Category: Uncategorized
-

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors [email protected] (The Hacker News)
The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting diplomatic, maritime, financial, and telecom entities in the Middle East with a Rust-based implant codenamed RustyWater. “The campaign uses icon spoofing and malicious Word documents to deliver Rust based implants capable of asynchronous C2, anti-analysis, registry persistence, and modularRead More
-

Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime [email protected] (The Hacker News)
Europol on Friday announced the arrest of 34 individuals in Spain who are alleged to be part of an international criminal organization called Black Axe. As part of an operation conducted by the Spanish National Police, in coordination with the Bavarian State Criminal Police Office and Europol, 28 arrests were made in Seville, along with…
-

China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines [email protected] (The Hacker News)
Chinese-speaking threat actors are suspected to have leveraged a compromised SonicWall VPN appliance as an initial access vector to deploy a VMware ESXi exploit that may have been developed as far back as February 2024. Cybersecurity firm Huntress, which observed the activity in December 2025 and stopped it before it could progress to the final…
-
How to create an incident response playbook
Learn how to build actionable, repeatable incident response playbooks that guide your team through every step of handling cybersecurity events effectively.Read More
-

Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations [email protected] (The Hacker News)
Russian state-sponsored threat actors have been linked to a fresh set of credential harvesting attacks targeting individuals associated with a Turkish energy and nuclear research agency, as well as staff affiliated with a European think tank and organizations in North Macedonia and Uzbekistan. The activity has been attributed to APT28 (aka BlueDelta), which was attributed…
-
News brief: AI threats to shape 2026 cybersecurity
Check out the latest security news from the Informa TechTarget team.Read More
-

Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t) [email protected] (The Hacker News)
As organizations plan for 2026, cybersecurity predictions are everywhere. Yet many strategies are still shaped by headlines and speculation rather than evidence. The real challenge isn’t a lack of forecasts—it’s identifying which predictions reflect real, emerging risks and which can safely be ignored. An upcoming webinar hosted by Bitdefender aims to cut through the noise…
-

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions [email protected] (The Hacker News)
Trend Micro has released security updates to address multiple security vulnerabilities impacting on-premise versions of Apex Central for Windows, including a critical bug that could result in arbitrary code execution. The vulnerability, tracked as CVE-2025-69258, carries a CVSS score of 9.8 out of a maximum of 10.0. The vulnerability has been described as a case…
-

CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024 [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday said it’s retiring 10 emergency directives (Eds) that were issued between 2019 and 2024. The list of the directives now considered closed is as follows – ED 19-01: Mitigate DNS Infrastructure Tampering ED 20-02: Mitigate Windows Vulnerabilities from January 2020 Patch Tuesday ED 20-03: Mitigate…
-

FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing [email protected] (The Hacker News)
The U.S. Federal Bureau of Investigation (FBI) on Thursday released an advisory warning of North Korean state-sponsored threat actors leveraging malicious QR codes in spear-phishing campaigns targeting entities in the country. “As of 2025, Kimsuky actors have targeted think tanks, academic institutions, and both U.S. and foreign government entities with embedded malicious Quick Response (QR)Read…
