Attackers are actively exploiting a new SmarterMail vulnerability to gain remote code execution, with incidents escalating to ransomware deployment. CISA added CVE-2026-24423 to its Known Exploited Vulnerabilities list after previously flagging two other SmarterMail bugs, signaling concerted targeting of the platform. Organizations should patch immediately, isolate exposed SmarterMail instances, and review logs for suspicious uploads or authentication bypass activity.
Source: HelpNet Security
Poland’s energy control systems breached via exposed VPN access
Coordinated cyberattacks on December 29 targeted Polish wind and solar farms, a CHP plant, and a manufacturer, with CERT Polska assessing a single destructive actor was responsible. While power generation wasn’t impacted, investigators found initial access hinged on exposed VPNs—a reminder that unmanaged remote access remains a prime vector into OT/ICS environments.
Source: HelpNet Security
CISA orders US agencies to remove unsupported edge devices
A new binding operational directive compels federal agencies to inventory and replace end-of-life edge devices—firewalls, load balancers, VPNs, routers, and similar gear—that no longer receive security updates. The move aims to reduce technical debt and close high-value ingress points routinely abused in real-world intrusions, with agencies given roughly 12–18 months to comply.
Source: HelpNet Security
Compromised dYdX npm/PyPI packages push wallet stealers and RATs
Legitimate dYdX client libraries on npm and PyPI were tampered with to distribute malware that can exfiltrate wallet credentials and enable remote code execution. The supply chain attack underscores the need for strict package pinning, integrity verification, and immediate rotation of compromised tokens and API keys in developer environments.
Source: TheHackerNews
China-linked ‘DKnife’ AitM toolkit targets routers and edge devices
Researchers detailed DKnife, a gateway-monitoring and adversary-in-the-middle framework with seven Linux implants capable of deep packet inspection, traffic manipulation, and on-path malware delivery. Active since at least 2019 and linked to China-nexus actors, DKnife highlights the strategic value of compromised routers and edge appliances in hijacking traffic and staging follow-on attacks.
Source: TheHackerNews
State-aligned espionage group breaches 70 orgs across 37 countries
Palo Alto Networks Unit 42 tracked an Asian state-backed operation, TGR-STA-1030, compromising at least 70 government and critical infrastructure entities and probing 155 more. Victims include national police, border control, parliaments, and telecoms, signaling broad objectives and sustained reconnaissance against high-value public-sector networks.
Source: TheHackerNews
Global DNS hijacking campaign abuses old, unsupported home routers
A widespread DNS hijacking operation is redirecting users via outdated consumer routers that no longer receive security updates. The campaign reinforces the risk posed by legacy SOHO devices to enterprise security—especially for remote workers—necessitating enforced DNS security controls, router refresh programs, and outbound DNS monitoring.
Source: SCMagazine
You May Also Be Interested In...
Apple Pay phish uses fake support calls to steal payment details
Google patches RCE, internal database leak flaws in Looker
State-backed phishing attacks targeting military officials and journalists on Signal