Browsing: Security

Microsoft’s January 2026 Patch Tuesday addresses 113 security flaws, including eight critical vulnerabilities and an actively exploited zero-day (CVE-2026-20805) in Desktop Window Manager. The update also removes legacy modem drivers due to known exploits and highlights a critical Secure Boot bypass (CVE-2026-21265) linked to expiring certificates. Additionally, browser updates for Firefox, Chrome, and Edge are noted.

The destructive Kimwolf botnet has infected millions of unofficial Android TV streaming boxes, forcing them into DDoS attacks and residential proxy services. This article delves into the digital footprints left by the operators and beneficiaries, including Resi Rack, Plainproxies, and Maskify, and highlights the interconnected web of cybercriminal activity surrounding Kimwolf and its predecessor, Aisuru.

Scattered Lapsus ShinyHunters (SLSH) employs aggressive extortion tactics, including harassment and threats against executives and their families. Despite some victims reportedly paying, experts warn that engaging with this unreliable group beyond a refusal to pay only escalates the harassment, as their history suggests they often do not uphold their promises.

A large-scale Android malware campaign is reportedly exploiting Hugging Face’s public hosting infrastructure to distribute a remote access trojan (RAT). This operation uses social engineering and staged payload delivery, with attackers generating thousands of unique Android package variants to bypass detection, according to Bitdefender Labs.