Hijacked Mobility: CISA Warns of Critical 9.8 Flaw Allowing Remote Control of WHILL Power Chairs
https://securityonline.info/hijacked-mobility-cisa-warns-of-critical-9-8-flaw-allowing-remote-control-of-whill-power-chairs/
https://securityonline.info/hijacked-mobility-cisa-warns-of-critical-9-8-flaw-allowing-remote-control-of-whill-power-chairs/
Daily CyberSecurity
Hijacked Mobility: CISA Warns of Critical 9.8 Flaw Allowing Remote Control of WHILL Power Chairs
CISA issues a 9.8 severity alert for WHILL wheelchairs! CVE-2025-14346 lets attackers hijack controls via Bluetooth. Update your firmware now.
The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
https://securityonline.info/the-ghost-in-the-kernel-how-honeymyte-weaponized-a-rootkit-to-hijack-asian-governments/
https://securityonline.info/the-ghost-in-the-kernel-how-honeymyte-weaponized-a-rootkit-to-hijack-asian-governments/
Daily CyberSecurity
The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
Kaspersky unmasks HoneyMyte's 2025 campaign, using the ProjectConfiguration.sys kernel rootkit to deploy ToneShell backdoors with elite stealth.
Apache NuttX RTOS Patches Two Filesystem Flaws
https://securityonline.info/apache-nuttx-rtos-patches-two-filesystem-flaws/
https://securityonline.info/apache-nuttx-rtos-patches-two-filesystem-flaws/
Daily CyberSecurity
Apache NuttX RTOS Patches Two Filesystem Flaws
Apache NuttX patches a moderate Use After Free (CVE-2025-48769) and a DoS flaw in its filesystem. Network-exposed devices must upgrade to v12.11.0.
React2Shell under attack: RondoDox Botnet spreads miners and malware
https://securityaffairs.com/186386/uncategorized/react2shell-under-attack-rondodox-botnet-spreads-miners-and-malware.html
https://securityaffairs.com/186386/uncategorized/react2shell-under-attack-rondodox-botnet-spreads-miners-and-malware.html
Security Affairs
React2Shell under attack: RondoDox Botnet spreads miners and malware
RondoDox botnet exploits the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers.
❤1
Trust Wallet confirms second Shai-Hulud supply-chain attack, $8.5M in crypto stolen
https://securityaffairs.com/186398/hacking/trust-wallet-confirms-second-shai-hulud-supply-chain-attack-8-5m-in-crypto-stolen.html
https://securityaffairs.com/186398/hacking/trust-wallet-confirms-second-shai-hulud-supply-chain-attack-8-5m-in-crypto-stolen.html
Security Affairs
Trust Wallet confirms second Shai-Hulud supply-chain attack, $8.5M in crypto stolen
Trust Wallet linked a second Shai-Hulud supply-chain attack to its Chrome extension hack, which resulted in the theft of about $8.5M in crypto
New “Eternl Desktop” Phishing Lure Drops LogMeIn to Hijack Cardano Wallets
https://securityonline.info/new-eternl-desktop-phishing-lure-drops-logmein-to-hijack-cardano-wallets/
https://securityonline.info/new-eternl-desktop-phishing-lure-drops-logmein-to-hijack-cardano-wallets/
Daily CyberSecurity
New "Eternl Desktop" Phishing Lure Drops LogMeIn to Hijack Cardano Wallets
Cardano users alert: A fake "Eternl Desktop" app uses LogMeIn Resolve to grant hackers remote control. Verify all downloads via official channels!
CVE-2025-68926: Critical Hardcoded Credential Flaw Exposes RustFS Storage Clusters
https://securityonline.info/cve-2025-68926-critical-hardcoded-credential-flaw-exposes-rustfs-storage-clusters/
https://securityonline.info/cve-2025-68926-critical-hardcoded-credential-flaw-exposes-rustfs-storage-clusters/
Daily CyberSecurity
CVE-2025-68926: Critical Hardcoded Credential Flaw Exposes RustFS Storage Clusters
RustFS patches a critical 9.8 CVSS flaw (CVE-2025-68926) where a hardcoded gRPC token allows unauthenticated attackers to wipe storage data.
Critical Wget2 Flaws Expose Users to Arbitrary File Overwrites and Memory Crashes
https://securityonline.info/critical-wget2-flaws-expose-users-to-arbitrary-file-overwrites-and-memory-crashes/
https://securityonline.info/critical-wget2-flaws-expose-users-to-arbitrary-file-overwrites-and-memory-crashes/
Daily CyberSecurity
Critical Wget2 Flaws Expose Users to Arbitrary File Overwrites and Memory Crashes
GNU Wget2 flaws (CVE-2025-69194 & 69195) allow attackers to overwrite files and crash systems via malicious downloads. Update your tools immediately!
The $3 Trillion Tidal Wave: SpaceX, OpenAI, and Anthropic Gear Up for 2026 IPOs
https://securityonline.info/the-3-trillion-tidal-wave-spacex-openai-and-anthropic-gear-up-for-2026-ipos/
https://securityonline.info/the-3-trillion-tidal-wave-spacex-openai-and-anthropic-gear-up-for-2026-ipos/
Daily CyberSecurity
The $3 Trillion Tidal Wave: SpaceX, OpenAI, and Anthropic Gear Up for 2026 IPOs
Wall Street braces for a $3 trillion spectacle in 2026 as SpaceX, OpenAI, and Anthropic reportedly prepare for the largest IPO wave in tech history.
The Vision Stalls: Why Apple is Quietly Pulling the Plug on Vision Pro Production
https://securityonline.info/the-vision-stalls-why-apple-is-quietly-pulling-the-plug-on-vision-pro-production/
https://securityonline.info/the-vision-stalls-why-apple-is-quietly-pulling-the-plug-on-vision-pro-production/
Daily CyberSecurity
The Vision Stalls: Why Apple is Quietly Pulling the Plug on Vision Pro Production
Facing a severe sales chill, Apple has slashed Vision Pro production and shifted focus to a cheaper model. Is the spatial computing dream in danger?
The End of Throttling? Samsung’s Radical “Side-by-Side” Plan to Save Exynos
https://securityonline.info/the-end-of-throttling-samsungs-radical-side-by-side-plan-to-save-exynos/
https://securityonline.info/the-end-of-throttling-samsungs-radical-side-by-side-plan-to-save-exynos/
Daily CyberSecurity
The End of Throttling? Samsung’s Radical "Side-by-Side" Plan to Save Exynos
Samsung is ditching chip-stacking for a Side-by-Side layout to end Exynos overheating. Will this radical 2nm design finally kill the "Exynos Curse"?
China’s New Cybersecurity Law Is Here — And It Changes Everything for Businesses
https://thecyberexpress.com/china-cybersecurity-law-2026/
https://thecyberexpress.com/china-cybersecurity-law-2026/
The Cyber Express
The New China Cybersecurity Law Becomes A Reality In 2026
China cybersecurity law takes effect in 2026, enforcing one-hour incident reporting, tougher penalties, AI governance rules, and compliance risks.
La Poste and La Banque Postale Hit by Cyberattack, Online Services Disrupted
https://thecyberexpress.com/la-poste-la-banque-postale-cyberattack-2026/
https://thecyberexpress.com/la-poste-la-banque-postale-cyberattack-2026/
The Cyber Express
La Poste & La Banque Postale Hit By Cyberattack Disruptions
A new cyberattack disrupted La Poste and La Banque Postale online services. Denial-of-service attacks by NoName057 temporarily blocked access.
A Week That Set the Tone for 2026: Cyber Laws, Breaches, and Disinformation
https://thecyberexpress.com/the-cyber-express-weekly-roundup-jan-2026/
https://thecyberexpress.com/the-cyber-express-weekly-roundup-jan-2026/
The Cyber Express
The Cyber Express Weekly Roundup: Dec 2025- Jan 2026
The Cyber Express rounds up the cybersecurity stories for this week, including, China’s new cybersecurity law, TikTok disinformation and more.
Phishing campaign abuses Google Cloud Application to impersonate legitimate Google emails
https://securityaffairs.com/186425/cyber-crime/phishing-campaign-abuses-google-cloud-application-to-impersonate-legitimate-google-emails.html
https://securityaffairs.com/186425/cyber-crime/phishing-campaign-abuses-google-cloud-application-to-impersonate-legitimate-google-emails.html
Security Affairs
Phishing campaign abuses Google Cloud Application to impersonate legitimate Google emails
Researchers uncovered a phishing campaign abusing Google Cloud Application Integration to send emails posing as legitimate Google messages.
The Kimwolf Botnet is Stalking Your Local Network
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/
Krebs on Security
The Kimwolf Botnet is Stalking Your Local Network
The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it's time for a broader awareness of the threat. The…
Covenant Health data breach after ransomware attack impacted over 478,000 people
https://securityaffairs.com/186439/data-breach/covenant-health-data-breach-after-ransomware-attack-impacted-over-478000-people.html
https://securityaffairs.com/186439/data-breach/covenant-health-data-breach-after-ransomware-attack-impacted-over-478000-people.html
Security Affairs
Covenant Health data breach after ransomware attack impacted over 478,000 people
Covenant Health suffered a ransomware attack by the Qilin group in May 2025, compromising data of over 478,000 individuals.
❤1
Treasury removes Intellexa spyware-linked trio from sanctions list
https://cyberscoop.com/treasury-removes-intellexa-spyware-linked-trio-from-sanctions-list/
https://cyberscoop.com/treasury-removes-intellexa-spyware-linked-trio-from-sanctions-list/
CyberScoop
Treasury removes Intellexa spyware-linked trio from sanctions list
The three Iranians had only just been added to the list in 2024, but a U.S. official said they had separated themselves from the company.
The Mainstream Master: Why MediaTek’s Dimensity 7100 is the Secret Weapon for 2026 Mid-Rangers
https://securityonline.info/the-mainstream-master-why-mediateks-dimensity-7100-is-the-secret-weapon-for-2026-mid-rangers/
https://securityonline.info/the-mainstream-master-why-mediateks-dimensity-7100-is-the-secret-weapon-for-2026-mid-rangers/
Daily CyberSecurity
The Mainstream Master: Why MediaTek’s Dimensity 7100 is the Secret Weapon for 2026 Mid-Rangers
MediaTek's Dimensity 7100 debuts with a powerful 4+4 CPU layout and native 45W fast charging, targeting a smoother 5G experience for 2026 mid-range phones.
Beyond the Screen: OpenAI’s Secret “Gumdrop” AI Pen Aims for the “iPhone Moment”
https://securityonline.info/beyond-the-screen-openais-secret-gumdrop-ai-pen-aims-for-the-iphone-moment/
https://securityonline.info/beyond-the-screen-openais-secret-gumdrop-ai-pen-aims-for-the-iphone-moment/
Daily CyberSecurity
Beyond the Screen: OpenAI’s Secret "Gumdrop" AI Pen Aims for the "iPhone Moment"
OpenAI is prepping "Gumdrop," an AI-integrated pen designed by Jony Ive. Launching in 2027, it promises zero-latency, "audio-first" companion intelligence.
Two U.S. cybersecurity professionals plead guilty in BlackCat/Alphv ransomware case
https://securityaffairs.com/186446/cyber-crime/two-u-s-cybersecurity-professionals-plead-guilty-in-blackcat-alphv-ransomware-case.html
https://securityaffairs.com/186446/cyber-crime/two-u-s-cybersecurity-professionals-plead-guilty-in-blackcat-alphv-ransomware-case.html
Security Affairs
Two U.S. cybersecurity professionals plead guilty in BlackCat/Alphv ransomware case
Two U.S. cybersecurity professionals pleaded guilty to charges tied to their roles in BlackCat/Alphv ransomware attacks.