This cybersecurity brief for January 10, 2026, covers several critical developments. A sophisticated Chinese-linked threat actor was discovered exploiting a trio of VMware ESXi zero-days for more than a year before they were patched, enabling full VM escapes. The FBI has issued a warning about the North Korean Kimsuky APT using QR code phishing ('quishing') to bypass email security and steal credentials. Additionally, major data breaches have been disclosed by the Illinois Department of Human Services, affecting 700,000 residents, and online gambling firm BetVictor. CISA has also added a critical, actively exploited HPE OneView vulnerability to its KEV catalog, mandating urgent patching.
Help others stay informed about cybersecurity threats