Microsoft warns that threat actors are abusing complex mail routing and misconfigured spoof protections to send phishing emails that appear to originate from inside victim organizations. Operators tied to phishing-as-a-service offerings, including Tycoon 2FA, have used this vector to increase trust and bypass controls. Microsoft urges organizations to review routing paths and enforce SPF, DKIM, and DMARC alignment, including for third-party senders.
Source: Microsoft MMPC
Active exploitation: Critical RCE hitting legacy D-Link DSL routers (CVE-2026-0625)
A command injection flaw in legacy D-Link DSL gateway routers is being actively exploited in the wild, enabling unauthenticated remote attackers to execute commands via a vulnerable dnscfg.cgi endpoint. With many devices end-of-life, patches may be unavailable—administrators should retire affected models, disable remote management, and isolate devices immediately.
Source: TheHackerNews
“ClickFix” lures and fake BSODs target European hotels to drop DCRat
A sophisticated social-engineering campaign impersonates Booking.com, funneling hospitality staff to fake Blue Screen of Death pages that prompt them to “apply a fix,” ultimately executing malware and installing the DCRat remote access trojan. The operation chains phishing, fake CAPTCHAs, and staged support flows to defeat user caution and email filtering.
Source: SecurityWeek
900,000 users hit by malicious Chrome extensions stealing ChatGPT and DeepSeek chats
Researchers uncovered two popular Chrome extensions siphoning AI chat content and browsing data to attacker servers, creating a high-risk data leakage vector for enterprises experimenting with generative AI. Organizations should remove the flagged extensions, audit browser extension usage, and lock down extension policies in managed environments.
Source: TheHackerNews
Critical auth bypass in IBM API Connect (CVE-2025-13915) — patch now
The Cyber Security Agency of Singapore and IBM disclosed a critical authentication bypass (CVSS 9.8) affecting IBM API Connect versions up to 10.0.8.5 and 10.0.11.0. While no active exploitation is reported, the remotely exploitable flaw can grant unauthorized access; IBM has issued interim fixes and urges immediate upgrades.
Source: Cyble
Android January update fixes critical Dolby decoder bug (CVE-2025-54957)
Google’s January Android security release patches a critical vulnerability in the Dolby audio decoder first fixed for Pixel devices in December. The flaw could enable remote code execution via crafted media; administrators should prioritize rolling out the update across managed fleets.
Source: SecurityWeek
Ledger confirms third‑party breach exposing customer data; phishing begins
Crypto wallet maker Ledger says customer information was accessed via ecommerce partner Global-e, and warns that phishing attempts have already started. While seed phrases and passwords weren’t exposed, attackers are leveraging the data to push fake updates and wallet-draining scams—users should distrust unsolicited messages and verify firmware only in-app.
Source: The Register
You May Also Be Interested In...
CERT/CC warns of critical, unfixed vulnerability in TOTOLINK EX200
FCC finalizes new penalties for robocall violators
UK government admits years of cyber policy have failed, announces reset