Latest Internet & Cybersecurity News

📅January 6, 2026 at 1:00 PM
Latest cybersecurity news highlights ongoing breaches from LastPass, ransomware attacks, state-sponsored hacks, supply chain compromises, and rising AI/quantum threats in early 2026.
1

LastPass 2022 Breach Fuels New Crypto Thefts

Blockchain investigators on January 2, 2026, traced high-value cryptocurrency thefts to the 2022 LastPass data breach.Source 1 Attackers continue exploiting stolen data for ongoing thefts. Businesses are urged to monitor for related activity.Source 1

2

GlassWorm Malware Targets macOS Developers

A new GlassWorm campaign detected January 1, 2026, uses malicious VSCode and OpenVSX extensions to deliver trojanized crypto wallets.Source 1 It exfiltrates seed phrases and session tokens from development environments. Firms should enforce extension whitelisting and EDR monitoring.Source 1

3

Inotiv Pharma Suffers Ransomware Attack

Pharma research firm Inotiv faced a late December 2025 ransomware attack, stealing data of nearly 10,000 individuals including SSNs.Source 1 Attackers accessed internal systems for extortion potential. This underscores risks in sensitive R&D sectors.Source 1

4

Over 10,000 Fortinet Firewalls Vulnerable to 2FA Bypass

A January 2, 2026 report shows 10,000+ exposed Fortinet firewalls unpatched against a five-year-old 2FA flaw.Source 1 Threat actors scan and exploit for network access. Patches available but adoption lags.Source 1

5

Silk Typhoon Targets US Congressional Budget Office

Chinese group Silk Typhoon exfiltrated emails and policy data from US CBO in late December 2025 campaign.Source 1 Highlights APT focus on government intellectual property. Organizations need anti-phishing defenses.Source 1

6

Trust Wallet Chrome Extension Hacked via Shai-Hulud Attack

Trust Wallet's extension hack stole $8.5M, linked to November 2025 Shai-Hulud supply chain attack with prep since December 8.Source 2 Second iteration compromised the extension. Users advised to update and monitor wallets.Source 2

7

DarkSpectre Compromises 8.8M Browser Users

Chinese group DarkSpectre ran seven-year malware campaign via Chrome, Edge, Firefox, Opera extensions affecting 8.8M users.Source 2 Targets across Asia, US, Europe. Immediate extension audits recommended.Source 2

8

Zestix Breaches 50 Orgs Using Stolen Cloud Credentials

Criminal Zestix stole data from 50 enterprises via infostealer-compromised credentials on MFA-less ShareFile, Nextcloud.Source 4 Victims include utilities, aviation; data sold on dark web. Highlights credential hygiene failures.Source 4

9

Handala Team Hacks Telegram of Israeli Officials

Pro-Iranian Handala group breached Telegram accounts of Naftali Bennett and Tzachi Braverman.Source 2 Used for potential info ops. Raises risks for high-profile targets on messaging apps.Source 2

10

Mustang Panda Deploys TONESHELL Backdoor with Rootkit

Chinese Mustang Panda used undocumented kernel rootkit to deliver TONESHELL backdoor in mid-2025 Asia attack.Source 2 Evades detection effectively. Defenders need advanced kernel monitoring.Source 2

11

AI and Quantum Threats to Define 2026 Cybersecurity

Thales predicts AI security as formal discipline with agent-governance layers; quantum-safe migration mandatory.Source 3 Zero-days weaponized in minutes via AI. Enterprises must invest in API scrutiny and PQC.Source 3

12

Sedgwick Confirms Cyber Incident on Federal Subsidiary

Sedgwick Government Solutions subsidiary hit by cyber incident confirmed January 5, 2026.Source 8 Affects major federal contractor operations. Details on impact pending investigation.Source 8

Latest Internet & Cybersecurity News | DeckBook AI