CISA added HPE OneView’s CVE-2025-37164 to the Known Exploited Vulnerabilities catalog, citing active attacks and setting a January 28 remediation deadline. The CVSS 10.0 flaw enables unauthenticated remote code execution on infrastructure management appliances, risking takeover of servers managed by OneView. Organizations should patch immediately, restrict management interfaces, and monitor for anomalous OneView activity.
Source: HackRead
FBI warns Kimsuky is using QR-code “quishing” to target policy and research orgs
North Korea–linked APT Kimsuky is delivering spear-phishing emails that embed malicious QR codes to compromise government agencies, think tanks, and academic institutions. The technique shifts the attack to mobile devices and bypasses traditional email link scanning. Teams should train users to avoid scanning QR codes from unsolicited emails and enforce phishing-resistant MFA.
Source: Security Affairs
Data of 17.5 million Instagram users exposed amid wave of password reset emails
Researchers report a breach exposing usernames, phone numbers, email addresses, and physical addresses of about 17.5M Instagram users, triggering mass password reset notifications. The leak heightens risks of targeted phishing and credential stuffing, with concerns the data is already circulating. Users should verify any reset only within the Instagram app, enable 2FA, and watch for SIM-swap attempts.
Source: Security Affairs
MuddyWater deploys new RustyWater RAT via spear-phishing across Middle East sectors
The Iranian threat group MuddyWater is targeting diplomatic, maritime, financial, and telecom entities with a Rust-based backdoor dubbed RustyWater. Delivered via icon-spoofed lures and malicious Word documents, the implant features asynchronous C2, anti-analysis measures, registry persistence, and modular extensions. Defenders should tighten attachment policies and hunt for RustyWater artifacts and traffic.
Source: TheHackerNews
Europol arrests 34 Black Axe members in Spain tied to €5.9M fraud operations
Spanish National Police, supported by Europol and Bavarian authorities, arrested 34 suspected members of the Black Axe crime syndicate across Seville, Madrid, Málaga, and Barcelona. The group allegedly ran large-scale romance scams and business email fraud that netted millions. Expect disruption and actor displacement; reinforce BEC controls, supplier verification, and payment-change procedures.
Source: TheHackerNews
UK exempts itself from flagship cyber law, prompting accountability concerns
An analysis finds the UK government has carved out an exemption for itself from obligations in a new cyber resilience law, promising “equivalent standards” without legal compulsion. After a series of government breaches, critics warn the move weakens trust and enforcement clarity. Security leaders should track how this affects regulatory expectations and incident accountability.
Source: The Register
Database of 323,986 BreachForums users leaked; admins dispute scope and timing
A dataset allegedly containing 323,986 BreachForums user records has surfaced online, though forum administrators claim it’s partial and dates to August 2025. The leak could expose threat actors, buyers, and even some researchers, increasing risks of doxxing, impersonation, and law-enforcement targeting. Monitor for forum migrations and emerging threat actor rebrandings.
Source: HackRead
You May Also Be Interested In...
YARA-X 1.11.0 adds hash function warnings to aid rule authors
PSA: Treat Instagram password reset emails as suspicious and verify in-app
AI-powered “Truman Show” scam builds synthetic communities to target investors