Iran-linked RedKitten cyber campaign targets human rights NGOs and activists

Farsi-speaking attackers aligned with Iran’s national interests are suspected of being behind a new campaign targeting non-governmental organizations and individuals involved in a recent record of human rights abuses. This activity, observed by HarfangLab in January 2026, is codenamed RedKitten. This is said to coincide with unrest that began across Iran towards the end of […]

Mandiant discovers ShinyHunters-style Vishing attack that steals MFA and compromises SaaS platforms

Ravi LakshmananJanuary 31, 2026Social Engineering/SaaS Security Mandiant, a Google company, said Friday that it has seen “expanded threat activity” using tradecraft consistent with extortion-themed attacks organized by a group of financially motivated hackers known as Shiny Hunters. This attack utilizes sophisticated voice phishing (also known as vishing) and a fake credential aggregator site that imitates […]

CERT Polska details coordinated cyberattacks on over 30 wind and solar farms

Ravi LakshmananJanuary 31, 2026Network security/SCADA CERT Polska, Poland’s computer emergency response team, has uncovered a coordinated cyberattack targeting more than 30 wind and solar power plants, private companies in the manufacturing industry, and large combined heat and power plants (CHPs) that provide heat to almost 500,000 customers in the country. This incident occurred on December […]

Researchers discover Chrome extension that exploits affiliate links to steal ChatGPT access

Cybersecurity researchers have discovered a malicious Google Chrome extension with the ability to hijack affiliate links, steal data, and collect OpenAI ChatGPT authentication tokens. One of the extensions in question is Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj), which claims to be a tool for browsing Amazon without sponsored content. It was uploaded to the Chrome Web […]

China-linked UAT-8099 targets IIS servers in Asia with BadIIS SEO malware

Cybersecurity researchers have discovered a new campaign attributed to a China-linked threat actor known as UAT-8099 that took place between late 2025 and early 2026. The activity, discovered by Cisco Talos, targeted vulnerable Internet Information Services (IIS) servers across Asia, with a particular focus on targets in Thailand and Vietnam. The scale of the campaign […]

Badges, Bytes and Intimidation January 30, 2026 Cybercrime / Threat Intelligence Behind the scenes of law enforcement in cyber: What do we know about the cybercriminals we have arrested? What brought them to us, where did they come from, and what role did they play at the crime scene? Introduction: One look at the decentralized fight against cybercrime The sophistication and diversification of cybercrime is forcing law enforcement agencies around the world to respond through increasingly coordinated and publicized actions. However, despite the visibility of these activities, to our knowledge, a comprehensive overview of how law enforcement agencies respond to cybercrime globally does not yet exist. Publicly available information includes agency, jurisdiction, and incident-specific reports (e.g. "operation endgame") [1] and reporting formats provide piecemeal insights rather than a coherent understanding of what types of crimes are being targeted, what actions are being taken, and who the offenders are. The result is isolated glimpses rather than a coherent picture. therefore…

Badges, Bytes and Intimidation January 30, 2026 Cybercrime / Threat Intelligence Behind the scenes of law enforcement in cyber: What do we know about the cybercriminals we have arrested? What brought them to us, where did they come from, and what role did they play at the crime scene? Introduction: One look at the decentralized […]

Former Google engineer found guilty of stealing 2,000 AI trade secrets from Chinese startup

Ravi LakshmananJanuary 30, 2026Artificial intelligence/economic espionage A former Google engineer accused of stealing thousands of confidential company documents to build a startup in China has been sentenced in the United States, the Department of Justice (DoJ) announced Thursday. Linwei Ding (also known as Leon Ding), 38, was convicted by a federal jury of seven counts […]

SmarterMail fixes critical uncertified RCE flaw in CVSS 9.3 scores

Ravi LakshmananJanuary 30, 2026Vulnerabilities / Email Security SmarterTools has addressed two additional security flaws in its SmarterMail email software. One of them is a critical security flaw that could lead to the execution of arbitrary code. This vulnerability is tracked as CVE-2026-24423 and has a CVSS score of 9.3 out of 10.0. According to the […]

Two Ivanti EPMM zero-day RCE flaws actively exploited, security update released

Ravi LakshmananJanuary 30, 2026Vulnerabilities / Enterprise Security Ivanti has released security updates to address two security flaws that affect Ivanti Endpoint Manager Mobile (EPMM) and were exploited in a zero-day attack. One of them was added to the Known Exploited Vulnerabilities (KEV) Catalog by the US Cybersecurity and Infrastructure Security Agency (CISA). The critical severity […]

Researchers discover 175,000 publicly available Ollama AI servers in 130 countries

A new joint study by SentinelOne SentinelLABS and Censys reveals that the deployment of open source artificial intelligence (AI) has created a vast “layer of unmanaged, publicly accessible AI computing infrastructure” spanning 175,000 unique Ollama hosts in 130 countries. The company says these systems span both cloud and residential networks around the world and operate […]