TikTok establishes joint venture in the U.S. to continue business pursuant to 2025 Executive Order

Ravi LakshmananJanuary 23, 2026Regulatory Compliance/National Security TikTok officially announced Friday that it has formed a joint venture that will allow the wildly popular video-sharing application to continue operating in the United States. The new venture, named TikTok USDS Joint Venture LLC, was established pursuant to an executive order signed by US President Donald Trump in […]

Phishing attack uses stolen credentials to install LogMeIn RMM for permanent access

Rabi LakshmananJanuary 23, 2026Email security/endpoint security Cybersecurity researchers have detailed a new dual-vector campaign that leverages stolen credentials to deploy legitimate remote monitoring and management (RMM) software to gain persistent remote access to compromised hosts. “Instead of deploying custom viruses, attackers are circumventing security boundaries by weaponizing necessary IT tools that administrators trust,” said Jeewan […]

Microsoft warns of multi-stage AitM phishing and BEC attacks targeting energy companies

Microsoft has warned of a multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) campaign targeting multiple organizations in the energy sector. “The campaign exploited the SharePoint file sharing service to deliver a phishing payload and relied on creating inbox rules to maintain persistence and avoid user awareness,” the Microsoft Defender Security Research Team said. […]

New Osiris ransomware emerges as a new variant that uses POORTRY drivers in BYOVD attacks

Cybersecurity researchers have revealed details of a new ransomware family called Osiris that targeted major food service franchise operators in Southeast Asia in November 2025. According to Symantec and the Carbon Black Threat Hunter Team, the attack used a malicious driver called POORTRY as part of a known technique known as BYOVD (Bring Your Own […]

Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories

Ravie LakshmananJan 22, 2026Cybersecurity / Hacking News Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them. What stands out is how little friction attackers now […]

Close the most common gaps in Google Workspace security

hacker newsJanuary 22, 2026Email security/SaaS security Security teams at agile, fast-growing companies are often tasked with the same mission: ensuring security without slowing down the business. Most teams inherit a technology stack that is optimized for exponential growth, not resilience. In these environments, the security team is a help desk, compliance expert, and incident response […]

Malicious PyPI package impersonates SymPy and deploys XMRig Miner to Linux hosts

Rabi LakshmananJanuary 22, 2026Cryptojacking/Malware A new malicious package discovered in the Python Package Index (PyPI) was found to impersonate a popular symbolic mathematics library and deploy a malicious payload, including a cryptocurrency miner, to Linux hosts. The package, named sympy-dev, mimics SymPy and copies SymPy’s project description exactly in an attempt to trick unsuspecting users […]

SmarterMail authentication bypass exploited 2 days after patch release

Rabi LakshmananJanuary 22, 2026Vulnerabilities / Email Security A new security flaw in SmarterTools SmarterMail email software is now being exploited in the wild two days after a patch was released. This vulnerability currently does not have a CVE identifier and is tracked by watchTowr Labs as WT-2026-0001. Patched by SmarterTools with build 9511 on January […]

Automated FortiGate attack exploits FortiCloud SSO to change firewall configuration

Ravi LakshmananJanuary 22, 2026Network security/vulnerabilities Cybersecurity firm Arctic Wolf warned of a “new cluster of automated malicious activity” involving unauthorized firewall configuration changes on Fortinet FortiGate devices. The group said the campaign began on January 15, 2026, adding that it bears similarities to a December 2025 campaign in which malicious SSO logins on FortiGate appliances […]