This cybersecurity brief for January 10, 2026, covers several critical developments. A sophisticated Chinese-linked threat actor was discovered exploiting a trio of VMware ESXi zero-days for more than a year before they were patched, enabling full VM escapes. The FBI has issued a warning about the North Korean Kimsuky APT using QR code phishing ('quishing') to bypass email security and steal credentials. Additionally, major data breaches have been disclosed by the Illinois Department of Human Services, affecting 700,000 residents, and online gambling firm BetVictor. CISA has also added a critical, actively exploited HPE OneView vulnerability to its KEV catalog, mandating urgent patching.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.