Latest Internet & Cybersecurity News

馃搮January 2, 2026 at 1:00 PM
2026 kicks off with new cyber threats like GhostAd adware, macOS attacks, proxy botnets, maritime bulletins, and ongoing 2025 breach aftermaths including major crypto heists.
1

Cybersecurity Outlook: 2026 Will Force a New Operating Model

Attackers are exploiting vulnerabilities at machine speed while developers ship AI-generated code, demanding a dramatic shift in cybersecurity models for 2026.Source 1 This evolution is driven by rapid AI integration in development and attack vectors.Source 1 Organizations must adapt to maintain defenses against accelerating threats.Source 1

2

Biggest Cybersecurity Stories of 2025: $1.5 Billion ByBit Crypto Heist

North Korea's Lazarus Group stole $1.5 billion in Ethereum from ByBit's cold wallet via a compromised developer machine.Source 2 The breach involved manipulating transaction approvals to drain funds.Source 2 FBI confirmed Lazarus responsibility, highlighting ongoing crypto threats.Source 2

3

2025 Crypto Thefts Surge Beyond ByBit

Additional heists included $85M from Phemex, $223M from Cetus Protocol, $27M from BigONE, and $7M impacting Trust Wallet users.Source 2 Pro-Israel hackers also burned $90M in Iran's Nobitex exchange.Source 2 These incidents underscore persistent vulnerabilities in crypto infrastructure.Source 2

4

AI Tools Vulnerable to Prompt Injection Attacks in 2025

Microsoft 365 Copilot suffered zero-click data leakage via hidden prompt injection in emails.Source 2 Google Gemini was exploited through email summaries and calendar invites for phishing.Source 2 AI coding assistants were manipulated to execute harmful code.Source 2

5

Insider Threats Hit High-Profile Targets in 2025

A CrowdStrike insider attempt was detected before network access.Source 2 FinWise Bank breach affected 689,000 customers due to insider activity.Source 2 A bank employee sold credentials for $920, enabling a $140M heist at Brazil鈥檚 Central Bank.Source 2

6

Zero-Day Flaws Exploited Across Major Vendors in 2025

Zero-days hit Cisco, Fortinet, Citrix NetScaler, Ivanti, SonicWall, FreePBX, and CrushFTP.Source 2 Microsoft SharePoint was targeted by Chinese actors and ransomware via ToolShell flaw.Source 2 These enabled web shells, data theft, and persistence in networks.Source 2

7

Lithuanian Hacker Arrested for $1.2M Clipboard Malware Scheme

A 29-year-old extradited to South Korea infected 2.8M systems with KMSAuto-disguised clipper malware from 2020-2023.Source 4 Stole $1.2M in virtual assets from 3,100 addresses.Source 4 Malware stole clipboard data for crypto wallet swaps.Source 4

8

Coordinated ColdFusion Exploit Spree Targets Servers

Holiday campaign from Japan-based infrastructure exploited 10+ ColdFusion CVEs from 2023-2024.Source 4 GreyNoise attributed ~98% of traffic to single actor CTG Server Limited.Source 4 Systematic attacks hit exposed Adobe ColdFusion servers.Source 4

9

Unleash Protocol Smart Contract Upgrade Exploited for $3.9M Theft

Unauthorized admin control via multisig governance led to contract upgrade and $3.9M fund withdrawal.Source 4 PeckShield confirmed the blockchain exploit on the IP platform.Source 4 Incident highlights DeFi governance risks.Source 4

10

New IPCola Proxy Botnet Offers 1.6M IPs from Infected Devices

Global network includes IoT, desktop, mobile from 100+ countries, mainly India, Brazil, Mexico, US.Source 4 Sold as proxy service for illicit activities.Source 4 Underscores rise in large-scale botnets.Source 4

11

Manage My Health Cyber Breach Update: 7% of 1.8M Patients Affected

Incident detected Dec 30, 2025; unauthorized access to specific documents for ~126,000 patients.Source 5 Forensic analysis ongoing with Privacy Commissioner and NZ Police notified.Source 5 Platform secured, no further access reported.Source 5

12

Maritime Cybersecurity Bulletin Highlights Latest Threats

Jan 1, 2026 bulletin covers recent vulnerabilities and attacks targeting maritime fleets.Source 3 Aims to help operators stay protected amid evolving risks.Source 3 Focuses on sector-specific cyber news.Source 3