The hype you can ignore (and the risks you can’t ignore)

January 9, 2026hacker newsArtificial Intelligence/Enterprise Security As organizations plan for 2026, cybersecurity predictions are everywhere. However, many strategies are still shaped by headlines and speculation rather than evidence. The real challenge is not a lack of predictability. It’s about identifying which predictions reflect real emerging risks and which predictions can be safely ignored. Upcoming webinars […]

Trend Micro Apex Central RCE defect score is 9.8 CVSS for on-premises Windows version

January 9, 2026Ravi LakshmananVulnerabilities / Endpoint Security Trend Micro has released security updates to address multiple security vulnerabilities affecting the on-premises version of Apex Central for Windows. This contains a critical bug that could lead to arbitrary code execution. This vulnerability is tracked as CVE-2025-69258 and has a CVSS score of 9.8 out of a […]

CISA repeals 10 cybersecurity emergency directives issued from 2019 to 2024

January 9, 2026Ravi LakshmananGovernment/Vulnerability Management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Thursday that it is rescinding 10 Emergency Directives (Eds) issued between 2019 and 2024. Here is a list of directives that are currently considered closed: CISA said these directives were issued to protect federal civilian executive branch (FCEB) agencies from potential […]

FBI warns North Korean hackers are using malicious QR codes in spear phishing

January 9, 2026Ravi LakshmananMobile Security / Email Security The US Federal Bureau of Investigation (FBI) on Thursday issued an advisory warning that North Korean state-sponsored attackers are using malicious QR codes in spear-phishing campaigns targeting organizations in the country. “As of 2025, Kimsuky threat actors have embedded malicious Quick Response (QR) codes in spear-phishing campaigns […]

WhatsApp worm spreads Astaroth banking Trojan across Brazil via contact automated messaging

January 8, 2026Rabi LakshmananMalware/Financial Crime Cybersecurity researchers have revealed details of a new campaign that uses WhatsApp as a distribution vector for a Windows banking Trojan called Astaroth in an attack targeting Brazil. The campaign has been codenamed “Boto Cor-de-Rosa” by Acronis Threat Research Unit. “The malware obtains the victim’s WhatsApp contact list and automatically […]

China-linked UAT-7290 targets telecom companies with Linux malware and ORB nodes

January 8, 2026Rabi LakshmananMalware/Threat Intelligence A China-affiliated threat actor known as UAT-7290 is believed to be conducting espionage-based infiltrations against organizations in South Asia and Southeast Europe. According to a Cisco Talos report published today, this activity cluster has been active since at least 2022 and primarily focuses on extensive technical reconnaissance of target organizations […]

RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories

Jan 08, 2026Ravie LakshmananCybersecurity / Hacking News The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep finding new ways to break in. Read on […]

The current state of trusted open source

Chainguard, the go-to source for open source, has a unique perspective on how modern organizations are actually using open source software and where they face risks and operational burdens. With a growing customer base and an extensive catalog of over 1,800 container image projects, 148,000 versions, 290,000 images, 100,000 language libraries, and nearly 500 million […]

Cisco patches ISE security vulnerability after releasing public PoC exploit

January 8, 2026Ravi LakshmananNetwork security/vulnerabilities Cisco has released updates that address medium-severity security flaws in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) using public proof-of-concept (PoC) exploits. This vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), exists in the licensing feature and could allow an authenticated, remote attacker with administrator privileges to access […]