Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware campaign is using fake WinRAR download sites to deliver the dangerous Winzipper malware directly to unsuspecting users. The attack emerged from links distributed across various Chinese websites, targeting users who attempt to download the popular file …

CISA Retires Ten Emergency Directives Following Milestone Achievement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) announced a significant milestone on January 8, 2026, by retiring ten Emergency Directives issued between 2019 and 2024. This marks the highest number of Emergency Directives retired by the agency simultaneously, reflecting progress …

CrowdStrike to Acquire Identity Security Startup SGNL in $740 Million Deal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike announced its agreement to acquire SGNL, a leading identity-first security company, for $740 million. The acquisition marks a significant strategic move to strengthen CrowdStrike’s Falcon Next-Gen Identity Security platform. Address the growing complexity of protecting human, non-human, and AI …

Trend Micro Apex Central Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches to address three severe vulnerabilities affecting Apex Central (on-premise) that could allow remote attackers to execute malicious code or launch denial-of-service attacks on vulnerable systems. Trend Micro issued the patches on January 7, 2026, urging all affected …

SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature and potential impact on affected systems. SmarterTools describes SmarterMail as …

Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise’s Ollama honeypot infrastructure captured 91,403 attack sessions during this period, revealing two distinct threat …

New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese threat actors have developed a dangerous new way to steal money directly from bank accounts using specially crafted Android applications. Known as Ghost Tapped, these malicious apps exploit Near Field Communication (NFC) technology, the same wireless technology that powers …

Cisco Small Business Switches Face Global DNS Crash Outage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network administrators worldwide reported widespread crashes in Cisco small business switches on January 8, 2026, triggered by fatal errors in the DNS client service. Devices entered reboot loops every few minutes, disrupting operations until DNS configurations were removed.​ The issue …

What tools help reduce fraud or friendly fraud for online businesses? 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

That’s the part most online businesses learn the hard way: not all fraud is the same. In most cases, you’re dealing with two different threats:  Fraud: someone outside your business uses stolen card details, stolen login credentials, bots, or a …

UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous hacking group known as UAT-7290 has been actively attacking important telecommunications companies and critical infrastructure targets across South Asia since at least 2022. This advanced threat actor operates with clear signs of Chinese government connections and poses a …