Latest Internet & Cybersecurity News

đź“…January 2, 2026 at 1:00 AM
2026 kicks off with smart contract exploits, new ransomware groups, DPRK crypto thefts, teen hacking rings, surging exfiltration attacks, and rising AI threats in cybersecurity.
1

Unleash Protocol Smart Contract Exploited for $3.9M

Unleash Protocol detected unauthorized activity via compromised multisig governance, enabling an external address to perform a contract upgrade and steal $3.9 million in user funds, per PeckShield analysis.Source 1Source 6 This incident highlights vulnerabilities in decentralized platforms' administrative controls.Source 1 Investigations continue into the breach's origins.Source 6

2

New IPCola Proxy Botnet Offers 1.6M IPs Worldwide

IPCola proxy network sells over 1.6 million unique IPs from IoT, desktop, and mobile devices across 100+ countries, mainly India, Brazil, Mexico, and U.S.Source 1 It enables cybercriminals to mask activities through infected devices.Source 1 This botnet underscores growing proxy abuse trends.Source 1

3

GhostAd Adware and macOS Malware in ThreatsDay Bulletin

The first 2026 ThreatsDay Bulletin covers GhostAd drain adware, macOS attacks, proxy botnets, and cloud exploits as emerging threats.Source 1 Threat actors evolve tactics post-holidays with subtle code changes and scams.Source 1 Defenders must adapt to quieter, precise attacks.Source 1

4

North Korean Hackers Thwarted in Amazon Job Infiltration

DPRK-affiliated hackers stole over $2B in crypto in 2025, including Bybit's $1.5B heist, using job scams despite declining attack frequency.Source 1 Amazon blocked infiltration attempts funding weapons via crypto theft.Source 1 TRM Labs notes DPRK as top financially motivated cyber operator.Source 1

5

Feds Probe 2025 Breaches at F5, Coupang, Bybit

Q4 2025 cybersecurity incidents at F5, Coupang, and Bybit sparked regulatory investigations and lawsuits over delayed disclosures.Source 2 Nation-state actors caused $3.95B+ losses; F5 stock fell 13.9% post-disruption.Source 2 Bybit's $1.4B Lazarus hack intensified crypto security scrutiny.Source 2

6

10 New Ransomware Groups Emerge in 2025

Cyble tracked 10 new 2025 ransomware groups like Global (cross-platform Linux/ESXi) and The Gentlemen, emphasizing double extortion and credential access.Source 5 Trends include faster rebrands, identity compromises over exploits, and hypervisor targeting.Source 5 Expect intensified tactics in 2026.Source 5

7

Pure Exfiltration Ransomware Attacks Surging

Ransomware shifts to encryption-free exfiltration for stealth, making detection harder with evolving attack chains.Source 4 Recent case studies predict continued rise in 2026.Source 4 Defenders struggle against these low-noise tactics.Source 4

8

Teen Hacking Group Scattered Spider Targets 120 Firms

Feds hunt Scattered Spider teens who breached Nike, Chick-fil-A, Instacart, and others via social engineering, affecting $1T+ market cap firms.Source 11 Group uses Telegram/Discord for 'lols' with profane antics unlike nation-state ops.Source 11 Associations fluid in 'spaghetti soup' structure.Source 11

9

Critical Infrastructure Faces Intensifying 2026 Threats

CNI cybersecurity challenges persist with geopolitical tensions, AI-assisted hacks expanding to healthcare, finance, data centers.Source 7 EU Cyber Resilience Act aids but upgrades lag; adopt ICS controls.Source 7 Criminal threats grow exponentially per Dragos CTO.Source 7

10

AI Agent Attacks to Drive $520B Cybersecurity Spend

Global cybersecurity spending hits $520B in 2026 amid AI agents as attack vectors, outnumbering humans 82:1.Source 3 CIBR ETF poised for gains from PANW, CRWD demand on agentic defenses.Source 3 Harvard notes surge in deepfake exploits.Source 3

11

Vendor Risk Rises with AI-Enabled Supply Chain Attacks

2026's top risk is vendor ecosystems via AI-automated credential theft and impersonation for mass client access.Source 12 Breaching small providers yields thousands of victims efficiently.Source 12 Organizations must prioritize third-party security.Source 12