CERT Polska disclosed that on December 29, 2025, coordinated cyberattacks targeted more than 30 wind and solar farms, a manufacturing firm, and a major combined heat and power plant serving nearly 500,000 people. Reported disruptions to communications with industrial assets highlight growing risks to energy-sector OT/IoT environments and remote management channels.
Source: The Hacker News
eScan Antivirus Supply-Chain Incident Pushes Malware via Update Server
Attackers compromised a MicroWorld Technologies update server and delivered a malicious file to eScan antivirus customers. The breach underscores the high leverage of trusted update channels in software supply-chain attacks and the need to verify update integrity and hunt for post-compromise activity.
Source: SecurityWeek
Mandiant: ShinyHunters-Style Vishing Steals MFA to Breach SaaS
Mandiant reports expanded campaigns using advanced voice phishing and realistic credential-harvesting sites to capture MFA and break into SaaS platforms. By targeting identity and exploiting real-time social engineering, attackers are bypassing MFA prompts and gaining persistence across cloud apps.
Source: The Hacker News
FBI Seizes RAMP, a Ransomware-Friendly Cybercrime Forum
The FBI has taken RAMP offline, a forum that openly allowed ransomware activity and boasted over 14,000 active users. The seizure likely yields valuable intelligence on operators and affiliates and could drive further disruptions as criminal communities regroup.
Source: Graham Cluley
Iran-Linked “RedKitten” Targets NGOs and Activists in Surveillance Campaign
HarfangLab observed a Farsi-speaking actor aligned with Iranian state interests conducting a January 2026 campaign—dubbed RedKitten—against NGOs and individuals documenting human rights abuses. Coinciding with late-2025 unrest, the operation appears focused on credential theft and monitoring of civil society.
Source: The Hacker News
U.S. Seizes $400M Tied to Helix Dark Web Crypto Mixer
U.S. authorities seized more than $400 million in cryptocurrency, cash, and property linked to Helix, a darknet bitcoin mixing service popular with drug markets. The move signals sustained pressure on mixers facilitating money laundering for cybercrime, raising compliance stakes for exchanges and other VASPs.
Source: HackRead
Windows Malware Uses Pulsar RAT for Live Chats While Stealing Data
Researchers warn of Windows malware leveraging Pulsar RAT to open live chat sessions with victims while exfiltrating data in the background. The high-touch tactic blends social engineering with active intrusion to speed privilege gains and persistence.
Source: HackRead
You May Also Be Interested In...
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flaw
Vulnerability & Patch Roundup — January 2026 (WordPress)
After TikTok: Navigating the Complex Web of Foreign Tech Bans