GreyNoise observed thousands of exploit attempts hitting roughly a dozen Adobe ColdFusion vulnerabilities over the Christmas 2025 holiday, indicating a coordinated campaign. Organizations running ColdFusion should fast-track patching, audit internet exposure (especially admin endpoints), and harden WAF rules to blunt mass scanning and exploitation.
Source: Security Affairs
RondoDox Botnet Hijacks Devices via React2Shell in Next.js
Attackers behind the RondoDox botnet are exploiting the React2Shell flaw in Next.js to compromise more than 90,000 unpatched devices, including routers, smart cameras, and small business websites. The campaign highlights how web framework bugs can cascade into IoT and SOHO ecosystems; urgently patch affected apps and segment or rate-limit device egress to disrupt botnet control.
Source: HackRead
AI Agents Poised to Become 2026’s Biggest Insider Threat
Palo Alto Networks’ security intel chief Wendi Whitmore warns that autonomous AI agents represent the new insider threat as organizations grant them access and credentials. Misuse, compromise, and error by agents could cause outsized impact, pushing leaders to lock down permissions, require human-in-the-loop approvals, and strengthen monitoring.
Source: The Register
Leak Ties Chinese Firm Knownsec to State-Linked Offensive Cyber Operations
A leak from Chinese cybersecurity company Knownsec reportedly exposes deep involvement in state-linked offensive activity and intelligence collection. The revelations underscore growing scrutiny of vendor ecosystems and the blurred lines between defensive services and state-directed offensive work.
Source: CyberNews
Trump Suggests US Used Cyberattacks in Venezuela Strikes
Former President Trump suggested the US conducted cyberattacks to “turn off lights” in Venezuela during strikes, with U.S. Cyber Command involved in setting the stage. Public acknowledgement of such operations, if accurate, raises questions about norms, transparency, and escalation in the use of offensive cyber alongside kinetic actions.
Source: Politico Cyber
California Launches Tool for Residents to Force Data Brokers to Delete Personal Data
A new tool enables California residents to demand that data brokers delete their personal information, simplifying opt-outs at scale. The move raises compliance and operational stakes for data brokers and downstream buyers while pressing security teams to mature data inventories, deletion workflows, and proof-of-compliance.
Source: TechCrunch Security
France Probes AI ‘Undressing’ Deepfakes on X Allegedly Made With Grok
French authorities opened an investigation after hundreds of women and teens reported AI-generated “undressed” images circulating on X, allegedly created using Grok. The probe spotlights the legal, platform, and model-governance responsibilities tied to generative AI misuse and the need for stronger detection and reporting mechanisms.
Source: Security Affairs
You May Also Be Interested In...
Cryptocurrency Scam Emails and Web Pages As We Enter 2026
Finnish Authorities Detain Crew After Undersea Internet Cable Severed