Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Between December 25–28, a single threat actor conducted a large-scale scanning campaign, testing over 240 different exploits against internet-facing systems and collecting data on every vulnerable target found. This reconnaissance …

Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cyber threat environment across Australia and New Zealand has entered a critical phase throughout 2025, with threat actors orchestrating increasingly sophisticated attacks centered on the sale of compromised network …

Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and sophisticated phishing campaign is targeting remote workers and IT administrators by impersonating the official Fortinet VPN download portal. This attack is particularly dangerous because it leverages search …

MuddyWater APT Weaponizing Word Documents to Deliver ‘RustyWater’ Toolkit Evading AV and EDR Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iran-linked MuddyWater Advanced Persistent Threat group has launched a sophisticated spear-phishing campaign targeting diplomatic, maritime, financial, and telecom sectors across the Middle East. The threat actors are using weaponized …

Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware campaign is using fake WinRAR download sites to deliver the dangerous Winzipper malware directly to unsuspecting users. The attack emerged from links distributed across various Chinese …

CISA Retires Ten Emergency Directives Following Milestone Achievement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) announced a significant milestone on January 8, 2026, by retiring ten Emergency Directives issued between 2019 and 2024. This marks the highest number …

CrowdStrike to Acquire Identity Security Startup SGNL in $740 Million Deal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike announced its agreement to acquire SGNL, a leading identity-first security company, for $740 million. The acquisition marks a significant strategic move to strengthen CrowdStrike’s Falcon Next-Gen Identity Security platform. …

Trend Micro Apex Central Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches to address three severe vulnerabilities affecting Apex Central (on-premise) that could allow remote attackers to execute malicious code or launch denial-of-service attacks on vulnerable systems. Trend Micro …

SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature …

Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise’s Ollama honeypot infrastructure captured …