Researchers uncover service providers facilitating industrial-scale pig butchering scams

Cybersecurity researchers have highlighted two service providers that provide online criminal networks with the tools and infrastructure needed to facilitate the Pig Butchering as a Service (PBaaS) economy. Since at least 2016, Chinese-speaking criminal groups have set up industrial-scale fraud centers across Southeast Asia and created special economic zones specializing in fraudulent investment and identity […]

MuddyWater launches RustyWater RAT via spearphishing across Middle East sector

January 10, 2026Ravi LakshmananCyber ​​espionage/malware The Iranian threat actor known as MuddyWater is believed to have engaged in spear-phishing campaigns targeting diplomatic, maritime, financial, and communications institutions in the Middle East using a Rust-based implant known by the codename RustyWater. “The campaign uses icon spoofing and malicious Word documents to deliver a Rust-based implant capable […]

Europol arrests 34 Spanish Black Ax members for €5.9 million fraud and organized crime

January 10, 2026Ravi LakshmananCybercrime/Financial Crime Europol announced on Friday that it had arrested 34 people in Spain suspected of being members of the international criminal organization Black Ax. As part of an operation carried out by the Spanish National Police in collaboration with the Bavarian Criminal Police and Europol, 28 people were arrested in Seville, […]

China-linked hackers exploit VMware ESXi zero-day to escape virtual machines

January 9, 2026Ravi LakshmananVirtualization/Vulnerability Chinese-speaking attackers are suspected of using compromised SonicWall VPN appliances as an initial access vector to deploy a VMware ESXi exploit that may have been developed in February 2024. Cybersecurity firm Huntress, which observed the activity in December 2025 and stopped it before it could reach its final stage, said it […]

Russia’s APT28 runs credential theft campaign targeting energy and policy organizations

January 9, 2026Ravi LakshmananEmail Security/Threat Intelligence Russian state-sponsored threat actors have been implicated in a series of new credential harvesting attacks targeting individuals associated with Turkey’s Energy and Nuclear Research Institute, as well as staff affiliated with European think tanks and organizations in North Macedonia and Uzbekistan. This activity is believed to be by APT28 […]

The hype you can ignore (and the risks you can’t ignore)

January 9, 2026hacker newsArtificial Intelligence/Enterprise Security As organizations plan for 2026, cybersecurity predictions are everywhere. However, many strategies are still shaped by headlines and speculation rather than evidence. The real challenge is not a lack of predictability. It’s about identifying which predictions reflect real emerging risks and which predictions can be safely ignored. Upcoming webinars […]

Trend Micro Apex Central RCE defect score is 9.8 CVSS for on-premises Windows version

January 9, 2026Ravi LakshmananVulnerabilities / Endpoint Security Trend Micro has released security updates to address multiple security vulnerabilities affecting the on-premises version of Apex Central for Windows. This contains a critical bug that could lead to arbitrary code execution. This vulnerability is tracked as CVE-2025-69258 and has a CVSS score of 9.8 out of a […]

CISA repeals 10 cybersecurity emergency directives issued from 2019 to 2024

January 9, 2026Ravi LakshmananGovernment/Vulnerability Management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Thursday that it is rescinding 10 Emergency Directives (Eds) issued between 2019 and 2024. Here is a list of directives that are currently considered closed: CISA said these directives were issued to protect federal civilian executive branch (FCEB) agencies from potential […]

FBI warns North Korean hackers are using malicious QR codes in spear phishing

January 9, 2026Ravi LakshmananMobile Security / Email Security The US Federal Bureau of Investigation (FBI) on Thursday issued an advisory warning that North Korean state-sponsored attackers are using malicious QR codes in spear-phishing campaigns targeting organizations in the country. “As of 2025, Kimsuky threat actors have embedded malicious Quick Response (QR) codes in spear-phishing campaigns […]

WhatsApp worm spreads Astaroth banking Trojan across Brazil via contact automated messaging

January 8, 2026Rabi LakshmananMalware/Financial Crime Cybersecurity researchers have revealed details of a new campaign that uses WhatsApp as a distribution vector for a Windows banking Trojan called Astaroth in an attack targeting Brazil. The campaign has been codenamed “Boto Cor-de-Rosa” by Acronis Threat Research Unit. “The malware obtains the victim’s WhatsApp contact list and automatically […]