Kimwolf Android botnet infects over 2 million devices via exposed ADB and proxy networks

January 5, 2026Ravi LakshmananIoT security/mobile security According to Synthient’s findings, the botnet known as Kimwolf infected more than 2 million Android devices by tunneling through residential proxy networks. “The primary actors involved in the Kimwolf botnet have been observed monetizing the botnet through app installations, selling residential proxy bandwidth, and selling DDoS capabilities,” the company […]
IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More

Jan 05, 2026Ravie LakshmananHacking News / Cybersecurity The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. Attacks moved quietly, reused familiar paths, and kept working longer than anyone wants to admit. This week’s […]
The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations

January 5, 2026hacker newsData protection/artificial intelligence Features: Cybersecurity is being reshaped by forces that go beyond individual threats and tools. As organizations operate across cloud infrastructure, distributed endpoints, and complex supply chains, security has moved from a collection of point solutions to a matter of architecture, reliability, and speed of execution. This report examines how […]
Ilya Lichtenstein, convicted of Bitfinex hacking, granted early release under US First Step Act

January 5, 2026Ravi LakshmananCryptocurrency/Financial Crime Ilya Lichtenstein, who was sentenced to prison last year on money laundering charges for his role in the massive hack of the virtual currency exchange Bitfinex in 2016, said he was released early. In a post shared on X last week, the 38-year-old announced his release by praising US President […]
New VVS Stealer malware targets Discord accounts via obfuscated Python code

January 5, 2026Ravi LakshmananThreat Intelligence / Windows Security Cybersecurity researchers have revealed details of a new Python-based information stealer called VVS Stealer (also known as VVS $tealer) that can collect Discord credentials and tokens. Palo Alto Networks Unit 42 reports that the thief was allegedly sold on Telegram in April 2025. “The VVS stealer code […]
Transparent Tribe launches new RAT attack against Indian government and academia

Threat actors known as Transparent Tribe are believed to have launched new attacks targeting government, academic, and strategic organizations in India using remote access Trojans (RATs) that allow them to take permanent control over compromised hosts. “The campaign uses deceptive delivery techniques, including weaponized Windows shortcut (LNK) files that disguise as legitimate PDF documents and […]
ROI issues in attack surface management

Attack Surface Management (ASM) tools promise to reduce risk. What they provide is usually more information. As security teams deploy ASM, their asset inventory increases, alerts start flowing, and dashboards fill up. There are visible activities and measurable outcomes. But when leaders ask a simple question, “Will this reduce incidents?” the answer is often unclear. […]
Cybercriminals exploit Google Cloud email capabilities in multi-step phishing campaign

January 2, 2026Ravi LakshmananCloud security/email security Cybersecurity researchers have detailed a phishing campaign in which attackers exploited Google Cloud’s application integration services to distribute emails that masqueraded as legitimate messages generated by Google. According to Check Point, this activity leverages the trust associated with Google Cloud infrastructure to send messages from a legitimate email address […]
GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories

Jan 01, 2026Ravie LakshmananCybersecurity / Hacking News The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defenders anything, it’s that threat actors don’t pause for holidays or resolutions. They just evolve faster. This week’s round-up shows how […]
RondoDox botnet exploits critical flaw in React2Shell to hijack IoT devices and web servers

January 1, 2026Ravi LakshmananNetwork security/vulnerabilities Cybersecurity researchers have revealed details of an ongoing nine-month campaign targeting Internet of Things (IoT) devices and web applications to enroll them in a botnet known as RondoDox. As of December 2025, CloudSEK has observed activity leveraging the recently revealed flaw in React2Shell (CVE-2025-55182, CVSS score: 10.0) as an initial […]