Latest Internet & Cybersecurity News

đź“…January 5, 2026 at 1:00 AM
Critical cybersecurity developments include AI agents as insider threats, major data breaches at Korean Air and ASUS, ransomware attacks, cable sabotage suspicions, and stock surges in 2026.
1

Finnish Authorities Seize Ship After Undersea Internet Cable Severed Between Finland and Estonia

Authorities detained the cargo ship Fitburg and two crew members following a sudden break in the internet cable linking Finland and Estonia, raising sabotage concerns.Source 2 Investigations are ongoing to determine if the damage was intentional.Source 2

2

Palo Alto Networks Warns AI Agents Are 2026's Biggest Insider Threat

Palo Alto Networks' security chief predicts AI agents will become major insider risks due to prompt injection and tool misuse vulnerabilities.Source 3 By end-2026, 40% of enterprise apps may integrate AI agents, enabling attacks like unauthorized transfers.Source 3 Security teams face pressure to secure rapid deployments.Source 3

3

Korean Air Confirms Data Breach Leaking 30,000 Employee Records by Cl0p Ransomware

Cl0p ransomware group leaked data of 30,000 Korean Air employees after hacking a catering partner, confirming the breach.Source 2Source 5Source 6 The attack exploited a vulnerability in Oracle Enterprise Business Suite.Source 6 Korean Air disclosed the incident affecting staff records.Source 5

4

ShinyHunters Claim Resecurity Breach Debunked as Honeypot Trap

Threat actor ShinyHunters claimed to breach US firm Resecurity, but the company revealed it was a honeypot with fake data, no real systems compromised.Source 2 Resecurity issued clarifications denying any customer data loss.Source 2 This highlights ongoing cat-and-mouse games in breach claims.Source 2

5

CrowdStrike, Palo Alto, Fortinet Top Cybersecurity Stocks to Watch in 2026

MarketBeat identifies CrowdStrike, Palo Alto Networks, and Fortinet as leading cybersecurity stocks due to high trading volume and sector growth.Source 1 These firms offer cloud security, firewalls, and converged networking solutions amid rising threats.Source 1 Investors note defensive demand despite breach and regulatory risks.Source 1

6

RondoDox Botnet Exploits React2Shell to Hijack 90,000+ Unpatched Devices

RondoDox botnet targets Next.js React2Shell flaw to infect routers, smart cameras, and business sites with miners and malware.Source 2 Over 90,000 devices are vulnerable to these attacks.Source 2 Organizations urged to patch immediately.Source 2

7

Everest Ransomware Leaks 1TB of Stolen ASUS Data

Everest ransomware group released 1TB of sensitive data stolen from ASUS, following claims reported in December 2025.Source 2 The leak underscores ongoing supply chain risks for hardware firms.Source 2 ASUS has not detailed response measures.Source 2

8

Two US Cybersecurity Experts Plead Guilty in ALPHV/BlackCat Ransomware Extortion

Two US-based cybersecurity professionals admitted guilt for affiliating with ALPHV/BlackCat ransomware in a federal extortion scheme.Source 2Source 4Source 5 The case raises trust issues in the cybersecurity industry.Source 4 They face significant penalties.Source 2

9

China-Linked Mustang Panda Deploys ToneShell Backdoor via Signed Rootkit

APT group Mustang Panda (HoneyMyte) uses signed kernel-mode rootkit to deliver ToneShell backdoor, evading Microsoft Defender.Source 2Source 4 Targets include governments in Europe and US since 2012.Source 4 New attacks blind security tools.Source 2

10

Thousands of Adobe ColdFusion Servers Targeted in Holiday Exploit Campaign

GreyNoise detected coordinated attacks exploiting a dozen ColdFusion vulnerabilities during Christmas 2025, with thousands of attempts.Source 4Source 5 Servers remain at high risk from unpatched flaws.Source 4 Rapid patching recommended.Source 5

11

Trust Wallet Chrome Extension Hacked in Second Shai-Hulud Supply-Chain Attack

Trust Wallet confirms a supply-chain attack compromised its Chrome extension, leading to $8.5M crypto theft.Source 4Source 5 Attackers independently developed malware for the breach.Source 4 Users advised to update and monitor wallets.Source 5

12

Xspeeder Router Firmware Flaw CVE-2025-54322 Enables Perfect 10 RCE

Pwn.ai disclosed a CVSS 10.0 pre-auth RCE zero-day in Xspeeder SXZOS firmware, found via AI agent, ignored by vendor for 7 months.Source 6 Attackers can gain full device control remotely.Source 6 First public AI-discovered hardware vuln disclosure.Source 6