The hype you can ignore (and the risks you can’t ignore)

January 9, 2026hacker newsArtificial Intelligence/Enterprise Security As organizations plan for 2026, cybersecurity predictions are everywhere. However, many strategies are still shaped by headlines and speculation rather than evidence. The real challenge is not a lack of predictability. It’s about identifying which predictions reflect real emerging risks and which predictions can be safely ignored. Upcoming webinars […]
Trend Micro Apex Central RCE defect score is 9.8 CVSS for on-premises Windows version

January 9, 2026Ravi LakshmananVulnerabilities / Endpoint Security Trend Micro has released security updates to address multiple security vulnerabilities affecting the on-premises version of Apex Central for Windows. This contains a critical bug that could lead to arbitrary code execution. This vulnerability is tracked as CVE-2025-69258 and has a CVSS score of 9.8 out of a […]
CISA repeals 10 cybersecurity emergency directives issued from 2019 to 2024

January 9, 2026Ravi LakshmananGovernment/Vulnerability Management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Thursday that it is rescinding 10 Emergency Directives (Eds) issued between 2019 and 2024. Here is a list of directives that are currently considered closed: CISA said these directives were issued to protect federal civilian executive branch (FCEB) agencies from potential […]
FBI warns North Korean hackers are using malicious QR codes in spear phishing

January 9, 2026Ravi LakshmananMobile Security / Email Security The US Federal Bureau of Investigation (FBI) on Thursday issued an advisory warning that North Korean state-sponsored attackers are using malicious QR codes in spear-phishing campaigns targeting organizations in the country. “As of 2025, Kimsuky threat actors have embedded malicious Quick Response (QR) codes in spear-phishing campaigns […]
WhatsApp worm spreads Astaroth banking Trojan across Brazil via contact automated messaging

January 8, 2026Rabi LakshmananMalware/Financial Crime Cybersecurity researchers have revealed details of a new campaign that uses WhatsApp as a distribution vector for a Windows banking Trojan called Astaroth in an attack targeting Brazil. The campaign has been codenamed “Boto Cor-de-Rosa” by Acronis Threat Research Unit. “The malware obtains the victim’s WhatsApp contact list and automatically […]
Your Last Breath is Just the Beginning: Inside TwinH’s Vision for an Eternal Legacy

TIME has always been regarded as the ultimate thief. It erodes the sharpness of a shared joke, softens the sound of a father’s guidance, and eventually claims the presence of those we love most. For centuries, humanity has settled for static memories—dusty photo albums and silent home videos. But what if time finally met its […]
China-linked UAT-7290 targets telecom companies with Linux malware and ORB nodes

January 8, 2026Rabi LakshmananMalware/Threat Intelligence A China-affiliated threat actor known as UAT-7290 is believed to be conducting espionage-based infiltrations against organizations in South Asia and Southeast Europe. According to a Cisco Talos report published today, this activity cluster has been active since at least 2022 and primarily focuses on extensive technical reconnaissance of target organizations […]
RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories

Jan 08, 2026Ravie LakshmananCybersecurity / Hacking News The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep finding new ways to break in. Read on […]
The current state of trusted open source

Chainguard, the go-to source for open source, has a unique perspective on how modern organizations are actually using open source software and where they face risks and operational burdens. With a growing customer base and an extensive catalog of over 1,800 container image projects, 148,000 versions, 290,000 images, 100,000 language libraries, and nearly 500 million […]
Cisco patches ISE security vulnerability after releasing public PoC exploit

January 8, 2026Ravi LakshmananNetwork security/vulnerabilities Cisco has released updates that address medium-severity security flaws in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) using public proof-of-concept (PoC) exploits. This vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), exists in the licensing feature and could allow an authenticated, remote attacker with administrator privileges to access […]