Multiple cybersecurity newsletters published in early January 2026 provide overviews of significant global security events, threat actor activity, and malware campaigns. The Security Affairs newsletters highlight a range of incidents, including a massive breach affecting 17.5 million Instagram users, North Korea-linked Kimsuky APT quishing attacks, a data breach at the Illinois Department of Human Services, and the exploitation of ESXi zero-days by Chinese-speaking hackers. Other notable topics include the spread of the Astaroth banking Trojan via WhatsApp in Brazil, critical vulnerabilities in D-Link DSL routers and Veeam, and intensified attacks on Taiwan’s critical infrastructure by China-linked groups. The newsletters also discuss technical developments such as the use of Pyarmor for obfuscation in the VVS Discord Stealer, malicious npm packages delivering NodeCordRAT, and the Boto-Cor-de-Rosa campaign.
Sherpa Intelligence’s "Five for Friday" newsletter similarly aggregates key security news, referencing the Resecurity report on cyber counterintelligence operations against the "Shiny Hunters" group and highlighting ongoing challenges in law enforcement collaboration. The newsletter also covers sector-specific risks, such as cybersecurity gaps in the Water and Wastewater Services sector, and updates on the OWASP Top 10 for 2025. Collectively, these newsletters serve as comprehensive roundups of the week’s most impactful cybersecurity developments, providing CISOs and security teams with a broad situational awareness of current threats, vulnerabilities, and industry trends.

See which actors are running it and whether you're in range.
19 events from the most recent confirmed update back to the earliest known activity.
CNCERT issued a risk warning that the Black Cat gang was using search engines to push counterfeit Notepad++ downloads that installed remote-control backdoors. The warning was cited in Security Affairs' malware roundup on January 11, 2026.
Researchers reported malicious NPM packages being used to deliver NodeCordRAT. The software supply chain threat was included in both Security Affairs roundups on January 11, 2026.
A Python-based malware dubbed VVS Stealer was reported targeting Discord credentials and using PyArmor for obfuscation. The malware was featured in Security Affairs' January 11, 2026 newsletters.
Threat actors were reported using fake Booking.com lures and fake blue-screen crash pages to distribute DCRat and related malware against the European hospitality sector. The campaign was referenced across Security Affairs' January 11, 2026 coverage.
Security researchers reported Astaroth-related activity spreading in Brazil through a WhatsApp-based worm, also described alongside the Boto-Cor-de-Rosa campaign. The activity was covered in Security Affairs' January 11, 2026 newsletters.
China-linked activity tracked as UAT-7290 was reported targeting telecommunications organizations in South Asia and Europe with modular malware. The campaign appeared in both Security Affairs roundups published on January 11, 2026.
North Korea-linked Kimsuky was reported conducting 'quishing' attacks that used malicious QR codes to target victims. The campaign was highlighted in Security Affairs' January 11, 2026 roundup.
CISA added vulnerabilities affecting HPE OneView and Microsoft Office PowerPoint to its Known Exploited Vulnerabilities catalog. The additions were reported in Security Affairs' January 11, 2026 newsletter.
A critical remote code execution vulnerability in legacy D-Link DSL routers was reported as being actively exploited. Security Affairs included the exploitation warning in its January 11, 2026 roundup.
Veeam addressed a critical remote code execution flaw rated CVSS 9.0. The fix was noted as a key defensive development in the January 11, 2026 newsletter.
Trend Micro released fixes for a remote code execution vulnerability affecting Apex Central. The remediation was highlighted in Security Affairs' January 11, 2026 vulnerability roundup.
Security Affairs reported that Sedgwick suffered a breach tied to a TridentLocker ransomware attack. The incident was listed as a significant breach development in the January 11, 2026 newsletter.
A breach at the Illinois Department of Human Services was reported as affecting about 700,000 individuals. The incident was included among the week's major data exposure events in Security Affairs' January 11, 2026 roundup.
Security Affairs reported an alleged exposure involving 17.5 million Instagram users. The item appeared as one of the major breach stories in its January 11, 2026 newsletter.
Reports cited in the weekly roundup said the U.S. administration was pulling out of several international cyber-related organizations. The move was presented as a significant geopolitical cyber policy development.
Reporting during the week of January 5–9, 2026 said proposed U.S. water and wastewater cybersecurity legislation still left major gaps because it did not impose mandatory requirements. Critics warned this could weaken sustained security investment despite rising threats.
A threat actor reportedly offered for sale a large internal dataset allegedly stolen from Pickett and Associates, LLC, an engineering firm serving U.S. utility companies. The alleged breach was highlighted in Sherpa Intelligence's January 2026 roundup.
Russia-linked activity tracked as UAC-0184 was reported using Viber messaging to spy on Ukrainian military targets during 2025. The campaign was later referenced in January 2026 security roundups.
OWASP published its 2025 update to the Top 10 for LLM Applications, emphasizing risks such as supply chain issues, exposed secrets, and misconfigurations. The update was cited in the January 5–9, 2026 roundup as a notable development.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityaffairs.com
Open sourcesherpaintelligence.substack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.