Researchers null-root over 550 Kimwolf and Aisuru botnet command servers

Lumen Technologies’ Black Lotus Labs team announced that it had been null-routing traffic to more than 550 command and control (C2) nodes associated with the AISURU/Kimwolf botnet since early October 2025. AISURU and its Android counterpart Kimwolf have recently emerged as one of the largest botnets, capable of forcing enslaved devices to participate in distributed […]
AI agents are becoming a privilege escalation path

AI agents have rapidly moved from experimental tools to core components of daily workflows across security, engineering, IT, and operations. What began as personal code assistants, chatbots, and co-pilots to help individuals improve their productivity have evolved into shared agents across the organization embedded in critical processes. These agents can coordinate workflows across multiple systems. […]
Hackers exploit sideloading of c-ares DLLs to bypass security and deploy malware

Security experts have detailed an active malware campaign that exploits a DLL sideloading vulnerability in legitimate binaries related to the open source c-ares library to bypass security controls and deliver a wide range of commodity Trojans and stealers. “The attacker achieves evasion by combining the malicious libcares-2.dll with a signed version of the legitimate ahost.exe […]
Fortinet fixes critical FortiSIEM flaw that allows unauthenticated remote code execution

January 14, 2026Ravi LakshmananVulnerability/patch management Fortinet has released an update that fixes a critical security flaw affecting FortiSIEM that could allow an unauthenticated attacker to execute code on a susceptible instance. The operating system (OS) injection vulnerability tracked as CVE-2025-64155 is rated 9.4 out of 10.0 on the CVSS scoring system. “Improper Disabling of Special […]
64% of third-party applications access sensitive data without legitimate reason

The study, which analyzed 4,700 major websites, found that 64% of third-party applications now access sensitive data without a legitimate business reason, up from 51% in 2024. Malicious activity in the government sector jumped from 2% to 12.9%, with 1 in 7 education sites showing active compromise. Specific violators: Google Tag Manager (8% of violations), […]
Microsoft fixes 114 Windows flaws in January 2026 patch, 1 of which is actively being exploited

Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability it announced was being actively exploited in the wild. Of the 114 deficiencies, 8 are rated as critical and 106 are rated as important. As many as 58 vulnerabilities were classified as privilege escalation, followed by 22 […]
Critical vulnerability in Node.js could cause server crash via async_hooks stack overflow

January 14, 2026Ravi LakshmananApplication security/vulnerabilities Node.js has released an update that fixes an issue described as a critical security issue that affects “virtually all production Node.js apps.” Exploitation of this issue could lead to a denial of service (DoS) condition. “Node.js/V8 makes a best-effort attempt to recover from stack space exhaustion due to catchable errors, […]
PLUGGYAPE malware uses Signal and WhatsApp to target Ukrainian Armed Forces

January 14, 2026Ravi LakshmananCyber espionage/threat intelligence The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed details of a new cyberattack targeting the Armed Forces between October and December 2025 with malware known as PLUGGYAPE. This activity is believed with medium confidence to be the work of a Russian hacker group tracked as Void Blizzard […]
Long-running web skimming campaign steals credit cards from online checkout pages

January 13, 2026Ravi Lakshmanan Web security/data theft Cybersecurity researchers have discovered a large-scale web skimming campaign that has been active since January 2022, targeting several major payment networks, including American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. “Enterprise organizations that are customers of these payment providers are likely to be most affected,” […]
Malicious Chrome extension steals MEXC API keys by pretending to be a trading tool

January 13, 2026Ravi LakshmananWeb security/online fraud Cybersecurity researchers have detailed a malicious Google Chrome extension that can steal API keys related to MEXC, a centralized cryptocurrency exchange (CEX) available in more than 170 countries, while masquerading as a tool to automate transactions on the platform. The extension is called MEXC API Automator (ID: pppdfgkfdemgfknfnhpkibbkabhghhfh), has […]