no alarms and no surprises please..
-
Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys
Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI’s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million “users.” Researchers revealed an exposed database misconfiguration…
-
Essential E-Signature Solutions for Cybersecurity in 2026
Essential E-Signature Solutions for Cybersecurity in 2026 E-signatures are now part of your security posture. In 2026, most organizations sign contracts, approvals, onboarding packets, and financial documents electronically. That increases exposure to account takeover, identity theft, document tampering, and audit gaps especially when teams rely on weak methods like a pasted signature image or email-only…
-
AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems
AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems AutoPentestX, an open-source automated penetration testing toolkit for Linux systems, enables comprehensive security assessments from a single command. Developed by Gowtham Darkseid and released in November 2025, it generates professional PDF reports while emphasizing safe, non-destructive testing. AutoPentestX targets Kali Linux, Ubuntu, and Debian-based distributions,…
-
This month in security with Tony Anscombe – January 2026 edition
This month in security with Tony Anscombe – January 2026 edition The trends that emerged in January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year Go to eset
-
DynoWiper update: Technical analysis and attribution
DynoWiper update: Technical analysis and attribution ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector Go to eset
-
Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists
Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists A Farsi-speaking threat actor aligned with Iranian state interests is suspected to be behind a new campaign targeting non-governmental organizations and individuals involved in documenting recent human rights abuses. The activity, observed by HarfangLab in January 2026, has been codenamed RedKitten. It’s said to coincide…
-
Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms
Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms Google-owned Mandiant on Friday said it identified an “expansion in threat activity” that uses tradecraft consistent with extortion-themed attacks orchestrated by a financially motivated hacking group known as ShinyHunters. The attacks leverage advanced voice phishing (aka vishing) and bogus credential harvesting sites mimicking targeted…
-
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms CERT Polska, the Polish computer emergency response team, revealed that coordinated cyber attacks targeted more than 30 wind and photovoltaic farms, a private company from the manufacturing sector, and a large combined heat and power plant (CHP) supplying heat to almost half a…
-
FBI takes notorious RAMP ransomware forum offline
FBI takes notorious RAMP ransomware forum offline The FBI has seized control of RAMP, a notorious cybercrime online forum that bragged to be the only place that allowed ransomware, and boasted over 14,000 active users. Now some of those users’ details are likely to be in the hands of the police… Read more in my…
-
Torq Moves SOCs Beyond SOAR With AI-Powered Hyper Automation
Torq Moves SOCs Beyond SOAR With AI-Powered Hyper Automation Investors poured $140 million into Torq’s Series D Round, bringing the startup’s valuation to $1.2 billion, to bring AI-based “hyper automation” to SOCs. Jeffrey Schwartz Go to gbhackers.com
-
TAMECAT PowerShell Backdoor Targets Edge and Chrome: Login Credentials At Risk
TAMECAT PowerShell Backdoor Targets Edge and Chrome: Login Credentials At Risk TAMECAT is a sophisticated PowerShell-based backdoor linked to APT42, an Iranian state-sponsored hacking group. It steals login credentials from Microsoft Edge and Chrome browsers… Go to gbhackers.com
-
Over 200 Magento Stores Compromised In Rootkit Rampage via Zero-Day Exploit
Over 200 Magento Stores Compromised In Rootkit Rampage via Zero-Day Exploit A dangerous wave of attacks exploiting CVE-2025-54236, dubbed “SessionReaper,” in Magento e-commerce platforms. This vulnerability lets attackers bypass authentication by reusing invalid session tokens, paving… Go to gbhackers.com
-
Hugging Face Repositories Hijacked For Android RAT Delivery, Bypassing Traditional Defenses
Hugging Face Repositories Hijacked For Android RAT Delivery, Bypassing Traditional Defenses A sophisticated Android RAT campaign that exploits Hugging Face’s popular machine learning platform to host and distribute malicious payloads. Attackers combine social engineering, legitimate infrastructure… Go to gbhackers.com
-
GhostChat Spyware Targets Android Users Through WhatsApp, Steals Sensitive Data
GhostChat Spyware Targets Android Users Through WhatsApp, Steals Sensitive Data A sneaky Android spyware called GhostChat, which tricks Pakistan-based users with romance scams via WhatsApp. The malware grabs sensitive data like contacts, photos, and files… Go to gbhackers.com
-
Threat Actors Hide Behind School-Themed Domains In Newly Uncovered Bulletproof Infrastructure
Threat Actors Hide Behind School-Themed Domains In Newly Uncovered Bulletproof Infrastructure A sophisticated traffic distribution system (TDS) hiding behind education-themed domains. The operation uses bulletproof hosting to deliver phishing pages, scams, and malware files. Analysts triaged… Go to gbhackers.com
-
Crypto wallets received a record $158 billion in illicit funds last year
Crypto wallets received a record $158 billion in illicit funds last year Illegal cryptocurrency flows hit a record $158 billion in 2025, reversing a three-year trend of declining amounts from $86B in 2021 to $64B in 2024. […] Bill Toulas Go to bleepingcomputer
-
Microsoft to disable NTLM by default in future Windows releases
Microsoft to disable NTLM by default in future Windows releases Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Operation Switch Off dismantles major pirate TV streaming services
Operation Switch Off dismantles major pirate TV streaming services The latest phase of the global law enforcement action resulted in seizing three industrial-scale illegal IPTV services. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes Outlook bug blocking access to encrypted emails
Microsoft fixes Outlook bug blocking access to encrypted emails Microsoft has fixed a known issue that prevented Microsoft 365 customers from opening encrypted emails in classic Outlook after a recent update. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5074105 update fixes boot, sign-in, and activation issues
Windows 11 KB5074105 update fixes boot, sign-in, and activation issues Microsoft has released the KB5074105 preview cumulative update for Windows 11 systems, which includes 32 changes, including fixes for sign-in, boot, and activation issues. […] Sergiu Gatlan Go to bleepingcomputer
-
SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations
SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control and data acquisition infrastructure widely deployed across automotive, energy, and manufacturing sectors. Vulnerability Overview CVE-2025-0921 stems from…
-
Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail
Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules directed at FreePBX, alongside…
-
UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS
UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims in Thailand and…
-
175,000 Exposed Ollama Hosts Enable Code Execution and External System Access
175,000 Exposed Ollama Hosts Enable Code Execution and External System Access A significant security discovery reveals that approximately 175,000 Ollama servers remain publicly accessible across the internet, creating a serious risk for widespread code execution and unauthorized access to external systems. Ollama, an open-source framework designed to run artificial intelligence models locally, has become unexpectedly…
-
TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome
TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part of espionage campaigns conducted by APT42, an Iranian state-sponsored cyber-espionage group that has been…
-
TR-26-0010 (Kodmatic Bilgisayar Yazılım – Online Sınav ve Ölçme Değerlendirme Güvenlik Bildirimi)
TR-26-0010 (Kodmatic Bilgisayar Yazılım – Online Sınav ve Ölçme Değerlendirme Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0009 (Coderiapp İnovasyon ve Yazılım Teknolojileri – HeyGarson Güvenlik Bildirimi)
TR-26-0009 (Coderiapp İnovasyon ve Yazılım Teknolojileri – HeyGarson Güvenlik Bildirimi) Go to usom.gov
-
Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access
Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access Cybersecurity researchers have discovered malicious Google Chrome extensions that come with capabilities to hijack affiliate links, steal data, and collect OpenAI ChatGPT authentication tokens. One of the extensions in question is Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj), which claims to be a tool to browse…
-
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware Cybersecurity researchers have discovered a new campaign attributed to a China-linked threat actor known as UAT-8099 that took place between late 2025 and early 2026. The activity, discovered by Cisco Talos, has targeted vulnerable Internet Information Services (IIS) servers located across Asia, but with…
-
Badges, Bytes and Blackmail
Badges, Bytes and Blackmail Behind the scenes of law enforcement in cyber: what do we know about caught cybercriminals? What brought them in, where do they come from and what was their function in the crimescape? Introduction: One view on the scattered fight against cybercrime The growing sophistication and diversification of cybercrime have compelled law…
-
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup A former Google engineer accused of stealing thousands of the company’s confidential documents to build a startup in China has been convicted in the U.S., the Department of Justice (DoJ) announced Thursday. Linwei Ding (aka Leon Ding), 38, was convicted by a federal…
-
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score SmarterTools has addressed two more security flaws in SmarterMail email software, including one critical security flaw that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-24423, carries a CVSS score of 9.3 out of 10.0. “SmarterTools SmarterMail versions prior to build 9511 contain…
-
Friday Squid Blogging: New Squid Species Discovered
Friday Squid Blogging: New Squid Species Discovered A new species of squid. pretends to be a plant: Scientists have filmed a never-before-seen species of deep-sea squid burying itself upside down in the seafloor—a behavior never documented in cephalopods. They captured the bizarre scene while studying the depths of the Clarion-Clipperton Zone (CCZ), an abyssal plain…
-
AIs Are Getting Better at Finding and Exploiting Security Vulnerabilities
AIs Are Getting Better at Finding and Exploiting Security Vulnerabilities From an Anthropic blog post: In a recent evaluation of AI models’ cyber capabilities, current Claude models can now succeed at multistage attacks on networks with dozens of hosts using only standard, open-source tools, instead of the custom tools needed by previous generations. This illustrates…
-
Google Presentations Abused for Phishing, (Fri, Jan 30th)
Google Presentations Abused for Phishing, (Fri, Jan 30th) Charlie, one of our readers, has forwarded an interesting phishing email. The email was sent to users of the Vivladi Webmail service. While not overly convincing, the email is likely sufficient to trick a non-empty group of users: The e-mail gets more interesting as the user clicks…
-
2026: The Year Agentic AI Becomes the Attack-Surface Poster Child
2026: The Year Agentic AI Becomes the Attack-Surface Poster Child Dark Reading asked readers whether agentic AI attacks, advanced deepfake threats, board recognition of cyber as a top priority, or password-less technology adoption would be most likely to become a trending reality for 2026. Tara Seals Go to gbhackers.com
-
Tenable Tackles AI Governance, Shadow AI Risks, Data Exposure
Tenable Tackles AI Governance, Shadow AI Risks, Data Exposure The Tenable One AI Exposure add-on discovers unsanctioned AI use in the organization and enforces policy compliance with approved tools. Jeffrey Schwartz Go to gbhackers.com
-
OpenClaw AI Runs Wild in Business Environments
OpenClaw AI Runs Wild in Business Environments The popular open source AI assistant (aka ClawdBot, MoltBot) has taken off, raising security concerns over its privileged, autonomous control within users’ computers. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Open Directory Exposure Leaks BYOB Framework Across Windows, Linux, and macOS
Open Directory Exposure Leaks BYOB Framework Across Windows, Linux, and macOS An exposed command-and-control server hosting a complete deployment of the BYOB (Build Your Own Botnet) framework, a sophisticated post-exploitation tool targeting Windows, Linux, and… Go to gbhackers.com
-
BlackIce Introduced as Container-Based Red Teaming Toolkit for AI Security Testing
BlackIce Introduced as Container-Based Red Teaming Toolkit for AI Security Testing Databricks introduced BlackIce at CAMLIS Red 2025, an open-source containerized toolkit that consolidates 14 widely-used AI security tools into a single, reproducible environment. This… Go to gbhackers.com
-
Swarmer Tool Abuses Windows Registry to Evade Detection and Persist on Systems
Swarmer Tool Abuses Windows Registry to Evade Detection and Persist on Systems Swarmer, a sophisticated tool designed to manipulate Windows registry hives while bypassing endpoint detection systems. The tool exploits legacy Windows infrastructure to achieve persistent… Go to gbhackers.com
-
Fake “Mac Cleaner” Campaign Uses Google Ads to Redirect Users to Malware
Fake “Mac Cleaner” Campaign Uses Google Ads to Redirect Users to Malware Cybercriminals are exploiting Google Search Ads to distribute malware through deceptive landing pages that impersonate Apple’s official website design. The malicious ads appear prominently… Go to gbhackers.com
-
eScan Antivirus Update Server Breached to Deliver Malicious Software Updates
eScan Antivirus Update Server Breached to Deliver Malicious Software Updates MicroWorld Technologies’ eScan antivirus platform fell victim to a sophisticated supply chain attack on January 20, 2026, when threat actors compromised legitimate update infrastructure… Go to gbhackers.com
-
Microsoft links Windows 11 boot failures to failed December 2025 update
Microsoft links Windows 11 boot failures to failed December 2025 update Microsoft has linked recent reports of Windows 11 boot failures after installing the January 2026 updates to previously failed attempts to install the December 2025 security update, which left systems in an “improper state.” […] Lawrence Abrams Go to bleepingcomputer
-
Hugging Face abused to spread thousands of Android malware variants
Hugging Face abused to spread thousands of Android malware variants A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services. […] Bill Toulas Go to bleepingcomputer
-
Ivanti warns of two EPMM flaws exploited in zero-day attacks
Ivanti warns of two EPMM flaws exploited in zero-day attacks Ivanti has disclosed two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340, that were exploited in zero-day attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Google disrupts IPIDEA residential proxy networks fueled by malware
Google disrupts IPIDEA residential proxy networks fueled by malware IPIDEA, one of the largest residential proxy networks used by threat actors, was disrupted earlier this week by Google Threat Intelligence Group (GTIG) in collaboration with industry partners. […] Bill Toulas Go to bleepingcomputer
-
Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match
Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match Match Group, the owner of multiple popular online dating services, Tinder, Match.com, Meetic, OkCupid, and Hinge, confirmed a cybersecurity incident that compromised user data. […] Bill Toulas Go to bleepingcomputer
-
Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks
Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks Two critical code-injection vulnerabilities have been disclosed in the Endpoint Manager Mobile (EPMM) platform, which are currently being actively exploited in real-world attacks. The security flaws, tracked as CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to execute arbitrary code remotely on vulnerable systems. The vulnerabilities…
-
Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed
Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed Security researchers have uncovered a sophisticated traffic distribution network leveraging deceptive education-themed domains to deliver malware and phishing attacks. The operation, tracked under infrastructure indicators pointing to TOXICSNAKE, uses legitimate-looking university and educational institution branding to deceive users into visiting malicious websites. This tactic exploits the…
-
Microsoft Teams New Feature to Flag Suspicious One-to-One Calls
Microsoft Teams New Feature to Flag Suspicious One-to-One Calls A new security feature is being added to Teams to help organizations detect and stop voice-based scams and phishing attacks. The new “Report a Call” button will allow users to flag suspicious one-to-one calls directly from their Teams call history. As use of Microsoft Teams calling…
-
Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5060+ Downloads
Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5060+ Downloads A dangerous malware campaign has infiltrated the Open VSX extension marketplace, compromising over 5,000 developer workstations through a fake Angular Language Service extension. The malicious package disguised itself as legitimate development tooling, bundling authentic Angular and TypeScript components alongside encrypted malware code that…
-
3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk
3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk Over 3,280,081 Fortinet Devices Were exposed, with web properties running vulnerable Fortinet devices affected by CVE-2026-24858, a severe authentication-bypass flaw actively exploited in the wild. The vulnerability, rated 9.4 on the CVSS scale, affects multiple Fortinet product lines, including FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb. Critical…
-
TR-26-0008 (Global İnteraktif Tasarım Medya Yazılım – CMS Güvenlik Bildirimi)
TR-26-0008 (Global İnteraktif Tasarım Medya Yazılım – CMS Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0007 (QR Menüm Pro Akıllı Menü Sistemleri – Menü Paneli Güvenlik Bildirimi)
TR-26-0007 (QR Menüm Pro Akıllı Menü Sistemleri – Menü Paneli Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0006 (Akın Yazılım – QR Menü Güvenlik Bildirimi)
TR-26-0006 (Akın Yazılım – QR Menü Güvenlik Bildirimi) Go to usom.gov
-
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks, one of which has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities…
-
Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries
Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries A new joint investigation by SentinelOne SentinelLABS, and Censys has revealed that the open-source artificial intelligence (AI) deployment has created a vast “unmanaged, publicly accessible layer of AI compute infrastructure” that spans 175,000 unique Ollama hosts across 130 countries. These systems, which span both…
-
ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories
ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories This week’s updates show how small changes can create real problems. Not loud incidents, but quiet shifts that are easy to miss until they add up. The kind that affects systems people rely on every day. Many of the stories point to the…
-
Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps
Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps A study by OMICRON has revealed widespread cybersecurity gaps in the operational technology (OT) networks of substations, power plants, and control centers worldwide. Drawing on data from more than 100 installations, the analysis highlights recurring technical, organizational, and functional issues that leave critical energy infrastructure…
-
3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026
3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 Beyond the direct impact of cyberattacks, enterprises suffer from a secondary but potentially even more costly risk: operational downtime, any amount of which translates into very real damage. That’s why for CISOs, it’s key to prioritize decisions that reduce dwell time and protect…
-
ISC Stormcast For Friday, January 30th, 2026 https://isc.sans.edu/podcastdetail/9788, (Fri, Jan 30th)
ISC Stormcast For Friday, January 30th, 2026 https://isc.sans.edu/podcastdetail/9788, (Fri, Jan 30th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
ISC Stormcast For Thursday, January 29th, 2026 https://isc.sans.edu/podcastdetail/9786, (Thu, Jan 29th)
ISC Stormcast For Thursday, January 29th, 2026 https://isc.sans.edu/podcastdetail/9786, (Thu, Jan 29th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Chinese APTs Hacking Asian Orgs With High-End Malware
Chinese APTs Hacking Asian Orgs With High-End Malware Advanced persistent threat (APT) groups have deployed new cyber weapons against a variety of targets, highlighting the increasing threats to the region. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Hacking attack leaves Russian car owners locked out of their vehicles
Hacking attack leaves Russian car owners locked out of their vehicles Imagine the scene. It’s a cold Monday morning in Moscow. You walk out to your car, coffee in hand, ready to face the day. You press the button to unlock your car, and … nothing happens. You try again. Still nothing. The alarm starts…
-
Trump Administration Rescinds Biden-Era SBOM Guidance
Trump Administration Rescinds Biden-Era SBOM Guidance Federal agencies will no longer be required to solicit software bills of material (SBOMs) from tech vendors, nor attestations that they comply with NIST’s Secure Software Development Framework (SSDF). What that means long term is unclear. Alexander Culafi Go to gbhackers.com
-
More Critical Flaws on n8n Could Compromise Customer Security
More Critical Flaws on n8n Could Compromise Customer Security A new around of vulnerabilities in the popular AI automation platform could let attackers hijack servers and steal credentials. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
‘Semantic Chaining’ Jailbreak Dupes Gemini Nano Banana, Grok 4
‘Semantic Chaining’ Jailbreak Dupes Gemini Nano Banana, Grok 4 If an attacker splits a malicious prompt into discrete chunks, some large language models (LLMs) will get lost in the details and miss the true intent. Nate Nelson, Contributing Writer Go to gbhackers.com
-
How Can CISOs Respond to Ransomware Getting More Violent?
How Can CISOs Respond to Ransomware Getting More Violent? Ransomware defense requires focusing on business resilience. This means patching issues promptly, improving user education, and deploying multi-factor authentication. James Doggett Go to gbhackers.com
-
Cal.com Broken Access Controls Lead to Account Takeover and Data Exposure
Cal.com Broken Access Controls Lead to Account Takeover and Data Exposure Cal.com, an open-source scheduling platform and developer-friendly alternative to Calendly, recently patched a set of critical vulnerabilities that exposed user accounts and sensitive booking… Go to gbhackers.com
-
eSkimming Attacks Surge with Evolving Tactics and Ongoing Recovery Challenges
eSkimming Attacks Surge with Evolving Tactics and Ongoing Recovery Challenges A new longitudinal study of Magecart-style eSkimming attacks overturns the assumption that discovery equals recovery. Instead of being a one-time incident that ends with… Go to gbhackers.com
-
Gemini MCP Tool 0-Day Vulnerability Exposes Systems to Remote Code Execution
Gemini MCP Tool 0-Day Vulnerability Exposes Systems to Remote Code Execution A critical zero-day vulnerability has been disclosed in the Gemini MCP Tool, enabling unauthenticated remote attackers to execute arbitrary code on vulnerable installations without… Go to gbhackers.com
-
Cybercriminals Leverage AI-Generated Malicious Job Offers to Spread PureRAT Malware
Cybercriminals Leverage AI-Generated Malicious Job Offers to Spread PureRAT Malware A Vietnamese threat actor is using AI-authored code to power a phishing campaign that delivers the PureRAT malware and related payloads, leveraging realistic job-themed… Go to gbhackers.com
-
Critical IDIS IP Camera Vulnerability Allows Full Computer Compromise with One-Click Exploit
Critical IDIS IP Camera Vulnerability Allows Full Computer Compromise with One-Click Exploit A critical vulnerability in IDIS Cloud Manager (ICM) Viewer exposes organizations using IDIS IP cameras to one-click remote code execution (RCE), potentially allowing attackers… Go to gbhackers.com
-
Initial access hackers switch to Tsundere Bot for ransomware attacks
Initial access hackers switch to Tsundere Bot for ransomware attacks A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks. […] Bill Toulas Go to bleepingcomputer
-
Cyberattack on Polish energy grid impacted around 30 facilities
Cyberattack on Polish energy grid impacted around 30 facilities The coordinated attack on Poland’s power grid in late December targeted multiple distributed energy resource (DER) sites across the country, including combined heat and power (CHP) facilities and wind and solar dispatch systems. […] Bill Toulas Go to bleepingcomputer
-
eScan confirms update server breached to push malicious update
eScan confirms update server breached to push malicious update MicroWorld Technologies, the maker of the eScan antivirus product, has confirmed that one of its update servers was breached and used to distribute an unauthorized update later analyzed as malicious to a small subset of customers earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Viral Moltbot AI assistant raises concerns over data security
Viral Moltbot AI assistant raises concerns over data security Security researchers are warning of insecure deployments in enterprise environments of the Moltbot (formerly Clawdbot) AI assistant, which can lead to leaking API keys, OAuth tokens, conversation history, and credentials. […] Bill Toulas Go to bleepingcomputer
-
New sandbox escape flaw exposes n8n instances to RCE attacks
New sandbox escape flaw exposes n8n instances to RCE attacks Two vulnerabilities in the n8n workflow automation platform could allow attackers to fully compromise affected instances, access sensitive data, and execute arbitrary code on the underlying host. […] Bill Toulas Go to bleepingcomputer
-
eScan Antivirus Update Server Hacked to Push Malicious Update packages
eScan Antivirus Update Server Hacked to Push Malicious Update packages A critical supply chain compromise affecting MicroWorld Technologies’ eScan antivirus product, wherein threat actors successfully hijacked the vendor’s legitimate update infrastructure to distribute malware. Discovered on January 20, 2026, by Morphisec, the attack utilized a trojanized update package to deploy multi-stage malware across enterprise and…
-
Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants
Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants Microsoft is preparing a major security shift for cloud email customers as Exchange Online moves toward deprecating SMTP AUTH Basic Authentication for all tenants. The change targets one of the oldest and weakest ways to sign in to email systems, where usernames and passwords…
-
Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass
Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass Multiple critical vulnerabilities in SolarWinds Web Help Desk (WHD), culminating in unauthenticated remote code execution (RCE) via Java deserialization in CVE-2025-40551, were uncovered by Horizon3.ai researchers. These flaws chain static credentials, security bypasses, and deserialization weaknesses, affecting versions prior to 2026.1. SolarWinds WHD, an…
-
Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services
Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services Attackers are increasingly targeting Canadian citizens by abusing their heavy dependence on online government and commercial services. From paying traffic fines and renewing licenses to tracking parcels and booking flights, people now expect these tasks to be quick and digital. Threat actors are taking…
-
Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence
Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence Praetorian Inc. has publicly released Swarmer, a tool enabling low-privilege attackers to achieve stealthy Windows registry persistence by sidestepping Endpoint Detection and Response (EDR) monitoring. Deployed operationally since February 2025, Swarmer exploits mandatory user profiles and the obscure Offline Registry API to…
-
Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation Go to eset
-
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly Clawdbot) on the official Extension Marketplace that claims to be a free artificial intelligence (AI) coding assistant, but stealthily drops a malicious payload on compromised hosts. The…
-
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid The “coordinated” cyber attack targeting multiple sites across the Polish power grid has been attributed with medium confidence to a Russian state-sponsored hacking crew known as ELECTRUM. Operational technology (OT) cybersecurity company Dragos, in a new intelligence brief published Tuesday, described the late…
-
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution. The weaknesses, discovered by the JFrog Security Research team, are listed below – CVE-2026-1470 (CVSS score: 9.9) – An eval injection…
-
From Triage to Threat Hunts: How AI Accelerates SecOps
From Triage to Threat Hunts: How AI Accelerates SecOps If you work in security operations, the concept of the AI SOC agent is likely familiar. Early narratives promised total autonomy. Vendors seized on the idea of the “Autonomous SOC” and suggested a future where algorithms replaced analysts. That future has not arrived. We have not…
-
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system. The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0…
-
Eeny, meeny, miny, moe? How ransomware operators choose victims
Eeny, meeny, miny, moe? How ransomware operators choose victims Go to sophos
-
Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?, (Wed, Jan 28th)
Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?, (Wed, Jan 28th) I was looking for possible exploitation of CVE-2026-21962, a recently patched WebLogic vulnerability. While looking for related exploit attempts in our data, I came across the following request: GET /weblogic//weblogic/..;/bea_wls_internal/ProxyServlet host: 71.126.165.182 user-agent: Mozilla/5.0 (compatible; Exploit/1.0) accept-encoding: gzip, deflate accept: */* connection:…
-
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus,…
-
Four arrested in crackdown on Discord-based SWATting and doxing
Four arrested in crackdown on Discord-based SWATting and doxing How badly do you want to win an online argument? I certainly hope it’s not enough to put the life of the other person at risk. Police in Hungary and Romania have arrested four young men suspected of making hoax bomb threats and terrorising internet users…
-
Beware! Fake ChatGPT browser extensions are stealing your login credentials
Beware! Fake ChatGPT browser extensions are stealing your login credentials If you’ve installed a browser extension to enhance your ChatGPT experience, you might want to think again. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest Russian and Chinese nation-state attackers are exploiting a months-old WinRAR vulnerability, despite a patch that came out last July. Alexander Culafi Go to gbhackers.com
-
Fortinet Confirms New Zero-Day Behind Malicious SSO Logins
Fortinet Confirms New Zero-Day Behind Malicious SSO Logins To stop the ongoing attacks, the cybersecurity vendor took the drastic step of temporarily disabling FortiCloud single sign-on (SSO) authentication for all devices. Rob Wright Go to gbhackers.com
-
China-Backed ‘PeckBirdy’ Takes Flight for Cross-Platform Attacks
China-Backed ‘PeckBirdy’ Takes Flight for Cross-Platform Attacks In two separate campaigns, attackers used the JScript C2 framework to target Chinese gambling websites and Asian government entities with new backdoors. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Surging Cyberattacks Boost Latin America to Riskiest Region
Surging Cyberattacks Boost Latin America to Riskiest Region The region is up against tactics like data-leak extortion, credential-stealing campaigns, edge-device exploitation, and attackers leveraging AI. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer
Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer Threat actors have successfully exploited a design flaw in GitHub’s fork architecture to distribute malware disguised as the legitimate GitHub Desktop installer. The attack… Go to gbhackers.com