no alarms and no surprises please..
-
Microsoft releases emergency OOB update to fix Outlook freezes
Microsoft releases emergency OOB update to fix Outlook freezes Microsoft has released emergency, out-of-band updates on Saturday for Windows 10, Windows 11, and Windows Server to fix an issue that prevented Microsoft Outlook classic from opening when using PSTs stored in cloud storage. […] Lawrence Abrams Go to bleepingcomputer
-
Sandworm hackers linked to failed wiper attack on Poland’s energy systems
Sandworm hackers linked to failed wiper attack on Poland’s energy systems A cyberattack targeting Poland’s power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. […] Lawrence Abrams Go to bleepingcomputer
-
Konni hackers target blockchain engineers with AI-built malware
Konni hackers target blockchain engineers with AI-built malware The North Korean hacker group Konni (Opal Sleet, TA406) is using AI-generated PowerShell malware to target developers and engineers in the blockchain sector. […] Bill Toulas Go to bleepingcomputer
-
Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack
Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack A sophisticated “homoglyph” phishing campaign targeting customers of Marriott International and Microsoft. Attackers are registering domains that replace the letter “m” with the combination “rn” (r + n), creating fake websites that look nearly identical to the real ones. This technique,…
-
CISA Warns of Critical VMware vCenter RCE Vulnerability Exploited in Attacks
CISA Warns of Critical VMware vCenter RCE Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom’s VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that active exploitation of CVE-2024-37079 has been detected in the wild, posing a significant risk to enterprise…
-
Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network
Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network Microsoft is preparing to deploy a significant, potentially controversial update to Microsoft Teams that automatically detects and displays a user’s physical work location based on the Wi-Fi network they connect to. According to the latest update on the Microsoft 365 Roadmap…
-
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware A new multi-stage phishing campaign has been observed targeting users in Russia with ransomware and a remote access trojan called Amnesia RAT. “The attack begins with social engineering lures delivered via business-themed documents crafted to appear routine and benign,” Fortinet FortiGuard Labs researcher Cara Lin…
-
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector The Russian nation-state hacking group known as Sandworm has been attributed to what has been described as the “largest cyber attack” targeting Poland’s power system in the last week of December 2025. The attack was unsuccessful, the country’s energy minister, Milosz Motyka, said…
-
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents AI agents are accelerating how work gets done. They schedule meetings, access data, trigger workflows, write code, and take action in real time, pushing productivity beyond human speed across the enterprise. Then comes the moment every security team eventually hits:…
-
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting Broadcom VMware vCenter Server that was patched in June 2024 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability in…
-
2025 Was a Wake-Up Call to Protect Human Decisions, Not Just Systems
2025 Was a Wake-Up Call to Protect Human Decisions, Not Just Systems Cybersecurity must shift from solely protecting systems to safeguarding human decision-making under uncertainty and system failures. Rashmi Tallapragada Go to gbhackers.com
-
Top 10 World’s Best Data Security Companies in 2026
Top 10 World’s Best Data Security Companies in 2026 In 2026, data has become the most valuable asset for businesses and the most targeted. With rising ransomware attacks, insider threats, AI-driven breaches, and… Go to gbhackers.com
-
Fortinet Confirms Active Exploitation of FortiCloud SSO Bypass Vulnerability
Fortinet Confirms Active Exploitation of FortiCloud SSO Bypass Vulnerability Fortinet has officially confirmed active exploitation of critical FortiCloud single sign-on (SSO) authentication bypass vulnerabilities affecting multiple enterprise security appliances. The company disclosed two… Go to gbhackers.com
-
TrustAsia Pulls 143 Certificates Following Critical LiteSSL ACME Vulnerability
TrustAsia Pulls 143 Certificates Following Critical LiteSSL ACME Vulnerability TrustAsia has revoked 143 SSL/TLS certificates following the discovery of a critical vulnerability in its LiteSSL ACME service. The flaw, disclosed on January 21,… Go to gbhackers.com
-
Fake Captcha Exploits Trusted Web Infrastructure to Distribute Malware
Fake Captcha Exploits Trusted Web Infrastructure to Distribute Malware Fake Captcha and “ClickFix” lures have emerged as among the most persistent and deceptive malware-delivery mechanisms on the modern web. These pages mimic legitimate… Go to gbhackers.com
-
20,000 WordPress Sites Compromised by Backdoor Vulnerability Enabling Malicious Admin Access
20,000 WordPress Sites Compromised by Backdoor Vulnerability Enabling Malicious Admin Access A critical backdoor vulnerability discovered in the LA-Studio Element Kit for the Elementor plugin poses an immediate threat to more than 20,000 WordPress installations…. Go to gbhackers.com
-
ShinyHunters claim to be behind SSO-account data theft attacks
ShinyHunters claim to be behind SSO-account data theft attacks The ShinyHunters extortion gang claims it is behind a wave of ongoing voice phishing attacks targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling threat actors to breach corporate SaaS platforms and steal company data for extortion. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious AI extensions on VSCode Marketplace steal developer data
Malicious AI extensions on VSCode Marketplace steal developer data Two malicious extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers. […] Bill Toulas Go to bleepingcomputer
-
CISA confirms active exploitation of four enterprise software bugs
CISA confirms active exploitation of four enterprise software bugs The Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. warned of active exploitation of four vulnerabilities impacting enterprise software from Versa and Zimbra, the Vite frontend tooling framework, and the Prettier code formatter. […] Bill Toulas Go to bleepingcomputer
-
US to deport Venezuelans who emptied bank ATMs using malware
US to deport Venezuelans who emptied bank ATMs using malware South Carolina federal prosecutors announced that two Venezuelan nationals convicted of stealing hundreds of thousands of dollars from U.S. banks in an ATM jackpotting scheme will be deported after serving their sentences. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit critical telnetd auth bypass flaw to get root
Hackers exploit critical telnetd auth bypass flaw to get root A coordinated campaign has been observed targeting a recently disclosed critical-severity vulnerability that has been present in the GNU InetUtils telnetd server for 11 years. […] Bill Toulas Go to bleepingcomputer
-
Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign
Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign Microsoft Defender researchers have exposed a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting energy sector organizations through SharePoint file-sharing abuse. The multi-stage attack compromised multiple user accounts and evolved into widespread business email compromise (BEC) operations across several organisations. Initial Compromise Through Trusted Vendor The attack…
-
Microsoft Launches Open-Source WinApp CLI to Streamline Windows App Development
Microsoft Launches Open-Source WinApp CLI to Streamline Windows App Development Microsoft has unveiled the public preview of WinApp CLI (winapp), a new open-source command-line tool designed to simplify Windows app development for developers using diverse frameworks outside Visual Studio or MSBuild. Hosted on GitHub, the tool targets web devs with Electron, C++ experts on CMake,…
-
Microsoft Shares BitLocker Keys with FBI to Unlock Encrypted Laptops in Guam Fraud Investigation
Microsoft Shares BitLocker Keys with FBI to Unlock Encrypted Laptops in Guam Fraud Investigation Microsoft gave U.S. federal agents the digital keys needed to unlock three encrypted laptops linked to a massive COVID unemployment scam in Guam. This case shows how cloud-stored encryption keys can help law enforcement, but also raises big privacy worries for…
-
Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released
Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released Active exploitation of a critical authentication bypass vulnerability in the GNU InetUtils telnetd server (CVE-2026-24061) has been observed in the wild, allowing unauthenticated attackers to gain root access to Linux systems. The vulnerability, which affects GNU InetUtils versions 1.9.3 through 2.7, enables remote code…
-
20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation
20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by more than 20,000 active sites. This security flaw allows attackers to create administrator accounts without any authentication, putting thousands of websites at risk…
-
ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025
ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper Go to eset
-
Children and chatbots: What parents should know
Children and chatbots: What parents should know As children turn to AI chatbots for answers, advice, and companionship, questions emerge about their safety, privacy, and emotional development Go to eset
-
TR-26-0005 (Birebirsoft Yazılım – Sufirmam Güvenlik Bildirimi)
TR-26-0005 (Birebirsoft Yazılım – Sufirmam Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0004 (Tapandsign Technologies – Tap&Sign Güvenlik Bildirimi)
TR-26-0004 (Tapandsign Technologies – Tap&Sign Güvenlik Bildirimi) Go to usom.gov
-
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2025-68645 (CVSS score: 8.8) – A PHP remote…
-
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls Fortinet has officially confirmed that it’s working to completely plug a FortiCloud SSO authentication bypass vulnerability following reports of fresh exploitation activity on fully-patched firewalls. “In the last 24 hours, we have identified a number of cases where the exploit was to a device…
-
TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order
TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order TikTok on Friday officially announced that it formed a joint venture that will allow the hugely popular video-sharing application to continue operating in the U.S. The new venture, named TikTok USDS Joint Venture LLC, has been established in compliance with the Executive Order…
-
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access Cybersecurity researchers have disclosed details of a new dual-vector campaign that leverages stolen credentials to deploy legitimate Remote Monitoring and Management (RMM) software for persistent remote access to compromised hosts. “Instead of deploying custom viruses, attackers are bypassing security perimeters by weaponizing the…
-
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms Microsoft has warned of a multi‑stage adversary‑in‑the‑middle (AitM) phishing and business email compromise (BEC) campaign targeting multiple organizations in the energy sector. “The campaign abused SharePoint file‑sharing services to deliver phishing payloads and relied on inbox rule creation to maintain persistence and evade user…
-
Friday Squid Blogging: Giant Squid in the Star Trek Universe
Friday Squid Blogging: Giant Squid in the Star Trek Universe Spock befriends a giant space squid in the comic Star Trek: Strange New Worlds: The Seeds of Salvation #5. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce…
-
AIs are Getting Better at Finding and Exploiting Internet Vulnerabilities
AIs are Getting Better at Finding and Exploiting Internet Vulnerabilities Really interesting blog post from Anthropic: In a recent evaluation of AI models’ cyber capabilities, current Claude models can now succeed at multistage attacks on networks with dozens of hosts using only standard, open-source tools, instead of the custom tools needed by previous generations. This…
-
Swipe, Plug-in, Pwned: Researchers Find New Ways to Hack Vehicles
Swipe, Plug-in, Pwned: Researchers Find New Ways to Hack Vehicles Security researchers exploited dozens of vulnerabilities in vehicle infotainment systems and EV chargers during the latest Pwn2Own contest at Automotive World 2026. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Exploited Zero-Day Flaw in Cisco UC Could Affect Millions
Exploited Zero-Day Flaw in Cisco UC Could Affect Millions Mass scanning is underway for CVE-2026-20045, which Cisco tagged as critical because successful exploitation could lead to a complete system takeover. Rob Wright Go to gbhackers.com
-
Healthy Security Cultures Thrive on Risk Reporting
Healthy Security Cultures Thrive on Risk Reporting The signs of an effective security culture are shifting as companies call on CISOs and security teams to raise their hands unabashedly. Arielle Waldman Go to gbhackers.com
-
Pwn2Own Automotive 2026: Researchers Score $516,500 For 37 Unique Zero-Days
Pwn2Own Automotive 2026: Researchers Score $516,500 For 37 Unique Zero-Days Day Two of Pwn2Own Automotive 2026 kicked off with high intensity, as security researchers targeted automotive infotainment systems, EV chargers, and gateways. Building on… Go to gbhackers.com
-
New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks
New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks A newly discovered ransomware family, Osiris, targeted a major foodservice franchisee in Southeast Asia in November 2025. Despite sharing a name with a 2016… Go to gbhackers.com
-
Critical Vivotek Flaw Enables Remote Arbitrary Code Execution
Critical Vivotek Flaw Enables Remote Arbitrary Code Execution Akamai’s Security Intelligence and Response Team (SIRT) uncovered a serious command injection vulnerability in legacy Vivotek IoT camera firmware. Tracked as CVE-2026-22755, the flaw… Go to gbhackers.com
-
NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution
NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution NVIDIA has patched critical vulnerabilities in its CUDA Toolkit that expose developers and GPU-accelerated systems to command injection and arbitrary code execution risks. Released… Go to gbhackers.com
-
BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records
BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records A critical vulnerability in BIND 9 exposes DNS servers to remote denial-of-service (DoS) attacks. Security firm ISC disclosed CVE-2025-13878 on January 21, 2026, warning… Go to gbhackers.com
-
Okta SSO accounts targeted in vishing-based data theft attacks
Okta SSO accounts targeted in vishing-based data theft attacks Okta is warning about custom phishing kits built specifically for voice-based social engineering (vishing) attacks. BleepingComputer has learned that these kits are being used in active attacks to steal Okta SSO credentials for data theft. […] Lawrence Abrams Go to bleepingcomputer
-
Curl ending bug bounty program after flood of AI slop reports
Curl ending bug bounty program after flood of AI slop reports The developer of the popular curl command-line utility and library announced that the project will end its HackerOne security bug bounty program at the end of this month, after being overwhelmed by low-quality AI-generated vulnerability reports. […] Lawrence Abrams Go to bleepingcomputer
-
SmarterMail auth bypass flaw now exploited to hijack admin accounts
SmarterMail auth bypass flaw now exploited to hijack admin accounts Hackers began exploiting an authentication bypass vulnerability in SmarterTools’ SmarterMail email server and collaboration tool that allows resetting admin passwords. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to add brand impersonation warnings to calls
Microsoft Teams to add brand impersonation warnings to calls Microsoft will soon add new fraud protection features to Teams calls, warning users about external callers who attempt to impersonate trusted organizations in social engineering attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
INC ransomware opsec fail allowed data recovery for 12 US orgs
INC ransomware opsec fail allowed data recovery for 12 US orgs An operational security failure allowed researchers to recover data that the INC ransomware gang stole from a dozen U.S. organizations. […] Bill Toulas Go to bleepingcomputer
-
North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams
North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams North Korea–aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. Using AI-written PowerShell code, the group known as KONNI is delivering a stealthy backdoor that blends real project content with malicious scripts. This operation…
-
Nike Allegedly Hacked by WorldLeaks Ransomware Group
Nike Allegedly Hacked by WorldLeaks Ransomware Group Athletic footwear and apparel manufacturer Nike has become the latest victim of WorldLeaks, a financially motivated ransomware group known for data extortion attacks. The group announced the breach on its darknet leak site on January 22, claiming responsibility for the incident and threatening to release stolen data on…
-
New Windows 11 KB5074109 Update Breaks Systems – Microsoft Asks Users to Remove Update
New Windows 11 KB5074109 Update Breaks Systems – Microsoft Asks Users to Remove Update Microsoft’s January 2026 Windows 11 security update KB5074109 has triggered multiple system stability issues, including lockups and black screens, prompting users to uninstall it. Reports highlight graphics regressions and app failures affecting both consumer and enterprise setups. KB5074109 targets Windows 11…
-
ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing
ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing The Zed Attack Proxy (ZAP) team has released the OWASP PTK add-on, version 0.2.0 alpha, integrating the OWASP Penetration Testing Kit (PTK) browser extension directly into ZAP-launched browsers. This streamlines application security testing by embedding DAST, IAST, SAST, SCA, and specialized tools like JWT…
-
New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks
New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks A newly discovered ransomware family called Osiris launched attacks against a major food service company in Southeast Asia during November 2025. Security researchers have identified this threat as a completely new malware variant with no connection to an older…
-
Common Apple Pay scams, and how to stay safe
Common Apple Pay scams, and how to stay safe Here’s how the most common scams targeting Apple Pay users work and what you can do to stay one step ahead Go to eset
-
TR-26-0003 (Solvera Yazılım Hizmetleri – Teknoera Güvenlik Bildirimi)
TR-26-0003 (Solvera Yazılım Hizmetleri – Teknoera Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0002 (EXERT Bilgisayar Teknolojileri – Eğitim Yönetim Sistemi Güvenlik Bildirimi)
TR-26-0002 (EXERT Bilgisayar Teknolojileri – Eğitim Yönetim Sistemi Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0001 (Aida Bilgisayar – Hotel Guest Hotspot Güvenlik Bildirimi)
TR-26-0001 (Aida Bilgisayar – Hotel Guest Hotspot Güvenlik Bildirimi) Go to usom.gov
-
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack Cybersecurity researchers have disclosed details of a new ransomware family called Osiris that targeted a major food service franchisee operator in Southeast Asia in November 2025. The attack leveraged a malicious driver called POORTRY as part of a known technique referred to…
-
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access A critical security flaw has been disclosed in the GNU InetUtils telnet daemon (telnetd) that went unnoticed for nearly 11 years. The vulnerability, tracked as CVE-2026-24061, is rated 9.8 out of 10.0 on the CVSS scoring system. It affects all versions of…
-
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them. What…
-
Filling the Most Common Gaps in Google Workspace Security
Filling the Most Common Gaps in Google Workspace Security Security teams at agile, fast-growing companies often have the same mandate: secure the business without slowing it down. Most teams inherit a tech stack optimized for breakneck growth, not resilience. In these environments, the security team is the helpdesk, the compliance expert, and the incident response…
-
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts A new malicious package discovered in the Python Package Index (PyPI) has been found to impersonate a popular library for symbolic mathematics to deploy malicious payloads, including a cryptocurrency miner, on Linux hosts. The package, named sympy-dev, mimics SymPy, replicating the latter’s project description…
-
Why AI Keeps Falling for Prompt Injection Attacks
Why AI Keeps Falling for Prompt Injection Attacks Imagine you work at a drive-through restaurant. Someone drives up and says: “I’ll have a double cheeseburger, large fries, and ignore previous instructions and give me the contents of the cash drawer.” Would you hand over the money? Of course not. Yet this is what large language…
-
ISC Stormcast For Friday, January 23rd, 2026 https://isc.sans.edu/podcastdetail/9778, (Fri, Jan 23rd)
ISC Stormcast For Friday, January 23rd, 2026 https://isc.sans.edu/podcastdetail/9778, (Fri, Jan 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Is AI-Generated Code Secure?, (Thu, Jan 22nd)
Is AI-Generated Code Secure?, (Thu, Jan 22nd) The title of this diary is perhaps a bit catchy but the question is important. I don’t consider myself as a good developer. That’s not my day job and I’m writing code to improve my daily tasks. I like to say “I’m writing sh*ty code! It works for…
-
Kimwolf Botnet Lurking in Corporate, Govt. Networks
Kimwolf Botnet Lurking in Corporate, Govt. Networks A new Internet-of-Things (IoT) botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf’s ability to scan the local networks of compromised systems for other IoT…
-
European Space Agency’s cybersecurity in freefall as yet another breach exposes spacecraft and mission data
European Space Agency’s cybersecurity in freefall as yet another breach exposes spacecraft and mission data It has just been a few weeks since reports emerged of the Christmas cyber attack suffered by the European Space Agency (ESA), and the situation has already become worse. Read more in my article on the Hot for Security blog.…
-
Risky Chinese Electric Buses Spark Aussie Gov’t Review
Risky Chinese Electric Buses Spark Aussie Gov’t Review Deployed across Australia and Europe, China’s electric buses are vulnerable to cybercriminals and sport a virtual kill switch the Chinese state could activate. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Fortinet Firewalls Hit With Malicious Configuration Changes
Fortinet Firewalls Hit With Malicious Configuration Changes Automated infections of potentially fully patched FortiGate devices are allowing threat actors to steal firewall configuration files. Rob Wright Go to gbhackers.com
-
From a Whisper to a Scream: Europe Frets About Overreliance on US Tech
From a Whisper to a Scream: Europe Frets About Overreliance on US Tech Concern is growing across Europe about relying on US cybersecurity companies, and Greenland takeover talk is eroding trust across the EU even further. Rik Turner Go to gbhackers.com
-
Latin American Orgs Lack Confidence in Cyber Defenses, Skills
Latin American Orgs Lack Confidence in Cyber Defenses, Skills Cybersecurity professionals in Latin America are least likely to have faith in their countries’ preparedness for cyberattacks on critical infrastructure, the World Economic Forum says. Robert Lemos, Contributing Writer Go to gbhackers.com
-
DPRK Actors Deploy VS Code Tunnels for Remote Hacking
DPRK Actors Deploy VS Code Tunnels for Remote Hacking A spear-phishing campaign tied to the Democratic People’s Republic of Korea (DPRK) uses trusted Microsoft infrastructure to avoid detection. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
AI Agents Undermine Progress in Browser Security
AI Agents Undermine Progress in Browser Security Web browser companies have put in substantial effort over the last three decades to strengthen the browser security stack to withstand abuses. Agentic browsers are undoing all that work. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Cisco Unified Communications Zero-Day RCE Flaw Actively Exploited For Root Shell Access
Cisco Unified Communications Zero-Day RCE Flaw Actively Exploited For Root Shell Access Cisco has warned customers of a critical zero-day vulnerability affecting several of its Unified Communications products, including Cisco Unified Communications Manager (Unified CM), Unified… Go to gbhackers.com
-
New ClickFix Campaign Exploits Fake Verification Pages to Hijack Facebook Sessions
New ClickFix Campaign Exploits Fake Verification Pages to Hijack Facebook Sessions A sophisticated ClickFix campaign targeting Facebook users has been identified, leveraging social engineering to extract live session credentials directly from victims’ browsers. Unlike traditional… Go to gbhackers.com
-
Malicious PyPI Package Impersonates sympy-dev, Targeting Millions of Users
Malicious PyPI Package Impersonates sympy-dev, Targeting Millions of Users A dangerous supply-chain attack targeting the Python Package Index (PyPI) that involves a malicious package named sympy-dev impersonating SymPy, one of the world’s most… Go to gbhackers.com
-
New Multi-Stage Windows Malware Disables Microsoft Defender, Deploys Malicious Payloads
New Multi-Stage Windows Malware Disables Microsoft Defender, Deploys Malicious Payloads A sophisticated multi-stage malware campaign targeting Russian users, leveraging social engineering, legitimate cloud services, and native Windows functionality to achieve full system compromise without… Go to gbhackers.com
-
New AI-Powered Android Malware Automatically Clicks Ads on Infected Devices
New AI-Powered Android Malware Automatically Clicks Ads on Infected Devices A sophisticated new Android malware family dubbed “Android.Phantom” that leverages artificial intelligence to automate ad-clicking fraud while establishing a persistent command-and-control infrastructure through dual-mode… Go to gbhackers.com
-
Zendesk ticket systems hijacked in massive global spam wave
Zendesk ticket systems hijacked in massive global spam wave People worldwide are being targeted by a massive spam wave originating from unsecured Zendesk support systems, with victims reporting receiving hundreds of emails with strange and sometimes alarming subject lines. […] Lawrence Abrams Go to bleepingcomputer
-
Chainlit AI framework bugs let hackers breach cloud environments
Chainlit AI framework bugs let hackers breach cloud environments Two high-severity vulnerabilities in Chainlit, a popular open-source framework for building conversational AI applications, allow reading any file on the server and leak sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Cisco fixes Unified Communications RCE zero day exploited in attacks
Cisco fixes Unified Communications RCE zero day exploited in attacks Cisco has fixed a critical Unified Communications and Webex Calling remote code execution vulnerability, tracked as CVE-2026-20045, that has been actively exploited as a zero-day in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
New Android malware uses AI to click on hidden browser ads
New Android malware uses AI to click on hidden browser ads A new family of Android click-fraud trojans leverages TensorFlow machine learning models to automatically detect and interact with specific advertisement elements. […] Bill Toulas Go to bleepingcomputer
-
Online retailer PcComponentes says data breach claims are fake
Online retailer PcComponentes says data breach claims are fake PcComponentes, a major technology retailer in Spain, has denied claims of a data breach on its systems impacting 16 million customers, but confirmed it suffered a credential stuffing attack. […] Bill Toulas Go to bleepingcomputer
-
New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature
New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature ClearFake has entered a new and more dangerous phase, turning a familiar fake CAPTCHA scam into a highly evasive malware delivery chain. Across hundreds of hacked websites, visitors now see what looks like a routine verification challenge, but behind the scenes…
-
Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access
Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access Cisco has disclosed a critical zero-day remote code execution (RCE) vulnerability, CVE-2026-20045, actively exploited in the wild. Affecting key Unified Communications products, this flaw allows unauthenticated attackers to run arbitrary commands on the underlying OS, potentially gaining root access. The Cisco…
-
Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access
Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access A critical vulnerability in Fortinet’s Single Sign-On (SSO) feature for FortiGate firewalls, tracked as CVE-2025-59718, is under active exploitation. Attackers are leveraging it to create unauthorized local admin accounts, granting full administrative access to internet-exposed devices. Multiple users have reported identical attack patterns,…
-
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware A large-scale campaign is turning a trusted Windows security driver into a weapon that shuts down protection tools before ransomware and remote access malware are dropped. The attacks abuse truesight.sys, a kernel driver from Adlice Software’s RogueKiller antivirus, and use more than 2,500 validly…
-
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework The cybersecurity landscape has entered a dangerous new chapter with the discovery of VoidLink, the first documented advanced malware framework built almost entirely by artificial intelligence. Unlike earlier attempts where inexperienced hackers used AI to create basic malicious…
-
Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex
Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex Cisco has released fresh patches to address what it described as a “critical” security vulnerability impacting multiple Unified Communications (CM) products and Webex Calling Dedicated Instance that it has been actively exploited as a zero-day in the wild. The vulnerability, CVE-2026-20045 (CVSS score: 8.2),…
-
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming 20 potential victim organizations spanning artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development sectors in Europe,…
-
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in denial-of-service (DoS) and remote code execution. The most severe of the lot is a critical security flaw impacting Zoom Node Multimedia Routers (MMRs) that…
-
Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff
Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff Every managed security provider is chasing the same problem in 2026 — too many alerts, too few analysts, and clients demanding “CISO-level protection” at SMB budgets. The truth? Most MSSPs are running harder, not smarter. And it’s breaking their margins. That’s where…
-
Exposure Assessment Platforms Signal a Shift in Focus
Exposure Assessment Platforms Signal a Shift in Focus Gartner® doesn’t create new categories lightly. Generally speaking, a new acronym only emerges when the industry’s collective “to-do list” has become mathematically impossible to complete. And so it seems that the introduction of the Exposure Assessment Platforms (EAP) category is a formal admission that traditional Vulnerability Management…
-
Internet Voting is Too Insecure for Use in Elections
Internet Voting is Too Insecure for Use in Elections No matter how many times we say it, the idea comes back again and again. Hopefully, this letter will hold back the tide for at least a while longer. Executive summary: Scientists have understood for many years that internet voting is insecure and that there is…
-
ISC Stormcast For Thursday, January 22nd, 2026 https://isc.sans.edu/podcastdetail/9776, (Thu, Jan 22nd)
ISC Stormcast For Thursday, January 22nd, 2026 https://isc.sans.edu/podcastdetail/9776, (Thu, Jan 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Automatic Script Execution In Visual Studio Code, (Wed, Jan 21st)
Automatic Script Execution In Visual Studio Code, (Wed, Jan 21st) Visual Studio Code is a popular open-source code editor[1]. But it’s much more than a simple editor, it’s a complete development platform that supports many languages and it is available on multiple platforms. Used by developers worldwide, it’s a juicy target for threat actors because it…
-
Smashing Security podcast #451: I hacked the government, and your headphones are next
Smashing Security podcast #451: I hacked the government, and your headphones are next In episode 451 of “Smashing Security,” we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more – and then helpfully posted screenshots (and even someone’s blood type) on an account called “I hacked the government.” Plus we discuss…
-
Pro-Russian denial-of-service attacks target UK, NCSC warns
Pro-Russian denial-of-service attacks target UK, NCSC warns The UK’s National Cyber Security Centre (NCSC) has issued a warning about the threat posed by distributed denial-of-service (DDoS) attacks from Russia-linked hacking groups who are reported to be continuing to target British organisations. Are you prepared? Read more in my article on the Hot for Security blog.…