Researchers null-root over 550 Kimwolf and Aisuru botnet command servers

Lumen Technologies’ Black Lotus Labs team announced that it had been null-routing traffic to more than 550 command and control (C2) nodes associated with the AISURU/Kimwolf botnet since early October 2025. AISURU and its Android counterpart Kimwolf have recently emerged as one of the largest botnets, capable of forcing enslaved devices to participate in distributed […]

AI agents are becoming a privilege escalation path

AI agents have rapidly moved from experimental tools to core components of daily workflows across security, engineering, IT, and operations. What began as personal code assistants, chatbots, and co-pilots to help individuals improve their productivity have evolved into shared agents across the organization embedded in critical processes. These agents can coordinate workflows across multiple systems. […]

Hackers exploit sideloading of c-ares DLLs to bypass security and deploy malware

Security experts have detailed an active malware campaign that exploits a DLL sideloading vulnerability in legitimate binaries related to the open source c-ares library to bypass security controls and deliver a wide range of commodity Trojans and stealers. “The attacker achieves evasion by combining the malicious libcares-2.dll with a signed version of the legitimate ahost.exe […]

Fortinet fixes critical FortiSIEM flaw that allows unauthenticated remote code execution

January 14, 2026Ravi LakshmananVulnerability/patch management Fortinet has released an update that fixes a critical security flaw affecting FortiSIEM that could allow an unauthenticated attacker to execute code on a susceptible instance. The operating system (OS) injection vulnerability tracked as CVE-2025-64155 is rated 9.4 out of 10.0 on the CVSS scoring system. “Improper Disabling of Special […]

64% of third-party applications access sensitive data without legitimate reason

The study, which analyzed 4,700 major websites, found that 64% of third-party applications now access sensitive data without a legitimate business reason, up from 51% in 2024. Malicious activity in the government sector jumped from 2% to 12.9%, with 1 in 7 education sites showing active compromise. Specific violators: Google Tag Manager (8% of violations), […]

Critical vulnerability in Node.js could cause server crash via async_hooks stack overflow

January 14, 2026Ravi LakshmananApplication security/vulnerabilities Node.js has released an update that fixes an issue described as a critical security issue that affects “virtually all production Node.js apps.” Exploitation of this issue could lead to a denial of service (DoS) condition. “Node.js/V8 makes a best-effort attempt to recover from stack space exhaustion due to catchable errors, […]

PLUGGYAPE malware uses Signal and WhatsApp to target Ukrainian Armed Forces

January 14, 2026Ravi LakshmananCyber ​​espionage/threat intelligence The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed details of a new cyberattack targeting the Armed Forces between October and December 2025 with malware known as PLUGGYAPE. This activity is believed with medium confidence to be the work of a Russian hacker group tracked as Void Blizzard […]

Long-running web skimming campaign steals credit cards from online checkout pages

January 13, 2026Ravi Lakshmanan Web security/data theft Cybersecurity researchers have discovered a large-scale web skimming campaign that has been active since January 2022, targeting several major payment networks, including American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. “Enterprise organizations that are customers of these payment providers are likely to be most affected,” […]

Malicious Chrome extension steals MEXC API keys by pretending to be a trading tool

January 13, 2026Ravi LakshmananWeb security/online fraud Cybersecurity researchers have detailed a malicious Google Chrome extension that can steal API keys related to MEXC, a centralized cryptocurrency exchange (CEX) available in more than 170 countries, while masquerading as a tool to automate transactions on the platform. The extension is called MEXC API Automator (ID: pppdfgkfdemgfknfnhpkibbkabhghhfh), has […]