HomeCybersecurity NewsNews roundup January 5, 2026
January 5, 2026

News roundup January 5, 2026

San Mateo, CA, January 5, 2026 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

ErrTraffic v2 commodifies ClickFix social engineering

Cybercrime analysts have uncovered ErrTraffic v2, a new commercial toolkit that industrializes ClickFix-style social engineering by tricking victims into manually executing malicious scripts. Promoted on Russian forums by an actor known as LenAI and sold for roughly $800, the service lowers the barrier for attackers to launch polished campaigns without deep technical skills. Researchers at Hudson Rock say ErrTraffic reflects a shift from exploit-driven attacks to psychological manipulation, using fake website errors and visual glitches to trick users into copying and pasting “verification commands” into Windows Run or PowerShell. Because the action appears to come from the user, the technique bypasses browser protections and many endpoint defenses. The platform includes a professional dashboard that tracks campaign performance and can deliver tailored payloads across Windows, macOS, Android, and Linux systems while leaving legitimate site content untouched. Read more.

Open-source tool exposes WhatsApp backup internals for researchers

Cybersecurity practitioners and researchers are increasingly using wa-crypt-tools. This open-source GitHub project enables encryption and decryption of WhatsApp and WhatsApp Business backups when users provide the required key material. The Python-based suite supports the .crypt12, .crypt14, and .crypt15 formats, converting end-to-end encrypted backups into readable SQLite databases or ZIP archives that contain chat history, media, and metadata. Developed by ElDavoo, the tool supports Protobuf for newer backup formats and is commonly paired with forensic frameworks such as whapa for deeper analysis. It can be run locally via pip or in Google Colab for quick browser-based testing, lowering the barrier to entry for non-specialists. Researchers use it to analyze mobile artifacts, disappearing messages, and backup integrity without bypassing WhatsApp’s encryption, since decryption is impossible without valid keys. Read more.

MongoBleed zero-day sparks emergency patch race

Cybersecurity teams are grappling with a high-severity information-disclosure vulnerability in MongoDB that is already being exploited in the wild. Tracked as CVE-2025-14847 and nicknamed MongoBleed, the flaw allows unauthenticated attackers to leak server memory from vulnerable MongoDB instances running default configurations, potentially exposing credentials or access tokens. MongoDB disclosed the issue on December 19, with concern escalating after a public proof of concept emerged days later. Researchers at Wiz estimate 42% of cloud environments contain at least one vulnerable MongoDB instance, while scans from Shadowserver and Censys show tens of thousands of exposed systems at risk. CISA has added the flaw to its catalog of known exploited vulnerabilities, though researchers say attribution remains unclear due to the lack of forensic artifacts. MongoDB is urging immediate upgrades as security teams work through limited holiday staffing. Read more.

Security insiders admit role in ALPHV BlackCat attacks

Two U.S. cybersecurity professionals have pleaded guilty in federal court for using their technical expertise to carry out ransomware attacks rather than prevent them. Ryan Goldberg of Georgia and Kevin Martin of Texas admitted to conspiracy to commit extortion through their involvement with the ALPHV BlackCat ransomware operation. Between April and December 2023, the pair worked with another conspirator to deploy the ransomware against multiple U.S. victims, agreeing to give ALPHV administrators 20 percent of ransom proceeds in exchange for access to the group’s infrastructure. After extorting one victim for roughly $1.2 million in Bitcoin, the attackers split their share and laundered the funds. Prosecutors say the case highlights the insider risk posed by trusted security professionals. Both men face up to 20 years in prison, with sentencing set for March 12, 2026. Read more.

GlassWorm shifts focus to macOS developer ecosystems

A fourth wave of the GlassWorm campaign is targeting macOS developers through malicious VS Code-compatible extensions hosted on OpenVSX and the Microsoft Visual Studio Marketplace. Researchers say the latest activity marks a shift from earlier Windows attacks, with the malware now using encrypted JavaScript payloads, AppleScript execution, and LaunchAgents for persistence. Once installed, the extensions delay execution to evade analysis and then attempt to steal GitHub, npm, and OpenVX credentials, browser data, Keychain passwords, and cryptocurrency wallet information. GlassWorm also checks for installed hardware wallet applications such as Ledger Live and Trezor Suite and attempts to replace them with trojanized versions. However, this feature is not yet fully functional. The campaign retains its Solana blockchain-based command and control infrastructure and overlaps with prior GlassWorm activity. Developers are urged to remove affected extensions immediately, rotate credentials, revoke tokens, and assess systems for compromise. Read more.

Agriculture sees fastest cyberattack growth of any U.S. sector

Cybercriminals are increasingly targeting the food production and agriculture sector as it modernizes and adopts more connected technologies. A new study from Check Point found that agriculture saw the most significant year-over-year increase in global cyberattacks, up 101 percent, with U.S. incidents rising 38 percent. “There is more and more modernization going on and continuing to grow — the computers in the field, and in manufacturing and transport,” researcher Omer Dembinsky said. “And it’s not something that has a lot of security and safety guards like bank institutions or the government.” While large attacks on companies like Ahold Delhaize USA and United Natural Foods draw headlines, experts warn that small and mid-size farmers are also frequent victims of phishing and payment diversion scams. Lawmakers have introduced multiple bipartisan bills to strengthen agricultural cybersecurity through research centers, grants, and crisis simulations, as universities expand their focus on protecting the food supply from digital threats. Read more.

New Shai Hulud variant resurfaces on npm supply chain

Cybersecurity researchers have identified what appears to be a new strain of the Shai Hulud malware on the npm registry, suggesting continued experimentation by the original operators rather than copycat activity. The package, @vietmoney/react-big-calendar, was first published in 2021 and was updated in late December 2025 to include obfuscated malicious code that could steal API keys, cloud credentials, and npm and GitHub tokens. While downloads remain limited and no widespread infections have been observed, researchers say the changes indicate access to the original worm source code. Shai Hulud’s most dangerous capability remains intact, allowing stolen npm tokens to be weaponized to trojanize up to 100 other popular packages in a worm-like fashion. Read more.

IBM API Connect auth bypass flaw enables remote compromise

IBM has urged customers to immediately patch a critical authentication-bypass vulnerability in its API Connect enterprise platform, which could allow unauthenticated attackers to remotely access exposed applications. Tracked as CVE-2025-13915 and rated 9.8 out of 10 in severity, the flaw affects IBM API Connect versions 10.0.11.0 and 10.0.8.0 through 10.0.8.5. Successful exploitation allows threat actors to bypass authentication without user interaction using low-complexity attacks. API Connect is widely deployed across banking, healthcare, retail, and telecommunications environments, increasing potential impact. IBM is advising administrators to upgrade to the latest release and has provided mitigation guidance for organizations unable to apply fixes immediately, including disabling self-service sign-up on the Developer Portal. The disclosure comes amid ongoing scrutiny of IBM vulnerabilities, several of which have previously been added to CISA’s Known Exploited Vulnerabilities Catalog and linked to ransomware activity. Read more.

Hacker alleges breach of millions of Condé Nast user accounts

A threat actor using the alias “Lovely” has leaked what they claim is personal data belonging to more than 2.3 million Wired.com users, raising concerns about a potentially much larger breach across Condé Nast properties. The data was posted on December 20, 2025, to a new hacking forum called Breach Stars, alongside accusations that Condé Nast ignored repeated warnings about vulnerabilities in its systems. The leaked records include names, email addresses, user IDs, display names, and account timestamps, with some entries containing last-session data. While no passwords or payment details appear to be exposed, the presence of confirmed email addresses and persistent identifiers makes the dataset sensitive and credible. The hacker also claims access to more than 40 million accounts associated with brands such as Vogue, GQ, The New Yorker, and others, suggesting a centralized identity platform may be involved. Condé Nast has not confirmed the breach, and verification efforts are ongoing. Read more.

MongoDB vulnerability exploitation escalates as exposed databases mount

A critical MongoDB vulnerability is now being actively exploited, exposing tens of thousands of databases to potential data leakage. Tracked as CVE-2025-14847 with a CVSS score of 8.7 and dubbed MongoBleed, the flaw stems from improper handling of zlib compression in MongoDB Server. By sending malformed compressed packets before authentication, attackers can access uninitialized memory and leak fragments of sensitive data, including user details, passwords, and API keys. “The affected logic returned the allocated buffer size (output.length()) instead of the actual decompressed data length, allowing undersized or malformed payloads to expose adjacent heap memory,” security researchers Merav Bar and Amitai Cohen said. “Because the vulnerability is reachable prior to authentication and does not require user interaction, Internet-exposed MongoDB servers are particularly at risk.” Censys identified over 87,000 potentially exposed instances globally. MongoDB urges immediate patching or disabling zlib compression. Read more.

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles