THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Coordinated Cyberattacks Hit Polish Energy and Industrial Facilities

CERT Polska disclosed that on December 29, 2025, coordinated cyberattacks targeted more than 30 wind and solar farms, a manufacturing firm, and a major combined heat and power plant serving nearly 500,000 people. Reported disruptions to communications with industrial assets highlight growing risks to energy-sector OT/IoT environments and remote management channels.

Source: The Hacker News


eScan Antivirus Supply-Chain Incident Pushes Malware via Update Server

Attackers compromised a MicroWorld Technologies update server and delivered a malicious file to eScan antivirus customers. The breach underscores the high leverage of trusted update channels in software supply-chain attacks and the need to verify update integrity and hunt for post-compromise activity.

Source: SecurityWeek


Mandiant: ShinyHunters-Style Vishing Steals MFA to Breach SaaS

Mandiant reports expanded campaigns using advanced voice phishing and realistic credential-harvesting sites to capture MFA and break into SaaS platforms. By targeting identity and exploiting real-time social engineering, attackers are bypassing MFA prompts and gaining persistence across cloud apps.

Source: The Hacker News


FBI Seizes RAMP, a Ransomware-Friendly Cybercrime Forum

The FBI has taken RAMP offline, a forum that openly allowed ransomware activity and boasted over 14,000 active users. The seizure likely yields valuable intelligence on operators and affiliates and could drive further disruptions as criminal communities regroup.

Source: Graham Cluley


Iran-Linked “RedKitten” Targets NGOs and Activists in Surveillance Campaign

HarfangLab observed a Farsi-speaking actor aligned with Iranian state interests conducting a January 2026 campaign—dubbed RedKitten—against NGOs and individuals documenting human rights abuses. Coinciding with late-2025 unrest, the operation appears focused on credential theft and monitoring of civil society.

Source: The Hacker News


U.S. Seizes $400M Tied to Helix Dark Web Crypto Mixer

U.S. authorities seized more than $400 million in cryptocurrency, cash, and property linked to Helix, a darknet bitcoin mixing service popular with drug markets. The move signals sustained pressure on mixers facilitating money laundering for cybercrime, raising compliance stakes for exchanges and other VASPs.

Source: HackRead


Windows Malware Uses Pulsar RAT for Live Chats While Stealing Data

Researchers warn of Windows malware leveraging Pulsar RAT to open live chat sessions with victims while exfiltrating data in the background. The high-touch tactic blends social engineering with active intrusion to speed privilege gains and persistence.

Source: HackRead


You May Also Be Interested In...
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flaw
Vulnerability & Patch Roundup — January 2026 (WordPress)
After TikTok: Navigating the Complex Web of Foreign Tech Bans
Cybersecurity — February 1, 2026 | Briefing24