“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts [email protected] (The Hacker News)
A new malicious package discovered in the Python Package Index (PyPI) has been found to impersonate a popular library for symbolic mathematics to deploy malicious payloads, including a cryptocurrency miner, on Linux hosts. The package, named sympy-dev, mimics SymPy, replicating the latter’s project description verbatim in an attempt to deceive unsuspecting users into thinking that…
-

SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release [email protected] (The Hacker News)
A new security flaw in SmarterTools SmarterMail email software has come under active exploitation in the wild, two days after the release of a patch. The vulnerability, which currently does not have a CVE identifier, is tracked by watchTowr Labs as WT-2026-0001. It was patched by SmarterTools on January 15, 2026, with Build 9511, following…
-
18 enterprise email security best practices for 2026
Safeguard your organization. Train employees to avoid password reuse, spot phishing attempts and encrypt messages, among other email security best practices.Read More
-

Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations [email protected] (The Hacker News)
Cybersecurity company Arctic Wolf has warned of a “new cluster of automated malicious activity” that involves unauthorized firewall configuration changes on Fortinet FortiGate devices. The activity, it said, commenced on January 15, 2026, adding it shares similarities with a December 2025 campaign in which malicious SSO logins on FortiGate appliances were recorded against the admin…
-

Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex [email protected] (The Hacker News)
Cisco has released fresh patches to address what it described as a “critical” security vulnerability impacting multiple Unified Communications (CM) products and Webex Calling Dedicated Instance that it has been actively exploited as a zero-day in the wild. The vulnerability, CVE-2026-20045 (CVSS score: 8.2), could permit an unauthenticated remote attacker to execute arbitrary commands on…
-
Top 8 cybersecurity predictions for 2026
AI will further reshape cybersecurity in 2026, predict CISOs. From agentic AI defensive toolchains to MCP server risks, explore the anticipated shifts.Read More
-

North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews [email protected] (The Hacker News)
As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming 20 potential victim organizations spanning artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development sectors in Europe, South Asia, the Middle East, and Central America. The new findingsRead More
-

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws [email protected] (The Hacker News)
Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in denial-of-service (DoS) and remote code execution. The most severe of the lot is a critical security flaw impacting Zoom Node Multimedia Routers (MMRs) that could permit a meeting participant to conduct remote code execution attacks. The vulnerability,…
-

Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff [email protected] (The Hacker News)
Every managed security provider is chasing the same problem in 2026 — too many alerts, too few analysts, and clients demanding “CISO-level protection” at SMB budgets. The truth? Most MSSPs are running harder, not smarter. And it’s breaking their margins. That’s where the quiet revolution is happening: AI isn’t just writing reports or surfacing risks…
-

Exposure Assessment Platforms Signal a Shift in Focus [email protected] (The Hacker News)
Gartner® doesn’t create new categories lightly. Generally speaking, a new acronym only emerges when the industry’s collective “to-do list” has become mathematically impossible to complete. And so it seems that the introduction of the Exposure Assessment Platforms (EAP) category is a formal admission that traditional Vulnerability Management (VM) is no longer a viable way to…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
