January 3, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

Welcome to 2026. So far it has been relatively quiet, unless you’re using a specific brand of Chinese network equipment, or SmarterMail. Otherwise, it has been a steady stream of new malware, exploits, and breaches to start the new year. We’ve got news to get to, so onward.

Headline NEWS:

  • IBM API Connect is used for managing the API lifecycle. And a critical defect has been found in it that can enable a threat actor to remotely access applications, bypassing authentication. If you use this in your enterprise anywhere, patch this quickly. If you can’t patch now, IBM does offer some mitigation guidance on their alert page.
  • SmarterMail is a collaboration suite similar to Microsoft Exchange. It has been shown to have a critical defect that is triggered via a file upload, requiring no user interaction or authentication. If successful, a threat actor could gain code execution access. Update to the latest version to fix this flaw.
  • X-Speeder Networking is a Chinese based maker of network hardware such as SD-WAN appliances, edge routers, and smart TV controllers. A critical remote code execution (RCE) defect was found in the django-based web application by pwn.ai that can enable a threat actor to bypass security without any authentication. Disturbingly, X-Speeder has not responded to bug reports despite being given seven months to do so prior to this being made public. Maybe the Chinese haven’t had time to fully exploit all of the X-Speeder connected networks yet. Perhaps they’ll fix the defect afterward. In the meanwhile, if you’re using their gear, replace it.
  • US Cybersecurity pros admit to moonlighting as ransomware scum. I couldn’t write that any better. There should be a toasty place in hades reserved for people that violate the public trust in such an egregious manner. I’m truly heartened to see that they were caught and prosecuted. Sadly, the people and companies that these dirtbags affected in their terror campaign may never be the same again.

In Ransomware, Malware, and Vulnerabilities News:

  • 2025 retrospectives and 2026 prognostication. There are about half a dozen links to articles regarding risks in 2025, top AI attacks, year in review, biggest attacks stories, and new tech laws for 2026 along with predictions for the future. They are worth reading to get a good overarching view of our industry’s prior year and upcoming changes. As the axiom says, if you don’t learn from the past, you’re doomed to repeat it.

In Other News Events of Note and Interest:

  • CES is coming next week. And already there are plenty of leaks and pre-announcements of products and technology that will debut at this colossal showcase in Las Vegas. Some early reports are AI everything, which is pretty much a repeat of last year, but also news of new display technology, larger screens, bio-mechanical assistive technologies, real-time translation tech, and more. It sounds like fun!

Musings:

We’re three days into 2026. The pages of this year should still be mostly blank, with perhaps a few short words or sentences penned. What do your opening lines look like? Is yours, “There was no possibility of a walk that day…” or “It was a dark and stormy day…” or perhaps, “There was nary a cloud in the sky on that bright sunlit morning, save for a few puffy wisps on the horizon. Were they harbingers of coming mayhem, or the heralds of much needed life-giving gentle rain?” Do you see a theme here? Sometimes the interpretation of the events of our lives is a matter of the author’s perspective, and you are the author. Will your 2026 epic be one of whirlwind and chaos, or will you turn what was intended by the hordes of evil for your harm into something good and useful? Like much needed rain falling on parched ground, it can bring a flood or slake the soil’s thirst and bring life. Which will it be? I, for one, say that this is indeed the bright dawn of a new year, let’s make it a good one, and never forget…

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with: