Latest Internet & Cybersecurity News

đź“…January 3, 2026 at 1:00 AM
Latest cybersecurity news highlights AI-driven attack predictions for 2026, major breaches at ESA and Sedgwick, ransomware surges, phishing campaigns, and US ransomware affiliates pleading guilty.
1

Tenable Predicts AI Will Supercharge Cyber Attacks in 2026

Tenable forecasts that AI will increase the speed and volume of cyber attacks, making them cheaper while emphasizing proactive prevention over reactive measures. Machine identities are expected to become the top cloud breach vector due to excessive privileges.Source 1 Custom AI security tools and automated remediation will rise to counter these threats.Source 1

2

Phishing Campaign Abuses Google Cloud for Fake Emails

Check Point researchers uncovered a phishing operation using Google Cloud Application Integration to impersonate legitimate Google messages. The campaign targets users with deceptive emails to steal credentials.Source 2 This highlights ongoing abuse of cloud services for phishing.Source 2

3

IBM Patches Critical API Connect Vulnerability CVE-2025-13915

IBM disclosed a critical flaw (CVSS 9.8) in API Connect allowing remote authentication bypass and access. The vulnerability has been addressed in recent updates.Source 2 Organizations are urged to patch immediately.Source 2

4

Trust Wallet Chrome Extension Hit by Second Shai-Hulud Attack

Trust Wallet reports a likely supply-chain compromise of its Chrome extension, resulting in $8.5 million crypto theft. This marks the second Shai-Hulud incident targeting the wallet.Source 2 Users are advised to update and monitor accounts.Source 2

5

RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers

CloudSEK warns of the RondoDox botnet using CVE-2025-55182 to infect vulnerable Next.js servers with malware and cryptominers. Server owners should apply patches urgently.Source 2 The botnet spreads rapidly across cloud environments.Source 2

6

European Space Agency Confirms Data Breach

ESA disclosed a breach after a hacker offered stolen data from external science servers for sale. The incident compromises sensitive research information.Source 2 Investigations are ongoing to assess full impact.Source 2

7

Singapore Warns of Critical SmarterMail RCE Flaw CVE-2025-52691

CSA alerts on a SmarterMail vulnerability enabling unauthenticated remote code execution via file upload. Immediate updates are recommended to prevent exploitation.Source 2 This poses high risk to email servers.Source 2

8

Sedgwick Confirms Cyber Incident on Federal Contractor Subsidiary

Claims administration firm Sedgwick reported a cyber incident disrupting its major federal contractor operations. The breach affects sensitive data handling.Source 4 Recovery efforts are underway as of January 2, 2026.Source 4

9

Two US Cybersecurity Pros Plead Guilty in BlackCat Ransomware Attacks

Ryan Goldberg and Kevin Martin admitted to being BlackCat/Alphv ransomware affiliates. They face charges for deploying ransomware against US victims.Source 8 The guilty pleas highlight internal threats from insiders.Source 8

10

Ransomware Hits Romania’s Oltenia Energy Complex

A ransomware attack on December 26 disrupted IT systems at Romania's largest coal power producer. Operations remain impacted, raising energy sector concerns.Source 2 This underscores persistent ransomware risks to infrastructure.Source 3

11

Hacker Leaks 2.3M WIRED Subscriber Records from Condé Nast

Hacker 'Lovely' claims breach of Condé Nast, leaking WIRED data and threatening 40M more records from other brands. Personal details are exposed.Source 2 Victims should monitor for identity theft.Source 2

12

China-Linked Mustang Panda Deploys ToneShell Backdoor

APT Mustang Panda used a signed kernel rootkit to load shellcode and deploy ToneShell in attacks. Targets include various organizations.Source 2 This reflects state-sponsored espionage trends.Source 2