“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Securing the Mid-Market Across the Complete Threat Lifecycle [email protected] (The Hacker News)
For mid-market organizations, cybersecurity is a constant balancing act. Proactive, preventative security measures are essential to protect an expanding attack surface. Combined with effective protection that blocks threats, they play a critical role in stopping cyberattacks before damage is done. The challenge is that many security tools add complexity and cost that most mid-market businessesRead…
-

Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users [email protected] (The Hacker News)
The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility’s update mechanism to redirect update traffic to malicious servers instead. “The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” developer Don Ho said. “The compromise occurred at the hostingRead More
-

eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware [email protected] (The Hacker News)
The update infrastructure for eScan antivirus, a security solution developed by Indian cybersecurity company MicroWorld Technologies, has been compromised by unknown attackers to deliver a persistent downloader to enterprise and consumer systems. “Malicious updates were distributed through eScan’s legitimate update infrastructure, resulting in the deployment of multi-stage malware to enterpriseRead More
-

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a supply chain attack targeting the Open VSX Registry in which unidentified threat actors compromised a legitimate developer’s resources to push malicious updates to downstream users. “On January 30, 2026, four established Open VSX extensions published by the oorzc author had malicious versions published to Open VSX that embed…
-

Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists [email protected] (The Hacker News)
A Farsi-speaking threat actor aligned with Iranian state interests is suspected to be behind a new campaign targeting non-governmental organizations and individuals involved in documenting recent human rights abuses. The activity, observed by HarfangLab in January 2026, has been codenamed RedKitten. It’s said to coincide with the nationwide unrest in Iran that began towards the…
-

Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms [email protected] (The Hacker News)
Google-owned Mandiant on Friday said it identified an “expansion in threat activity” that uses tradecraft consistent with extortion-themed attacks orchestrated by a financially motivated hacking group known as ShinyHunters. The attacks leverage advanced voice phishing (aka vishing) and bogus credential harvesting sites mimicking targeted companies to gain unauthorized access to victimRead More
-

CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms [email protected] (The Hacker News)
CERT Polska, the Polish computer emergency response team, revealed that coordinated cyber attacks targeted more than 30 wind and photovoltaic farms, a private company from the manufacturing sector, and a large combined heat and power plant (CHP) supplying heat to almost half a million customers in the country. The incident took place on December 29,…
-
Quantifying cyber risk at Netflix, Highmark Health: Case studies
Show me the money: In these case studies, learn how the FAIR model helped a nonprofit healthcare company and a streaming giant quantify cyber risk in financial terms.Read More
-
News brief: Patch critical and high-severity vulnerabilities now
Check out the latest security news from the Informa TechTarget team.Read More
-
5 deepfake detection tools to protect enterprise users
Deepfakes are wreaking havoc worldwide — and they’re likely just getting started. To fight fire with fire, CISOs should consider AI-enabled deepfake detection tools.Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
