no alarms and no surprises please..
-
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly Clawdbot) on the official Extension Marketplace that claims to be a free artificial intelligence (AI) coding assistant, but stealthily drops a malicious payload on compromised hosts. The…
-
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid The “coordinated” cyber attack targeting multiple sites across the Polish power grid has been attributed with medium confidence to a Russian state-sponsored hacking crew known as ELECTRUM. Operational technology (OT) cybersecurity company Dragos, in a new intelligence brief published Tuesday, described the late…
-
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution. The weaknesses, discovered by the JFrog Security Research team, are listed below – CVE-2026-1470 (CVSS score: 9.9) – An eval injection…
-
From Triage to Threat Hunts: How AI Accelerates SecOps
From Triage to Threat Hunts: How AI Accelerates SecOps If you work in security operations, the concept of the AI SOC agent is likely familiar. Early narratives promised total autonomy. Vendors seized on the idea of the “Autonomous SOC” and suggested a future where algorithms replaced analysts. That future has not arrived. We have not…
-
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system. The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0…
-
Eeny, meeny, miny, moe? How ransomware operators choose victims
Eeny, meeny, miny, moe? How ransomware operators choose victims Go to sophos
-
Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?, (Wed, Jan 28th)
Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?, (Wed, Jan 28th) I was looking for possible exploitation of CVE-2026-21962, a recently patched WebLogic vulnerability. While looking for related exploit attempts in our data, I came across the following request: GET /weblogic//weblogic/..;/bea_wls_internal/ProxyServlet host: 71.126.165.182 user-agent: Mozilla/5.0 (compatible; Exploit/1.0) accept-encoding: gzip, deflate accept: */* connection:…
-
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus,…
-
Four arrested in crackdown on Discord-based SWATting and doxing
Four arrested in crackdown on Discord-based SWATting and doxing How badly do you want to win an online argument? I certainly hope it’s not enough to put the life of the other person at risk. Police in Hungary and Romania have arrested four young men suspected of making hoax bomb threats and terrorising internet users…
-
Beware! Fake ChatGPT browser extensions are stealing your login credentials
Beware! Fake ChatGPT browser extensions are stealing your login credentials If you’ve installed a browser extension to enhance your ChatGPT experience, you might want to think again. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest Russian and Chinese nation-state attackers are exploiting a months-old WinRAR vulnerability, despite a patch that came out last July. Alexander Culafi Go to gbhackers.com
-
Fortinet Confirms New Zero-Day Behind Malicious SSO Logins
Fortinet Confirms New Zero-Day Behind Malicious SSO Logins To stop the ongoing attacks, the cybersecurity vendor took the drastic step of temporarily disabling FortiCloud single sign-on (SSO) authentication for all devices. Rob Wright Go to gbhackers.com
-
China-Backed ‘PeckBirdy’ Takes Flight for Cross-Platform Attacks
China-Backed ‘PeckBirdy’ Takes Flight for Cross-Platform Attacks In two separate campaigns, attackers used the JScript C2 framework to target Chinese gambling websites and Asian government entities with new backdoors. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Surging Cyberattacks Boost Latin America to Riskiest Region
Surging Cyberattacks Boost Latin America to Riskiest Region The region is up against tactics like data-leak extortion, credential-stealing campaigns, edge-device exploitation, and attackers leveraging AI. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer
Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer Threat actors have successfully exploited a design flaw in GitHub’s fork architecture to distribute malware disguised as the legitimate GitHub Desktop installer. The attack… Go to gbhackers.com
-
G_Wagon NPM Package Exploits Users to Steal Browser Credentials with Obfuscated Payload
G_Wagon NPM Package Exploits Users to Steal Browser Credentials with Obfuscated Payload A highly sophisticated infostealer malware disguised as a legitimate npm UI component library has been targeting developers through the ansi-universal-ui package. The malware, internally… Go to gbhackers.com
-
CISA Urges Public to Stay Alert Against Rising Natural Disaster Scams
CISA Urges Public to Stay Alert Against Rising Natural Disaster Scams The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory alerting the public to heightened risks of malicious cyber activity targeting disaster… Go to gbhackers.com
-
ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games
ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games A surge in infrastructure deployment that mirrors the tactics of SLSH, a predatory alliance uniting three major threat actors: Scattered Spider, LAPSUS$, and ShinyHunters. A… Go to gbhackers.com
-
Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js
Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js A critical vulnerability in the vm2 JavaScript sandbox library (versions ≤ 3.10.0) enables attackers to bypass sandbox protections and execute arbitrary code with full… Go to gbhackers.com
-
OpenAI’s ChatGPT ad costs are on par with live NFL broadcasts
OpenAI’s ChatGPT ad costs are on par with live NFL broadcasts OpenAI plans to begin rolling out ads on ChatGPT in the United States if you have a free or $8 Go subscription, but the catch is that the ads could be very expensive for advertisers. […] Mayank Parmar Go to bleepingcomputer
-
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions. […] Lawrence Abrams Go to bleepingcomputer
-
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard. […] Bill Toulas Go to bleepingcomputer
-
WinRAR path traversal flaw still exploited by numerous hackers
WinRAR path traversal flaw still exploited by numerous hackers Multiple threat actors, both state-sponsored and financially motivated, are exploiting the CVE-2025-8088 high-severity vulnerability in WinRAR for initial access and to deliver various malicious payloads. […] Bill Toulas Go to bleepingcomputer
-
Nike investigates data breach after extortion gang leaks files
Nike investigates data breach after extortion gang leaks files Nike is investigating what it described as a “potential cyber security incident” after the World Leaks ransomware gang leaked 1.4 TB of files allegedly stolen from the sportswear giant. […] Sergiu Gatlan Go to bleepingcomputer
-
WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private
WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private WhatsApp has strongly denied a new class-action lawsuit accusing Meta of secretly accessing users’ end-to-end encrypted messages, labeling the claims as false and baseless. The messaging giant reiterated that messages remain private through device-based encryption via the open-source Signal protocol. A class-action complaint filed…
-
Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors
Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors A Chinese national named Jingliang Su has been sentenced to 46 months in prison for his involvement in a major cryptocurrency fraud scheme targeting American investors. On January 27, 2026, federal courts ordered Su to serve his sentence and pay…
-
Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware
Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware A newly discovered campaign demonstrates a sophisticated approach to delivering information-stealing malware through a combination of social engineering and legitimate Windows components. The attack begins with a deceptive CAPTCHA prompt that tricks users into executing commands manually through the Windows Run dialog, presenting the…
-
WhatsApp New Strict Account Settings Option to Protect Your Account from Hackers
WhatsApp New Strict Account Settings Option to Protect Your Account from Hackers WhatsApp has introduced Strict Account Settings, a lockdown-style security feature designed to protect users from highly sophisticated cyber-attacks. The new privacy feature is specifically tailored for individuals who may be targets of advanced threats, including journalists, activists, and public figures who face elevated…
-
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. Recent security research has revealed that this advanced hacker collective is actively upgrading its digital arsenal with enhanced…
-
Drowning in spam or scam emails? Here’s probably why
Drowning in spam or scam emails? Here’s probably why Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons – and how to stem the tide. Go to eset
-
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-24858 (CVSS score: 9.4), has been described as an authentication bypass related to FortiOS single sign-on (SSO). The…
-
WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware
WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware Meta on Tuesday announced it’s adding Strict Account Settings on WhatsApp to secure certain users against advanced cyber attacks because of who they are and what they do. The feature, similar to Lockdown Mode in Apple iOS and Advanced Protection in Android, aims…
-
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft. The campaigns have been codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, which identified them in September 2025. “While these campaigns share…
-
ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services
ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services Cybersecurity researchers have disclosed details of a new campaign that combines ClickFix-style fake CAPTCHAs with a signed Microsoft Application Virtualization (App-V) script to distribute an information stealer called Amatera. “Instead of launching PowerShell directly, the attacker uses this script to control how execution…
-
CTEM in Practice: Prioritization, Validation, and Outcomes That Matter
CTEM in Practice: Prioritization, Validation, and Outcomes That Matter Cybersecurity teams increasingly want to move beyond looking at threats and vulnerabilities in isolation. It’s not only about what could go wrong (vulnerabilities) or who might attack (threats), but where they intersect in your actual environment to create real, exploitable exposure. Which exposures truly matter? Can…
-
Microsoft Office vulnerability (CVE-2026-21509) in active exploitation
Microsoft Office vulnerability (CVE-2026-21509) in active exploitation Go to sophos
-
Beyond MFA: Building true resilience against identity-based attacks
Beyond MFA: Building true resilience against identity-based attacks Go to sophos
-
The Constitutionality of Geofence Warrants
The Constitutionality of Geofence Warrants The US Supreme Court is considering the constitutionality of geofence warrants. The case centers on the trial of Okello Chatrie, a Virginia man who pleaded guilty to a 2019 robbery outside of Richmond and was sentenced to almost 12 years in prison for stealing $195,000 at gunpoint. Police probing the…
-
ISC Stormcast For Wednesday, January 28th, 2026 https://isc.sans.edu/podcastdetail/9784, (Wed, Jan 28th)
ISC Stormcast For Wednesday, January 28th, 2026 https://isc.sans.edu/podcastdetail/9784, (Wed, Jan 28th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Weekly Update 488
Weekly Update 488 It’s the discussion about the reaction of some people in the UK regarding their impending social media ban for under 16s that bugged me most. Most noteably was the hand-waving around “the gov is just trying to siphon up all our IDs” and “this means everyone will have to show ID, not…
-
AI & the Death of Accuracy: What It Means for Zero-Trust
AI & the Death of Accuracy: What It Means for Zero-Trust AI “model collapse,” where LLMs over time train on more and more AI-generated data and become degraded as a result, can introduce inaccuracies, promulgate malicious activity, and impact PII protections. Alexander Culafi Go to gbhackers.com
-
Vibe-Coded ‘Sicarii’ Ransomware Can’t Be Decrypted
Vibe-Coded ‘Sicarii’ Ransomware Can’t Be Decrypted A new ransomware strain that entered the scene last year has poorly designed code and an odd “Hebrew” identity that might be a false flag. Alexander Culafi Go to gbhackers.com
-
Critical Telnet Server Flaw Exposes Forgotten Attack Surface
Critical Telnet Server Flaw Exposes Forgotten Attack Surface While telnet is considered obsolete, the network protocol is still used by hundreds of thousands of legacy systems and IoT devices for remote access. Rob Wright Go to gbhackers.com
-
Microsoft Rushes Emergency Patch for Office Zero-Day
Microsoft Rushes Emergency Patch for Office Zero-Day To exploit the vulnerability, an attacker would need either system access or be able to convince a user to open a malicious Office file. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
‘Stanley’ Toolkit Turns Chrome Into Undetectable Phishing Vector
‘Stanley’ Toolkit Turns Chrome Into Undetectable Phishing Vector The malware-as-a-service kit enables malicious extensions to overlay pages on real websites without changing the visible URL, signaling a fresh challenge for enterprise security. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
WorldLeaks Extortion Group Claims It Stole 1.4TB of Nike Data
WorldLeaks Extortion Group Claims It Stole 1.4TB of Nike Data The sportswear brand is investigating an alleged breach of its network that exposed some 188,347 files of highly sensitive corporate data. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Beauty in Destruction: Exploring Malware’s Impact Through Art
Beauty in Destruction: Exploring Malware’s Impact Through Art Artistic initiatives turn cybersecurity into immersive exhibits at the Museum of Malware Art, transforming digital threats into thought-provoking experiences. Andrada Fiscutean Go to gbhackers.com
-
Hand CVE Over to the Private Sector
Hand CVE Over to the Private Sector How MITRE has mismanaged the world’s vulnerability database for decades and wasted millions along the way. Brian Martin Go to gbhackers.com
-
Lazarus Hackers Target European Drone Manufacturers in Active Campaign
Lazarus Hackers Target European Drone Manufacturers in Active Campaign The North Korean state-sponsored Lazarus hacking group has launched a sophisticated cyberespionage campaign targeting European defense contractors involved in uncrewed aerial vehicle (UAV) manufacturing. The… Go to gbhackers.com
-
PoC Released for GNU InetUtils telnetd RCE as 800K+ Exposed Instances Remain Online
PoC Released for GNU InetUtils telnetd RCE as 800K+ Exposed Instances Remain Online A proof-of-concept exploit for CVE-2026-24061, a critical remote code execution vulnerability in the GNU Inetutils telnetd, has surfaced, with security researchers warning that over… Go to gbhackers.com
-
Instagram Investigates Reported Vulnerability Allowing Access to Private Content
Instagram Investigates Reported Vulnerability Allowing Access to Private Content A server-side vulnerability in Instagram that allegedly allowed completely unauthenticated access to private account posts. This raises concerns about Meta’s vulnerability disclosure handling and… Go to gbhackers.com
-
New Malware Toolkit Redirects Victims to Malicious Sites Without Changing the URL
New Malware Toolkit Redirects Victims to Malicious Sites Without Changing the URL A dangerous new malware toolkit is being sold on Russian cybercrime forums that can redirect victims to fake websites while keeping the real domain… Go to gbhackers.com
-
New DPRK Interview Campaign Uses Fake Fonts to Deliver Malware
New DPRK Interview Campaign Uses Fake Fonts to Deliver Malware A dangerous new iteration of the “Contagious Interview” campaign that weaponizes Microsoft Visual Studio Code task files to distribute sophisticated malware targeting software developers…. Go to gbhackers.com
-
New malware service guarantees phishing extensions on Chrome web store
New malware service guarantees phishing extensions on Chrome web store A new malware-as-a-service (MaaS) called ‘Stanley’ promises malicious Chrome extensions that can clear Google’s review process and publish them to the Chrome Web Store. […] Bill Toulas Go to bleepingcomputer
-
New ClickFix attacks abuse Windows App-V scripts to push malware
New ClickFix attacks abuse Windows App-V scripts to push malware A new malicious campaign mixes the ClickFix method with fake CAPTCHA and a signed Microsoft Application Virtualization (App-V) script to ultimately deliver the Amatera infostealing malware. […] Bill Toulas Go to bleepingcomputer
-
Microsoft patches actively exploited Office zero-day vulnerability
Microsoft patches actively exploited Office zero-day vulnerability Microsoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare misconfiguration behind recent BGP route leak
Cloudflare misconfiguration behind recent BGP route leak Cloudflare has shared more details about a recent 25-minute Border Gateway Protocol (BGP) route leak affecting IPv6 traffic, which caused measurable congestion, packet loss, and approximately 12 Gbps of dropped traffic. […] Bill Toulas Go to bleepingcomputer
-
EU launches investigation into X over Grok-generated sexual images
EU launches investigation into X over Grok-generated sexual images The European Commission is now investigating whether X properly assessed risks before deploying its Grok artificial intelligence tool, following its use to generate sexually explicit images. […] Sergiu Gatlan Go to bleepingcomputer
-
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files Caminho Loader is a new Loader-as-a-Service threat that blends steganography, fileless execution, and cloud abuse to quietly deliver malware across several regions. First seen in March 2025 and believed to originate from Brazil, this service hides .NET payloads inside harmless-looking image files hosted on…
-
Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published
Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published A critical vulnerability has been identified in the PyPI-distributed version of PLY (Python Lex-Yacc) 3.11, allowing arbitrary code execution through unsafe deserialization of untrusted pickle files. The vulnerability, assigned CVE-2025-56005, affects the undocumented picklefile parameter in the yacc() function, which remains absent from official documentation despite…
-
APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware
APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. The campaign, identified as Gopher Strike, emerged in September 2025 and represents a significant escalation in targeted cyber…
-
Multiple Vulnerabilities in React Server Components Enable DoS Attacks
Multiple Vulnerabilities in React Server Components Enable DoS Attacks Multiple critical security vulnerabilities have recently been disclosed in React Server Components, enabling threat actors to launch Denial-of-Service (DoS) attacks against vulnerable servers. The flaws, tracked as CVE-2026-23864 with a CVSS score of 7.5, are due to incomplete patches from previous security fixes and require immediate…
-
China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates
China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work across multiple system environments, giving attackers remarkable flexibility in how they deploy their…
-
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware Cybersecurity researchers have discovered an ongoing campaign that’s targeting Indian users with a multi-stage backdoor as part of a suspected cyber espionage campaign. The activity, per the eSentire Threat Response Unit (TRU), involves using phishing emails impersonating the Income Tax Department of India to trick…
-
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also harbor covert functionality to siphon developer data to China-based servers. The extensions, which have 1.5 million combined installs…
-
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More Security failures rarely arrive loudly. They slip in through trusted tools, half-fixed problems, and habits people stop questioning. This week’s recap shows that pattern clearly. Attackers are moving faster than defenses, mixing old tricks with new paths. “Patched” no longer means safe,…
-
Winning Against AI-Based Attacks Requires a Combined Defensive Approach
Winning Against AI-Based Attacks Requires a Combined Defensive Approach If there’s a constant in cybersecurity, it’s that adversaries are always innovating. The rise of offensive AI is transforming attack strategies and making them harder to detect. Google’s Threat Intelligence Group, recently reported on adversaries using Large Language Models (LLMs) to both conceal code and generate…
-
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target developers and engineering teams in the blockchain sector. The phishing campaign has targeted Japan, Australia, and India, highlighting the adversary’s expansion of the targeting…
-
Generative AI and cybersecurity: What Sophos experts expect in 2026
Generative AI and cybersecurity: What Sophos experts expect in 2026 Go to sophos
-
Ireland Proposes Giving Police New Digital Surveillance Powers
Ireland Proposes Giving Police New Digital Surveillance Powers This is coming: The Irish government is planning to bolster its police’s ability to intercept communications, including encrypted messages, and provide a legal basis for spyware use. Bruce Schneier Go to bruce schneier
-
Initial Stages of Romance Scams [Guest Diary], (Tue, Jan 27th)
Initial Stages of Romance Scams [Guest Diary], (Tue, Jan 27th) [This is a Guest Diary by Fares Azhari, an ISC intern as part of the SANS.edu BACS program] Romance scams are a form of social-engineering fraud that causes both financial and emotional harm. They vary in technique and platform, but most follow the same high-level roadmap: initial contact,…
-
ISC Stormcast For Tuesday, January 27th, 2026 https://isc.sans.edu/podcastdetail/9782, (Tue, Jan 27th)
ISC Stormcast For Tuesday, January 27th, 2026 https://isc.sans.edu/podcastdetail/9782, (Tue, Jan 27th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Sandworm Blamed for Wiper Attack on Poland Power Grid
Sandworm Blamed for Wiper Attack on Poland Power Grid Researchers attributed the failed attempt to the infamous Russian APT Sandworm, which is notorious for wiper attacks on critical infrastructure organizations. Alexander Culafi Go to gbhackers.com
-
DPRK’s Konni Targets Blockchain Developers With AI-Generated Backdoor
DPRK’s Konni Targets Blockchain Developers With AI-Generated Backdoor The North Korean threat group is using a new PowerShell backdoor to compromise development environments and target cryptocurrency holdings, according to researchers. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
ChatGPT Temporary chat feature is getting a much-needed upgrade
ChatGPT Temporary chat feature is getting a much-needed upgrade OpenAI is testing a big upgrade for ChatGPT’s temporary chat feature. The update will allow you to retain personalization in temporary chat, and still block temporary chat from influencing your account. […] Mayank Parmar Go to bleepingcomputer
-
1Password adds pop-up warnings for suspected phishing sites
1Password adds pop-up warnings for suspected phishing sites The 1Password digital vault and password manager has added built-in protection against phishing URLs to help users identify malicious pages and prevent them from sharing account credentials with threat actors. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates Windows 11 boot failures after January updates
Microsoft investigates Windows 11 boot failures after January updates Microsoft is investigating reports that some Windows 11 devices are failing to boot with “UNMOUNTABLE_BOOT_VOLUME” errors after installing the January 2026 Patch Tuesday security updates. […] Lawrence Abrams Go to bleepingcomputer
-
Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption
Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption A moderate-severity vulnerability in the Hadoop Distributed File System (HDFS) native client could allow attackers to trigger system crashes or corrupt critical data through maliciously crafted URI inputs. The vulnerability, tracked as CVE-2025-27821, affects Apache Hadoop versions 3.2.0 through 3.4.1. Stems from an out-of-bounds write…
-
Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes
Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes An out-of-band (OOB) cumulative update, KB5078127, to address critical file system compatibility issues affecting Windows 11 users. The update resolves widespread problems introduced by the January 13, 2026, security update (KB5074109) that caused application freezes and cloud storage failures across multiple…
-
New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool
New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool A sophisticated phishing campaign active between November 2025 and January 2026 has been exploiting Vercel’s legitimate hosting platform to distribute remote access tools to unsuspecting victims. The attack chain combines social engineering with trusted domain exploitation, making it particularly effective at bypassing…
-
New Instagram Vulnerability Exposes Private Posts to Anyone
New Instagram Vulnerability Exposes Private Posts to Anyone A critical server-side vulnerability in Instagram’s infrastructure allowed unauthenticated attackers to access private photos and captions without a login or follower relationship, according to a disclosure released this week by security researcher Jatin Banga. The vulnerability, which was reportedly patched silently by Meta in October 2025, relied…
-
Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware
Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware Late December 2025 brought alarming news to Poland as its energy infrastructure became the target of what security experts describe as the country’s largest cyberattack in years. The Russian-aligned Sandworm group, known for orchestrating some of the most damaging attacks on critical infrastructure, emerged as…
-
ISC Stormcast For Monday, January 26th, 2026 https://isc.sans.edu/podcastdetail/9780, (Mon, Jan 26th)
ISC Stormcast For Monday, January 26th, 2026 https://isc.sans.edu/podcastdetail/9780, (Mon, Jan 26th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scanning Webserver with /$(pwd)/ as a Starting Path, (Sun, Jan 25th)
Scanning Webserver with /$(pwd)/ as a Starting Path, (Sun, Jan 25th) Based on the sensors reporting to ISC, this activity started on the 13 Jan 2026. My own sensor started seeing the first scan on the 21 Jan 2026 with limited probes. So far, this activity has been limited to a few scans based on…
-
Microsoft Teams to Begin Sharing Employee Location with Employers Based on Wi-Fi Networks
Microsoft Teams to Begin Sharing Employee Location with Employers Based on Wi-Fi Networks Microsoft has confirmed a controversial new feature coming to Teams that will automatically reveal employee work locations by detecting which Wi-Fi networks they connect… Go to gbhackers.com
-
Microsoft Open-Sources winapp, a New CLI Tool for Streamlined Windows App Development
Microsoft Open-Sources winapp, a New CLI Tool for Streamlined Windows App Development Microsoft has announced the public preview of the Windows App Development CLI (winapp), a new open-source command-line tool designed to simplify Windows application development… Go to gbhackers.com
-
Microsoft Shared BitLocker Recovery Keys with the FBI to Unlock Encrypted Laptop Data
Microsoft Shared BitLocker Recovery Keys with the FBI to Unlock Encrypted Laptop Data Microsoft has confirmed that it provided BitLocker encryption recovery keys to the FBI following a valid search warrant, marking the first publicly known case… Go to gbhackers.com
-
Researchers Uncover Multi-Stage AiTM Attack Using SharePoint to Bypass Security Controls
Researchers Uncover Multi-Stage AiTM Attack Using SharePoint to Bypass Security Controls Microsoft Defender researchers have exposed a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting energy sector organizations, leveraging SharePoint file-sharing services to bypass traditional email security… Go to gbhackers.com
-
Attackers Leveraging telnetd Exploit for Root Privileges After PoC Goes Public
Attackers Leveraging telnetd Exploit for Root Privileges After PoC Goes Public The threat actors have begun actively exploiting a critical authentication bypass vulnerability in GNU InetUtils telnetd immediately after proof-of-concept code became publicly available. The… Go to gbhackers.com
-
Microsoft releases emergency OOB update to fix Outlook freezes
Microsoft releases emergency OOB update to fix Outlook freezes Microsoft has released emergency, out-of-band updates on Saturday for Windows 10, Windows 11, and Windows Server to fix an issue that prevented Microsoft Outlook classic from opening when using PSTs stored in cloud storage. […] Lawrence Abrams Go to bleepingcomputer
-
Sandworm hackers linked to failed wiper attack on Poland’s energy systems
Sandworm hackers linked to failed wiper attack on Poland’s energy systems A cyberattack targeting Poland’s power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. […] Lawrence Abrams Go to bleepingcomputer
-
Konni hackers target blockchain engineers with AI-built malware
Konni hackers target blockchain engineers with AI-built malware The North Korean hacker group Konni (Opal Sleet, TA406) is using AI-generated PowerShell malware to target developers and engineers in the blockchain sector. […] Bill Toulas Go to bleepingcomputer
-
Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack
Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack A sophisticated “homoglyph” phishing campaign targeting customers of Marriott International and Microsoft. Attackers are registering domains that replace the letter “m” with the combination “rn” (r + n), creating fake websites that look nearly identical to the real ones. This technique,…
-
CISA Warns of Critical VMware vCenter RCE Vulnerability Exploited in Attacks
CISA Warns of Critical VMware vCenter RCE Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom’s VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that active exploitation of CVE-2024-37079 has been detected in the wild, posing a significant risk to enterprise…
-
Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network
Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network Microsoft is preparing to deploy a significant, potentially controversial update to Microsoft Teams that automatically detects and displays a user’s physical work location based on the Wi-Fi network they connect to. According to the latest update on the Microsoft 365 Roadmap…
-
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware A new multi-stage phishing campaign has been observed targeting users in Russia with ransomware and a remote access trojan called Amnesia RAT. “The attack begins with social engineering lures delivered via business-themed documents crafted to appear routine and benign,” Fortinet FortiGuard Labs researcher Cara Lin…
-
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector The Russian nation-state hacking group known as Sandworm has been attributed to what has been described as the “largest cyber attack” targeting Poland’s power system in the last week of December 2025. The attack was unsuccessful, the country’s energy minister, Milosz Motyka, said…
-
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents AI agents are accelerating how work gets done. They schedule meetings, access data, trigger workflows, write code, and take action in real time, pushing productivity beyond human speed across the enterprise. Then comes the moment every security team eventually hits:…
-
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting Broadcom VMware vCenter Server that was patched in June 2024 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability in…