Detection engineering teams released several new and updated detection rules across multiple platforms, including YARA, KQL, Fibratus, and Elastic, to address emerging threats. Notable additions include YARA rules for identifying VMware ESXi exploit payloads and the CoralWave loader, which masquerades as a Lenovo DLL to deploy Remcos RAT. Updates to Fibratus rules enhance detection of credential access, MS Office attack chains, and defense evasion techniques, while Elastic introduced a higher-order rule to correlate multiple EDR alerts from the same process tree, improving the identification of related malicious activities.
In parallel, recent malware and threat intelligence newsletters highlighted a range of active campaigns and vulnerabilities, such as DNS poisoning by Evasive Panda APT to deliver MgBot, supply chain attacks involving EmEditor and Trust Wallet, and the spread of the RondoDoX botnet exploiting React2Shell. Other reports covered the evolution of APTs like HoneyMyte and Mustang Panda, major data breaches, and the exploitation of critical vulnerabilities like MongoBleed. These updates underscore the rapidly evolving threat landscape and the need for continuous improvement in detection capabilities.

See real exploitation activity before you spend the cycle.
21 events from the most recent confirmed update back to the earliest known activity.
The newly added and updated detection content was made available through CTIChef’s MISP and STIX/TAXII feeds for downstream integration. This enabled broader automated threat detection and intelligence enrichment across security platforms.
Across five GitHub repositories, defenders added seven new detection rules and modified twenty-three existing ones during the December 29, 2025 to January 5, 2026 period. Updates included improved Fibratus coverage for credential access, Office attack chains, and defense evasion, plus an Elastic higher-order rule correlating multiple EDR alerts from the same process tree.
Between December 29, 2025 and January 5, 2026, detection engineers added new YARA rules covering VMware ESXi exploit payloads including MAESTRO, VSOCKpuppet, and MyDriver.sys, as well as the CoralWave loader that drops Remcos RAT. These rule additions expanded defender visibility into current malware and exploit activity.
Researchers reported phishing operations using Google Cloud infrastructure to help evade security detection. The tactic reflected continued abuse of legitimate cloud services by threat actors.
IBM issued a warning about a critical bug affecting API Connect. The alert signaled urgent risk for organizations using the platform.
Security reporting highlighted fresh Mustang Panda activity involving sophisticated malware deployment. The references frame this as part of ongoing APT operations observed in early January 2026.
Threat intelligence reporting said the RondoDoX botnet was weaponizing React2Shell. The development showed active adoption of a new exploitation technique by botnet operators.
Researchers reported that GlassWorm had developed new infrastructure focused on macOS targeting. This indicated an expansion or refinement of the group's capabilities against Mac users.
Security researchers highlighted the Kimwolf botnet as a notable malware threat in current reporting. The references identify it as an active botnet development during the period.
A supply-chain compromise involving EmEditor was reported to have distributed information-stealing malware to users. The incident underscored the continued risk posed by trusted software update channels.
Researchers identified a spearphishing campaign leveraging the npm registry to target U.S. and allied manufacturing and healthcare organizations. The activity suggested software ecosystem abuse to reach strategic sectors.
Threat reporting said the HoneyMyte APT expanded its capabilities with a kernel-mode rootkit and the ToneShell backdoor. This represented a notable technical evolution in the group's malware arsenal.
Researchers reported that Evasive Panda used DNS poisoning as part of a campaign to deliver the MgBot malware. The technique showed a sophisticated delivery method associated with the APT group.
Security reporting disclosed a data breach affecting Korean Air. The references did not provide further technical detail, but the breach was identified as a distinct incident.
A significant ransomware attack was reported against Romania’s Oltenia Energy Complex. The incident highlighted continued targeting of critical energy infrastructure.
Authorities arrested a Lithuanian suspect allegedly connected to KMSAuto malware activity. The arrest represented a concrete law-enforcement action tied to malware distribution.
French authorities opened an investigation into AI-generated 'undressing' deepfake content circulating on X. The case reflected growing law-enforcement attention to abusive generative-AI content.
A ransomware attack on Covenant Health was reported as impacting more than 478,000 individuals. The incident was notable for the large number of affected people and healthcare-sector impact.
A major data breach at Condé Nast was reported as affecting 2.3 million WIRED records, with an additional 40 million records potentially at risk. The disclosure elevated the scale of the incident significantly.
Security reporting said attackers were actively exploiting the MongoBleed flaw, tracked as CVE-2025-14847, in MongoDB. This marked the vulnerability as an in-the-wild threat rather than a theoretical issue.
Trust Wallet disclosed a second supply-chain compromise that resulted in the theft of cryptocurrency. Reported losses were described as between $7 million and $8.5 million across the referenced summaries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
detections-digest.rulecheck.io
Open sourcesecurityaffairs.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.