MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: CTIX FLASH Update – January 20, 2026
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$66,841.00-0.14%
  • ethereumEthereum(ETH)$2,053.22-0.73%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.32-0.13%
  • binancecoinBNB(BNB)$588.790.86%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$80.211.28%
  • tronTRON(TRX)$0.314723-0.09%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.23%
  • dogecoinDogecoin(DOGE)$0.0919821.54%
Smart Contracts

CTIX FLASH Update – January 20, 2026

Last updated: January 21, 2026 4:15 pm
Published: 2 months ago
Share

Find out more about Lexology or get in touch by visiting our About page.

Cloud and AI Security Threats Highlight the Need for Vigilance

Recent security research has revealed new threats targeting cloud systems and AI tools. The discovery of VoidLink, a sophisticated Linux malware framework, shows how cybercriminals are developing advanced tools to covertly control cloud environments like AWS, Azure, and Google Cloud. This malware is modular, stealthy, and capable of stealing credentials. Moving laterally, hiding its presence using rootkits and anti-debugging techniques. Although not yet observed in active attacks, experts warn it could be used for long-term espionage or commercial cyber operations. Separately, researchers uncovered a method called Reprompt that tricks Microsoft’s AI assistant, Copilot, into revealing sensitive user data through malicious links. While Microsoft has since fixed this flaw, these incidents highlight the increasing sophistication of cyber threats targeting critical digital infrastructure, emphasizing the importance of proactive security measures to safeguard cloud and AI environments from covert and persistent attacks. CTIX analysts will continue to report on the latest malware strains and attack methodologies.

Threat Actor Activity

DeadLock Ransomware Group Using Blockchain Smart Contracts to Evade Detection

The DeadLock ransomware group, identified in July 2025, employs blockchain-based methods to evade detection, distinguishing it from typical ransomware operations. Unlike the common double extortion approach, DeadLock does not have a data leak site to threaten victims with public exposure. Instead, it claims to sell stolen data on underground markets if ransoms aren’t paid, a tactic some experts consider dubious. The group’s notable innovation is using Polygon smart contracts to obscure its command-and-control (C2) infrastructure. This method allows frequent rotation of proxy server URLs, making it challenging for defenders to block the infrastructure permanently. After encrypting a victim’s systems, DeadLock provides an HTML file as a wrapper for the decentralized messenger Session, guiding victims to communicate via this platform. This technique of using smart contracts is gaining traction, with North Korean state-sponsored attackers employing similar methods, described as “EtherHiding,” to conceal malware, according to Google’s Threat Intelligence Group (GTIG). These methods represent a new evolution in cybercriminal tradecraft, offering a kind of bulletproof hosting. While DeadLock’s smart contract usage is well-documented, details about its initial access methods remain unclear. However, it is suspected to use techniques like bring your own vulnerable driver (BYOVD) and exploiting vulnerabilities to disable endpoint detection and response (EDR) systems, as noted by Cisco Talos.

Vulnerabilities

Palo Alto Networks Patches Vulnerability as GlobalProtect Exposure and Scanning Activity Persist

Palo Alto Networks has released security updates for a high-severity denial-of-service (DoS) vulnerability, CVE-2026-0227 (CVSS 7.7/10), affecting PAN-OS firewalls and Prisma Access deployments when a GlobalProtect gateway or portal is enabled, stemming from an improper check for exceptional conditions (CWE-754) that allows unauthenticated attackers to repeatedly trigger maintenance mode and disrupt firewall protections. The company confirmed a proof-of-concept exploit exists but reported no evidence of in-the-wild exploitation to date, noting that Cloud NGFW is not impacted and that there are no viable workarounds beyond patching. Most cloud-hosted Prisma Access instances have already been upgraded, with remaining customers scheduled through standard maintenance windows, while on-premises administrators are urged to update across affected PAN-OS branches. Risk remains elevated given sustained reconnaissance and attack interest in GlobalProtect infrastructure. Shadowserver tracks nearly 6,000 Palo Alto Networks firewalls exposed online, and GreyNoise has recently warned of large-scale automated activity targeting GlobalProtect portals. Set against a backdrop of multiple PAN-OS zero-day and DoS incidents in recent years, CTIX analysts emphasize immediate patching to mitigate disruption risks to widely deployed environments across government, service providers, and large enterprises.

Read more on Lexology

This news is powered by Lexology Lexology

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

AG META Ushers in the Next Generation of Wealth Security Through RWA Integration
From Centralized to Web3: Best Decentralized Crypto Casinos in 2026 | Headlines | News | CoinMarketCap
AlphaPepe Crosses 6,300 Holders as New AlphaGems System Expands Ecosystem Utility
Trusted Smart Chain Completes CertiK Audit, Advancing Secure RWA Tokenization
Vitalik Buterin Discusses Ethereum AI Integration as SUBBD Token Targets Creators

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Bitcoin dips below $88K to fill New Year CME gap
Next Article How Blockchain-Based Casinos Are Reshaping Online Gambling Transparency
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d