomware crews—are increasingly targeting OT environments. Patch if possible, but also isolate engineering systems and enforce strict network segmentation.
READ THE STORY: GBhackers
Coordinated Cyberattacks Target Solar Farms in Poland Amid Geopolitical Tensions
Bottom Line Up Front (BLUF): Multiple solar energy farms in Poland were hit by a series of coordinated cyberattacks in late 2023, disrupting operations and triggering broader concerns over energy sector resilience. The attacks appear to have been aimed at the remote management infrastructure of photovoltaic systems, with potential links to state-aligned threat actors.
Analyst Comments: Disrupting distributed energy assets like solar farms requires deep knowledge of industrial protocols, vendor ecosystems, and network architecture—this wasn’t opportunistic ransomware. As more renewable energy infrastructure comes online, it presents an increasingly attractive attack surface for geopolitical signaling and economic disruption. Defenders in the energy sector should take this seriously, especially in NATO-adjacent countries. Prioritize segmentation between IT and OT, harden remote access paths, and assume that even low-voltage assets like solar controllers can be high-value targets.
READ THE STORY: CSN
eScan Antivirus Update Servers Breached: Attackers Delivered Malware via Legitimate Channel
Bottom Line Up Front (BLUF): Attackers compromised the update infrastructure of eScan antivirus, pushing malicious payloads to users through legitimate software updates. The breach, first observed in May 2023, has been linked to an advanced threat actor using the foothold to deploy backdoors and stage follow-on intrusions, primarily targeting users in India.
Analyst Comments: While eScan may not be a dominant AV vendor globally, the implications are significant—users who trust an antivirus product were infected by it. The malware delivery began in May 2023, yet the breach wasn’t publicly confirmed until January 2024, raising concerns over detection gaps and response timelines. Defenders should review environments for signs of compromise related to eScan installations and inspect update logs and executables dating back to mid-2023.
READ THE STORY: GBhackers
Microsoft Notepad Update Mechanism Hijacked to Deploy Malware via Malicious Ads
Bottom Line Up Front (BLUF): Threat actors are abusing malicious ads and SEO poisoning to trick users into downloading a fake Microsoft Notepad update, which delivers malware instead of legitimate software. The campaign redirects victims to a spoofed site that installs the malware loader “FakeBat,” commonly used for initial access in ransomware operations.
Analyst Comments: Victims searching for “Notepad update” are redirected to a fake site that drops a malicious MSI installer embedded with FakeBat (also known as EugenLoader). Once installed, the loader can fetch second-stage payloads including ransomware or infostealers. This campaign is part of a broader trend of abusing trusted brand names and search platforms to deliver malware. Microsoft is not associated with the update or the campaign.
READ THE STORY: InfoSecMag
New APT Group “Punishing Owl” Targets Government and Telecom Networks in Asia
Bottom Line Up Front (BLUF): A newly identified advanced persistent threat (APT) group dubbed Punishing Owl has been observed targeting government, telecommunications, and critical infrastructure networks in multiple Asian countries. The group uses custom malware and living-off-the-land techniques to maintain long-term persistence and evade detection.
Analyst Comments: Punishing Owl has conducted stealthy intrusions into multiple high-value networks in Asia, using custom loaders and modular payloads to establish persistence. The group heavily leverages legitimate system tools (LOLBins), minimizing their malware footprint. Their infrastructure overlaps with older, unattributed espionage campaigns, and early indicators suggest links to a larger threat ecosystem active in the region. The report emphasizes that detection is difficult due to the group’s low-and-slow tactics and recommends behavioral monitoring and network anomaly detection over signature-based defenses.
READ THE STORY: CSN
Russian Hacker Claims Breach of Iranian Aviation Authority and Air Traffic Systems
Bottom Line Up Front (BLUF): A hacker operating under the alias “ColdRiver” has claimed responsibility for breaching Iran’s Civil Aviation Organization (CAO), leaking documents, emails, and internal systems data. The attacker also alleges access to Iranian air traffic control systems, raising concerns about the integrity of critical infrastructure. Iranian authorities have not confirmed the extent of the intrusion.
Analyst Comments: A Russian-linked actor hitting Iranian infrastructure suggests either rogue activity, false-flag signaling, or a break in quiet cooperation between the two countries. ColdRiver is no script kiddie; they’ve previously targeted Western nuclear entities and government bodies. The leak includes flight records, internal correspondence, and alleged access to air traffic controls, which—if verified—would be a major embarrassment for Tehran. For defenders, this reinforces the risk of aviation sector targeting and the value such intrusions hold for both espionage and disruption.
READ THE STORY: GBhackers
GlassWorm Malware Targets Eclipse Open VSX Registry in Software Supply Chain Attack
Bottom Line Up Front (BLUF): A sophisticated supply chain attack leveraging GlassWorm malware has compromised the Eclipse Open VSX Registry, a popular repository for Visual Studio Code extensions used in enterprise and developer environments. Attackers uploaded malicious extensions that, once installed, executed multi-stage payloads aimed at data exfiltration and persistent access.
Analyst Comments: The Open VSX Registry feeds directly into CI/CD pipelines and developer environments—prime targets for attackers looking to pivot into internal systems. The use of GlassWorm, a relatively new malware family, suggests a well-resourced actor with a focus on stealth and long-term access. As with past registry hijacks (e.g., PyPI, npm), this shows that attacker tradecraft is evolving to blend into trusted developer workflows. Enterprises should immediately audit extension usage, especially in air-gapped or sensitive dev environments, and consider freezing or mirroring known-good packages.
READ THE STORY: SCMEDIA
Hackers Wipe MongoDB Instances in Ransomware Extortion Campaign
Bottom Line Up Front (BLUF): Threat actors are mass-scanning for internet-exposed MongoDB databases and wiping them, leaving behind ransom notes demanding payment for data recovery. The campaign is automated, fast, and opportunistic—exploiting weak authentication or unsecured instances left open to the public. Over 23,000 affected databases have been identified so far.
Analyst Comments: MongoDB ransom wiping attacks have been around since at least 2017, but attackers are now accelerating their scans and targeting cloud-hosted instances at scale. Most victims aren’t even targeted specifically—they just show up in Shodan with no password. If your team is running MongoDB in the cloud or for dev environments, verify authentication is enforced and that the instance isn’t listening on 0.0.0.0 without proper firewalling. These attacks offer no real recovery path—the data is usually gone. Treat it as a burn notice.
READ THE STORY: GBhackers
APT28 Exploits Microsoft Office Zero-Day (CVE-2026-21724) in Targeted Espionage Campaigns
Bottom Line Up Front (BLUF): APT28—Russia’s GRU-linked threat actor—is actively exploiting a zero-day vulnerability in Microsoft Office (CVE-2026-21724) to deliver malware via malicious Word documents. The flaw allows for remote code execution upon opening or previewing a weaponized file. Microsoft has acknowledged the vulnerability but has not yet released a patch.
Analyst Comments: CVE-2026-21724 enables code execution through a malformed Word document, and the fact that it triggers on preview makes this especially dangerous in Outlook-based attacks. This isn’t scattershot phishing—targets appear to be diplomatic entities and military-linked organizations across Europe. Until Microsoft releases a fix, orgs should disable preview panes, use attack surface reduction (ASR) rules, and sandbox untrusted attachments. Expect this to be folded into broader GRU-linked campaigns if left unpatched for long.
READ THE STORY: THN
DynoWiper Malware Targets Iran: Data-Wiping Attacks Disrupt Systems Amid Regional Tensions
Bottom Line Up Front (BLUF): A destructive malware dubbed DynoWiper has been deployed against organizations in Iran, targeting Windows systems and erasing data to render devices inoperable. The wiper appears to be part of a politically motivated campaign, discovered during escalating regional tensions in early 2024. Victims include entities in the energy and industrial sectors.
Analyst Comments: DynoWiper was identified by researchers at ESET targeting organizations in Iran. It doesn’t encrypt data for ransom; it erases it outright. The malware disables recovery options, deletes shadow copies, and wipes key system directories, making recovery virtually impossible. It’s designed to destroy, not extort. Wipers like this often accompany geopolitical flare-ups, and attribution tends to get murky fast. While there's no confirmed link yet, the timing suggests a state-aligned actor. Defenders in the region—and anyone with exposure to Iranian networks—should review endpoint telemetry for early indicators and ensure offline backups are maintained.
READ THE STORY: CSN
Zero-Day in Microsoft Office Exploited in the Wild via RTF Files
Bottom Line Up Front (BLUF): A newly discovered zero-day vulnerability in Microsoft Office is being actively exploited through malicious RTF documents. Attackers can trigger code execution simply by getting a target to preview a booby-trapped file in Outlook, without requiring any user interaction. The flaw affects multiple Office versions and has no official patch at the time of reporting.
Analyst Comments: The exploit can be delivered via email, with the payload executing upon preview in Outlook—even without opening the attachment. While Microsoft has acknowledged the issue and assigned it a CVE, no fix is yet available. Advanced persistent threat (APT) groups are reportedly already leveraging this flaw in live operations. Suggested mitigations include using Microsoft’s attack surface reduction (ASR) rules and blocking RTF file rendering.
READ THE STORY: GBhackers
Google Chrome Update Patches Actively Exploited Zero-Day (CVE-2024-0519)
Bottom Line Up Front (BLUF): Google has released an emergency security update for Chrome to fix a critical zero-day vulnerability tracked as CVE-2024-0519. The flaw, a high-severity out-of-bounds memory access in Chrome’s V8 JavaScript engine, is being actively exploited in the wild. Users are strongly urged to update immediately.
Analyst Comments: Exploiting memory issues in V8 is a tried-and-true method for achieving code execution or sandbox escapes, and the fact that Google confirmed in-the-wild exploitation means someone is already using this in targeted attacks. Expect state-backed actors and exploit brokers to integrate this into toolkits quickly. Enterprises should push version 120.0.6099.224/.225 (Windows) or 120.0.6099.234 (Mac/Linux) ASAP and validate that auto-updates are functioning across managed endpoints.
READ THE STORY: GBhackers
Items of interest
Ivanti EPMM Hit with Two Pre-Auth RCE Vulnerabilities Exploited in the Wild (CVE-2026-1281 & CVE-2026-1340)
Bottom Line Up Front (BLUF): WatchTowr Labs disclosed two new pre-authentication remote code execution (RCE) vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340. Both flaws are actively exploited in the wild and stem from classic Bash injection techniques. Attackers can gain unauthenticated shell access to vulnerable appliances exposed to the internet.
Analyst Comments: This pair of RCEs amounts to another critical blow to EPMM customers, especially given that both vulnerabilities are trivial to exploit and don’t require credentials. Worse, active exploitation has been confirmed before public disclosure, suggesting either private exploitation or leaks from coordinated disclosure processes. If your EPMM instance is exposed to the internet and unpatched, you’re already late. Prioritize isolation and forensic review.
READ THE STORY: Watchtowr
Chaining Vulnerabilities Like a Pro Bug Bounty Hunter (Video)
FROM THE MEDIA: Whether you're a beginner or an experienced bug hunter, this video will give you valuable insights and techniques to elevate your hacking game. Don't miss out—your next big find could be just one chain away.
Sina Kheirkhah - Unveiling the Ivanti vulnerability: from discovery to exploitation (Video)
FROM THE MEDIA: Unveiling the Ivanti vulnerability: from discovery to exploitation
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don't hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


