The Hacker Returns: Bitfinex Mastermind Ilya Lichtenstein Freed Early via Trump Law
https://securityonline.info/the-hacker-returns-bitfinex-mastermind-ilya-lichtenstein-freed-early-via-trump-law/
https://securityonline.info/the-hacker-returns-bitfinex-mastermind-ilya-lichtenstein-freed-early-via-trump-law/
Daily CyberSecurity
The Hacker Returns: Bitfinex Mastermind Ilya Lichtenstein Freed Early via Trump Law
Bitfinex hacker Ilya Lichtenstein released early in Jan 2026! He credits Trump’s First Step Act and vows a new career in cybersecurity research.
The Unpatchable Leak: Sony’s PS5 Security Crumples as BootROM Keys Hit the Web
https://securityonline.info/the-unpatchable-leak-sonys-ps5-security-crumples-as-bootrom-keys-hit-the-web/
https://securityonline.info/the-unpatchable-leak-sonys-ps5-security-crumples-as-bootrom-keys-hit-the-web/
Daily CyberSecurity
The Unpatchable Leak: Sony’s PS5 Security Crumples as BootROM Keys Hit the Web
A massive leak of PS5 BootROM keys has exposed Sony’s hardware trust root. This unpatchable flaw clears the path for permanent jailbreaks and custom firmware.
Systems over Slop: Nadella’s 2026 AI Vision Sparks “Microslop” Revolt
https://securityonline.info/systems-over-slop-nadellas-2026-ai-vision-sparks-microslop-revolt/
https://securityonline.info/systems-over-slop-nadellas-2026-ai-vision-sparks-microslop-revolt/
Daily CyberSecurity
Systems over Slop: Nadella’s 2026 AI Vision Sparks "Microslop" Revolt
Satya Nadella’s 2026 AI manifesto calls for a shift from "models to systems," but the #Microslop backlash proves users are tired of AI-generated junk.
The Scrapbook Strategy: Why OpenAI is Betting $17 Billion on Pinterest
https://securityonline.info/the-scrapbook-strategy-why-openai-is-betting-17-billion-on-pinterest/
https://securityonline.info/the-scrapbook-strategy-why-openai-is-betting-17-billion-on-pinterest/
Daily CyberSecurity
The Scrapbook Strategy: Why OpenAI is Betting $17 Billion on Pinterest
OpenAI is reportedly planning to acquire Pinterest for $17.5B in 2026. The goal? High-quality visual data and a proven ad engine to take on Google.
Resecurity Caught ShinyHunters in Honeypot
https://securityaffairs.com/186528/security/resecurity-caught-shinyhunters-in-honeypot.html
https://securityaffairs.com/186528/security/resecurity-caught-shinyhunters-in-honeypot.html
Security Affairs
Resecurity Caught ShinyHunters in Honeypot
Resecurity caught ShinyHunters (SLH) using decoy accounts; the group attacked airlines, telecoms, and law enforcement in Sept 2025.
European Space Agency Confirms Cybersecurity Breach on External Servers
https://thecyberexpress.com/european-space-agency-confirms-cyber-incident/
https://thecyberexpress.com/european-space-agency-confirms-cyber-incident/
The Cyber Express
European Space Agency Confirms Cybersecurity Incident
European Space Agency (ESA) has said further updates will be shared once more information becomes available.
SlowMist Flags Potential Security Risk at HitBTC Exchange
https://thecyberexpress.com/hitbtc-exchange-critical-security-warning/
https://thecyberexpress.com/hitbtc-exchange-critical-security-warning/
The Cyber Express
HitBTC Exchange Faces Critical Security Warning
A security alert from SlowMist warns of a critical vulnerability at HitBTC Exchange after failed disclosure attempts.
Sedgwick discloses data breach after TridentLocker ransomware attack
https://securityaffairs.com/186525/data-breach/sedgwick-discloses-data-breach-after-tridentlocker-ransomware-attack.html
https://securityaffairs.com/186525/data-breach/sedgwick-discloses-data-breach-after-tridentlocker-ransomware-attack.html
Security Affairs
Sedgwick discloses data breach after TridentLocker ransomware attack
Sedgwick confirmed a cyber incident at its federal contractor unit after TridentLocker claimed to steal 3.4GB of data.
Critical IBM API Connect Vulnerability Enables Authentication Bypass
https://thecyberexpress.com/ibm-api-connect-security-vulnerability/
https://thecyberexpress.com/ibm-api-connect-security-vulnerability/
The Cyber Express
IBM API Connect Faces Critical Security Vulnerability
Organizations running affected versions of IBM API Connect are urged to assess their deployments immediately.
ManageMyHealth Provides Update on Ongoing Cyberattack Investigation
https://thecyberexpress.com/managemyhealth-hack-explained/
https://thecyberexpress.com/managemyhealth-hack-explained/
The Cyber Express
Understanding The ManageMyHealth Hack And Its Impact
The ManageMyHealth hack affected multiple users. MMH investigates, secures systems, and begins patient notifications.
VVS Stealer, a new python malware steals Discord credentials
https://securityaffairs.com/186542/malware/vvs-stealer-a-new-python-malware-steals-discord-credentials.html
https://securityaffairs.com/186542/malware/vvs-stealer-a-new-python-malware-steals-discord-credentials.html
Security Affairs
VVS Stealer, a new python malware steals Discord credentials
VVS Stealer is a Python-based malware that steals Discord credentials and tokens and has been sold on Telegram since at least April 2025.
The cybercriminal behind the 2016 Bitfinex hack has been released from prison early thanks to Trump’s 2018 First Step Act
https://securityaffairs.com/186551/cyber-crime/the-cybercriminal-behind-2016-bitfinex-hack-released.html
https://securityaffairs.com/186551/cyber-crime/the-cybercriminal-behind-2016-bitfinex-hack-released.html
Security Affairs
The cybercriminal behind the 2016 Bitfinex hack has been released from prison early thanks to Trump’s 2018 First Step Act
Ilya Lichtenstein, who was sentenced to prison for his role in the Bitfinex hack that occurred in 2016, has been released from prison early.
Fragged Files: Critical Zero-Day Hits Quake III Arena Engines via Directory Traversal
https://securityonline.info/fragged-files-critical-zero-day-hits-quake-iii-arena-engines-via-directory-traversal/
https://securityonline.info/fragged-files-critical-zero-day-hits-quake-iii-arena-engines-via-directory-traversal/
Daily CyberSecurity
Fragged Files: Critical Zero-Day Hits Quake III Arena Engines via Directory Traversal
A zero-day in Quake III Arena engines (ioquake3, OpenArena) allows attackers to read sensitive system files and target players. Check RCON access now!
Riot Games Login Outage Traced to Expired SSL Certificate
https://securityonline.info/riot-games-login-outage-traced-to-expired-ssl-certificate/
https://securityonline.info/riot-games-login-outage-traced-to-expired-ssl-certificate/
Daily CyberSecurity
Riot Games Login Outage Traced to Expired SSL Certificate
Riot Games suffers a global League of Legends login outage after a digital certificate expired on Jan 4, 2026—echoing a similar lapse from 2016.
Time to restore America’s cyberspace security system
https://cyberscoop.com/us-cyber-defense-falling-behind-cisa-leadership-funding-op-ed/
https://cyberscoop.com/us-cyber-defense-falling-behind-cisa-leadership-funding-op-ed/
CyberScoop
Time to restore America’s cyberspace security system
America’s cyber defenses are slipping as China, Russia, Iran, and North Korea escalate attacks. Congress must restore CISA leadership, funding, and partnerships.
Kimwolf botnet leverages residential proxies to hijack 2M+ Android devices
https://securityaffairs.com/186559/malware/kimwolf-botnet-leverages-residential-proxies-to-hijack-2m-android-devices.html
https://securityaffairs.com/186559/malware/kimwolf-botnet-leverages-residential-proxies-to-hijack-2m-android-devices.html
Security Affairs
Kimwolf botnet leverages residential proxies to hijack 2M+ Android devices
The Kimwolf botnet has infected over 2 million Android devices, spreading mainly through residential proxy networks, researchers say.
Convicted Bitfinex bitcoin launderer freed from prison, thanks Trump law
https://cyberscoop.com/bitfinex-hacker-ilya-lichtenstein-early-release-first-step-act/
https://cyberscoop.com/bitfinex-hacker-ilya-lichtenstein-early-release-first-step-act/
CyberScoop
Convicted Bitfinex bitcoin launderer freed from prison, thanks Trump law
A hacker who pleaded guilty to conspiring to launder billions of dollars worth of bitcoin stolen in the 2016 Bitfinex hack has been released from prison, a little more than one year after being sentenced to a five-year stint.
AI, voting machine conspiracies fill information vacuum around Venezuela operation
https://cyberscoop.com/ai-voting-machine-conspiracies-fill-information-vacuum-venezuela-raid/
https://cyberscoop.com/ai-voting-machine-conspiracies-fill-information-vacuum-venezuela-raid/
CyberScoop
AI, voting machine conspiracies fill information vacuum around Venezuela operation
After the U.S. capture of Nicholas Maduro, fake AI-driven media quickly flooded the internet, while Trump allies revived debunked theories of rigged voting machines.
The Chromebook Killer Fails: Microsoft to Kill Windows 11 SE in 2026
https://securityonline.info/the-chromebook-killer-fails-microsoft-to-kill-windows-11-se-in-2026/
https://securityonline.info/the-chromebook-killer-fails-microsoft-to-kill-windows-11-se-in-2026/
Daily CyberSecurity
The Chromebook Killer Fails: Microsoft to Kill Windows 11 SE in 2026
Microsoft confirms Windows 11 SE support ends Oct 2026, leaving schools with underpowered hardware and a forced choice: upgrade or switch to Google.
New TCC Bypass (CVE-2025-43530) Exposes macOS to Unchecked Automation
https://securityonline.info/new-tcc-bypass-cve-2025-43530-exposes-macos-to-unchecked-automation/
https://securityonline.info/new-tcc-bypass-cve-2025-43530-exposes-macos-to-unchecked-automation/
Daily CyberSecurity
New TCC Bypass (CVE-2025-43530) Exposes macOS to Unchecked Automation
Researcher Mickey Jin uncovers CVE-2025-43530, a critical TCC bypass in macOS allowing attackers to hijack user data via accessibility tools.
Researcher Details Stack Buffer Overflow Flaw in Net-SNMP snmptrapd with PoC
https://securityonline.info/researcher-details-stack-buffer-overflow-flaw-in-net-snmp-snmptrapd-with-poc/
https://securityonline.info/researcher-details-stack-buffer-overflow-flaw-in-net-snmp-snmptrapd-with-poc/
Daily CyberSecurity
Researcher Details Stack Buffer Overflow Flaw in Net-SNMP snmptrapd with PoC
D4mianWayne details CVE-2025-68615, a 9.8 critical flaw in Net-SNMP allowing unauthenticated RCE. Update to v5.9.5 or v5.10.pre2 now!