Zero Day Wire

Microsoft and Global Police Disrupt RedVDS, a Scaled Engine Behind Massive BEC Fraud

Threats

Microsoft and Global Police Disrupt RedVDS, a Scaled Engine Behind Massive BEC Fraud

A coordinated operation led by Microsoft and international law enforcement has dismantled RedVDS, a major infrastructure provider behind large-scale business email compromise (BEC) fraud worldwide. RedVDS functioned as a low-cost, subscription-based cybercrime service, offering criminals disposable virtual machines that appeared online as legitimate Windows systems. These rented environments allowed attackers

By Zero Day Wire
Microsoft January 2026 Patch Tuesday: 114 Vulnerabilities Fixed Including 3 Zero-Days

Alerts

Microsoft January 2026 Patch Tuesday: 114 Vulnerabilities Fixed Including 3 Zero-Days

Microsoft's first Patch Tuesday of 2026 addresses 114 security vulnerabilities across Windows, Office, and related services. The release includes 12 critical-severity flaws and patches for three zero-day vulnerabilities. By the Numbers Zero-Days Patched Three zero-day vulnerabilities were addressed in this release: * CVE-2026-20805 - Desktop Window Manager information disclosure

By Zero Day Wire
China-Linked Hackers Deploy Custom Linux Malware Against Telecoms in Espionage Campaign

Threats

China-Linked Hackers Deploy Custom Linux Malware Against Telecoms in Espionage Campaign

A newly attributed China-nexus threat actor designated UAT-7290 has been conducting espionage operations against telecommunications providers in South Asia and organizations in Southeastern Europe since at least 2022. According to research published recently by Cisco Talos, the group employs a sophisticated multi-stage attack chain combining open-source tools, custom malware, and

By Zero Day Wire
MuddyWater Escalates Espionage Campaigns With New Rust-Based Malware “RustyWater”

Threats

MuddyWater Escalates Espionage Campaigns With New Rust-Based Malware “RustyWater”

An Iran-linked threat actor known as MuddyWater has been linked to a newly identified spear-phishing campaign targeting diplomatic, maritime, financial, and telecommunications organizations across the Middle East. The operation deploys a Rust-based remote access trojan (RAT) dubbed RustyWater, signaling a continued evolution in the group’s malware development strategy. According

By Zero Day Wire