MuddyWater APT Weaponizing Word Documents to Deliver ‘RustyWater’ Toolkit Evading AV and EDR Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iran-linked MuddyWater Advanced Persistent Threat group has launched a sophisticated spear-phishing campaign targeting diplomatic, maritime, financial, and telecom sectors across the Middle East. The threat actors are using weaponized …

Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware campaign is using fake WinRAR download sites to deliver the dangerous Winzipper malware directly to unsuspecting users. The attack emerged from links distributed across various Chinese …

CISA Retires Ten Emergency Directives Following Milestone Achievement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) announced a significant milestone on January 8, 2026, by retiring ten Emergency Directives issued between 2019 and 2024. This marks the highest number …

CrowdStrike to Acquire Identity Security Startup SGNL in $740 Million Deal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike announced its agreement to acquire SGNL, a leading identity-first security company, for $740 million. The acquisition marks a significant strategic move to strengthen CrowdStrike’s Falcon Next-Gen Identity Security platform. …

Trend Micro Apex Central Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches to address three severe vulnerabilities affecting Apex Central (on-premise) that could allow remote attackers to execute malicious code or launch denial-of-service attacks on vulnerable systems. Trend Micro …

SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature …

Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise’s Ollama honeypot infrastructure captured …

New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese threat actors have developed a dangerous new way to steal money directly from bank accounts using specially crafted Android applications. Known as Ghost Tapped, these malicious apps exploit Near …

Cisco Small Business Switches Face Global DNS Crash Outage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network administrators worldwide reported widespread crashes in Cisco small business switches on January 8, 2026, triggered by fatal errors in the DNS client service. Devices entered reboot loops every few …