1/29/2026

Latvia Says Russia Remains Its Top Cyber Threat as Attacks Hit Record High

Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid

Operation Winter SHIELD: FBI Issues Call to Arms for Organizations to Improve Cybersecurity

Google Disrupts Extensive Residential Proxy Networks IPIDEA

Ransomware Victim Numbers Rise, Despite Drop in Active Extortion Groups

How Can CISOs Respond to Ransomware Getting More Violent?

Patch or Perish: Vulnerability Exploits Now Dominate Intrusions

An AI Toy Exposed 50,000 Logs of Its Chats With Kids to Anyone With a Gmail Account

Open-Source AI Models Vulnerable to Criminal Misuse, Researchers Warn

U.S. Software Stocks Slump as AI Disruption Fears Take Over

ICE Is Using Palantir’s AI Tools to Sort Through Tips

Italy’s Winter Games Security Plan Keeps U.S. ICE in Advisory Role

Cybersecurity Teams Embrace AI, Just Not at the Scale Marketing Suggests

AV Vendor eScan Goes to War With Security Shop Morphisec Over Update Server Scare

France Fines National Employment Agency €5m Over 2024 Data Breach
Cyberattack on Large Russian Bread Factory The Vladimir Bread Factory Disrupts Supply Deliveries

ShinyHunters Swipes Right on 10M Records in Alleged Dating App Match Group Data Grab

Match Group Breach Exposes Data from Hinge, Tinder, OkCupid, and Match

Contractor Data Breach at TriZetto Provider Solutions May Have Exposed the Protected Health Info of Thousands of Central Oregonians

Fintech Marquis Blames Ransomware Breach on SonicWall Cloud Backup Hack

Initial Access Hackers TA584 Switch to Tsundere Bot for Ransomware Attacks

Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries

Hugging Face Abused to Spread Thousands of Android Malware Variants

Aisuru Botnet Sets New Record with 31.4 Tbps DDoS Attack

Ivanti Warns of Two EPMM flaws Exploited in Zero-Day Attacks

Google Rolls Out Android Theft Protection Feature Updates

New Apple Feature Will Block Cell Networks From Capturing Precise Location Data

New Microsoft Teams Feature Will Let You Report Suspicious Calls

NSA Pick Champions Foreign Spying Law as Nomination Advances

1/28/2026

Cyberattack on Polish Energy Grid Impacted Around 30 Facilities

Ransomware Crims Forced to Take Off-RAMP as FBI Seizes Forum

Virginia Man & Empire Cybercrime Market Owner, with Partner from Florida, Pleads Guilty to Drug Conspiracy

Teen Swatting Suspects Arrested in Hungary and Romania

Slovakian Man Pleads Guilty to Operating Darknet Marketplace

OpenAI’s ChatGPT’s Ad Costs Are on Par With Live NFL Broadcasts

Ex-Palantir Engineer Raises $40 Million for Cyber Startup Outtake, With Backing From Microsoft CEO Nadella

Trump’s Acting Cybersecurity Chief Madhu Gottumukkala Uploaded Sensitive Government Docs to ChatGPT
eScan Confirms Update Server Breached to Push Malicious Update

Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign

Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation

Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware

Autonomous System Uncovers Long-Standing OpenSSL Flaws

SolarWinds Warns of Critical Web Help Desk RCE, Auth Bypass Flaws

Critical and High Severity n8n Sandbox Flaws Allow RCE

UK Leaders Warned Country Risks ‘Absorbing’ Cyber and Hybrid Attacks Without Offensive Deterrence

FTC Commissioner Says Online Age Verification ‘Offers a Better Way’ to Protect Kids

1/27/2026

Chinese Mustang Panda Hackers Deploy Infostealers via CoolClient Backdoor

PeckBirdy Framework Tied to China-Aligned Cyber Campaigns

Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

Over 80% of Ethical Hackers Now Use AI

Revealed: Leaked Chats Expose the Daily Life of a Scam Compound’s Enslaved Workforce

He Leaked the Secrets of a Southeast Asian Scam Compound. Then He Had to Get Out Alive

WhatsApp’s New ‘Lockdown’ Settings Add Another Layer of Protection Against Cyberattacks

France to Replace U.S. Videoconferencing Wares With Unfortunately Named Sovereign Alternative

Private Equity Firm Audax Group Seeks Over $1.5 Billion for BlueCat Networks

U.S. Charges 31 More Suspects Linked to Tren de Aragua ATM Malware Attacks

Chinese Money Launderers Moved More Than $16 Billion of Illicit Crypto in 2025, Report Finds
Let Them Eat Sourdough: ShinyHunters Claims Panera Bread as Stolen Credentials Victim

Nike Investigates Data Breach After Extortion Gang Leaks Files

Russian Security Systems Firm Delta Hit by Cyberattack, Services Disrupted

Ransomware Attacks Hits Winona County (MN)

Have I Been Pwned: SoundCloud Data Breach Impacts 29.8 Million Accounts

New Malware Service ‘Stanley’ Guarantees Phishing Extensions on Chrome Web Store

WinRAR Path Traversal Flaw Still Exploited by Numerous Hackers

Fortinet Blocks Exploited FortiCloud SSO Zero Day Until Patch is ready

Pyodide Sandbox Escape Enables Remote Code Execution in Grist-Core

Critical Sandbox Escape Flaw Found in Popular vm2 NodeJS Library

Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

UK Plans Sweeping Overhaul of Policing Amid Surge in Online Crimes

1/26/2026

Krebs: Who Operates the Badbox 2.0 Botnet?

Deepfake ‘Nudify’ Technology Is Getting Darker—And More Dangerous

EU Launches Investigation Into X Over Grok-Generated Sexual Images

2025 Was a Wake-up Call to Protect Human Decisions, Not Just Systems

CISA Releases List of Post-Quantum Cryptography Product Categories

Upwind Raises $250 Million to Expand Cloud Security

Law Firm Investigates Coupang Security Failures Ahead of Class Action Deadline

Google Agrees to Pay $68 Million to Settle Voice Recording Lawsuit

Judge Awards British Critic of Saudis $4.1 Million, Finds the Regime Hacked His Devices
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware

New ClickFix Attacks Abuse Windows App-V Scripts to Push Malware

eScan Antivirus Supply Chain Breach Delivers Signed Malware

Researchers Uncover “Haxor” SEO Poisoning Marketplace

Cloudflare Misconfiguration Behind Recent BGP Route Leak

Hackers Can Bypass npm’s Shai-Hulud Defenses via Git Dependencies

Microsoft Patches Actively Exploited Office Zero-Day Vulnerability

Supreme Court to Hear Facebook Pixel Tracking Case

Romania Probes Two Suspects Over Alleged Hitman-For-Hire Website

1/23-25/2026

New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

Konni Hackers Target Blockchain Engineers With AI-Built Malware

Millions of People Imperiled Through Sign-in Links Sent by SMS

Gmail’s Spam Filter and Automatic Sorting Are Broken

Ring Can Verify Videos Now, but That Might Not Help You With Most AI Fakes

TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order

U.S. to Deport Venezuelans Who Emptied Bank ATMs Using Malware

UK Border Tech Budget Swells by £100M as Home Office Targets Small Boat Crossings

Germany Expels Russian Diplomat Accused of Spying on Ukraine War Effort

China Investigates Top General Zhang Youxia in Rare Purge of Senior Military Leaders

U.S. Storm Leaves 850,000 Without Power, Forces 10,000 Flight Cancellations
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware

Cyberattack Disrupts Digital Systems at Renowned Dresden Museum Network

149 Million Usernames and Passwords Exposed by Unsecured Database

ShinyHunters Claims Okta Customer Breaches, Leaks Data Belonging to 3 Orgs

Nike Probing Potential Security Incident as Hackers Threaten to Leak Data

Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access

Malicious AI Extensions on VSCode Marketplace Steal Developer Data

Fortinet Confirms Critical FortiCloud Auth Bypass Not Fully Patched

CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities

CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog

Hackers Get $1,047,000 for 76 Zero-Days at Pwn2Own Automotive 2026

1/22/2026

From a Whisper to a Scream: Europe Frets About Overreliance on U.S. Tech

Risky Chinese Electric Buses Spark Aussie Gov’t Review

Spanish Judge Closes NSO Group Spyware Probe Due to Lack of Cooperation From Israel

Claude’s New AI File-Creation Feature Ships With Security Risks Built In

Crims Compromised Energy Firms’ Microsoft Accounts, Sent 600 Phishing Emails

Microsoft Teams to Add Brand Impersonation Warnings to Calls

1Password Is Introducing a New Phishing Prevention Feature

House of Lords Backs Legislation to Ban Social Media for Children Under 16

Bank of England: Financial Sector Failing to Implement Basic Cybersecurity Controls

Over 160,000 Companies Notify Regulators of GDPR Breaches

Europe’s GDPR Cops Dished Out €1.2B in Fines Last Year as Data Breaches Piled Up

INC Ransomware Opsec Fail Allowed Data Recovery for 12 U.S. Orgs
Hackers Breach Fortinet FortiGate Devices, Steal Firewall Configs

Fortinet Firewalls Hit With Malicious Configuration Changes

Jordan Used Cellebrite Phone-Hacking Tools Against Activists Critical of Gaza War, Report Finds

Okta SSO Accounts Targeted in Vishing-Based Data Theft Attacks

New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts

SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release

RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites

Critical Appsmith Flaw Enables Account Takeovers

Hackers Exploit 29 Zero-Days on Second Day of Pwn2Own Automotive

Curl Ending Bug Bounty Program After Flood of AI Slop Reports

1/21/2026

North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

Phishing and Spoofed Sites Remain Primary Entry Points For Olympics

Hackers Exploit Security Testing Apps to Breach Fortune 500 Firms

Fortinet Admins Report Patched FortiGate Firewalls Getting Hacked

New Android Malware Uses AI to Click on Hidden Browser Ads

Greek Police Arrest Scammers Using Fake Cell Tower Hidden in Car Trunk

Ireland Wants to Give Its Cops Spyware, Ability to Crack Encrypted Messages

EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act

UK’s NCC Group to Sell Escode for $369.4 Million
Everest Ransomware Gang Said to Be Sitting on Mountain of Under Armour Data

Online Retailer PcComponentes Says Data Breach Claims are Fake

Peruvian Loan Scam Harvests Cards and PINs via Fake Applications

LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Cisco Fixes Unified Communications RCE Zero Day Exploited in Attacks

Tesla Hacked, 37 Zero-Days Demoed at Pwn2Own Automotive 2026

Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch

1/20/2026

North Korea-Linked Hackers Target Developers via Malicious VS Code Projects

EU Plan to Phase-Out High-Risk Tech Draws Fire From China’s Huawei

Greece, Israel to Cooperate on Anti-Drone Systems, Cybersecurity, Greek Minister Says

Krebs: Kimwolf Botnet Lurking in Corporate, Gov’t Networks

UK Launches Landmark ‘Report Fraud’ Service to Tackle Cybercrime and Fraud

Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

Cyber Risks Among CEOs’ Top Worries Amid Weak Short Term Growth Outlook

AI Supercharges Attacks in Cybercrime’s New ‘Fifth Wave’

VoidLink Cloud Malware Shows Clear Signs of Being AI-Generated

True Agentic AI Is Years Away – Here’s Why and How We Get There

Supreme Court to Consider Whether Geofence Warrants Are Constitutional

UK Says It Will Consider Banning Social Media for Children
Hackers Target Afghan Government Workers With Fake Correspondence From Senior Officials

Linkedin Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs

Numerous Mass Spam Attacks Leverage Zendesk Instances

UStrive Security Lapse Exposed Personal Data of Its Users, Including Children

Minnesota Department of Human Services Data Breach Affects Over 300K Individuals

Everest Ransomware Claims McDonalds India Breach Involving Customer Data

Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto

ACF Plugin Bug Gives Hackers Admin on 50,000 WordPress Sites

Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers

Chainlit Security Flaws Highlight Infrastructure Risks in AI Apps

Prompt Injection Bugs Found in Official Anthropic Git MCP Server

Lawmakers Move to Extend Two Cyber Programs (Again) in Funding Proposal

1/19/2026

Iran to Consider Lifting Internet Ban; State TV Hacked to Air Anti-Regime Messages

Russian Hacktivists Intensify Disruptive Cyber Pressure on UK Orgs

Read the Texts Between Trump and Norway’s Prime Minister

How Crypto Criminals Stole $700 Million From People – Often Using Age-Old Tricks
Ingram Micro Admits Summer Ransomware Raid Exposed Thousands of Staff Records

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Researchers Uncover PDFSIDER Malware Built for Long-Term, Covert System Access

Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites

1/16-18/2026

China-Linked Hackers Exploited Sitecore Zero-Day for Initial Access

Trump Says Iran Has Told Him ‘Killing Has Stopped’ as He Pulls Back From Strike Threats

Donald Trump Calls off Iran Strikes After Steve Witkoff, Araghchi Texts

By Asking Trump to Delay Iran Attacks, Netanyahu Exposes Israel’s Air Defense Holes

Anti-Regime Activists Hack Iran’s National Broadcaster, Transmit Pahlavi’s Calls to Protest

Canada Will Regret Allowing Chinese EVs Into Their Market, U.S. Says

EU Moves to Force the Phase-Out of Chinese Suppliers From Key Infrastructure

A Faceless Hacker Stole My Therapy Notes – Now My Deepest Secrets Are Online Forever

Jordanian Initial Access Broker Pleads Guilty to Helping Target 50 Companies

Police Raid Homes of Alleged Black Basta Hackers, Hunt Suspected Russian Ringleader

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
Canadian Investment Regulatory Organization (CIRO) Confirms Data Breach Exposed Info on 750,000 Canadian Investors

Tens of Millions of French Citizen Records Exposed

TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals

RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation Wave

Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection

Malicious GhostPoster Browser Extensions Found with 840,000 Installs

Hackers Now Exploiting Critical Fortinet FortiSIEM Flaw in Attacks

StealC Hackers Hacked as Researchers Hijack Malware Control Panels

Cisco Finally Fixes AsyncOS Zero-Day Exploited Since November

I’m Sorry Dave, I’m Afraid I Can’t Do That! PCs Refuse to Shut Down After Microsoft Patch

1/15/2026

Chinese-Linked Hackers Target U.S. Entities With Venezuelan-Themed Malware

ICE Agent Doxxing Site DDoS-ed Via Russian Servers

Hackers Increasingly Shun Encryption in Favour of Pure Data Theft and Extortion

Former CISA Director Jen Easterly Will Lead RSAC Conference

FTC Bans GM From Selling Drivers’ Location Data for Five Years

Google to Pay $8.25 Million to Settle Lawsuit Alleging Children’s Privacy Violations

Elon Musk’s X Says It Will Block Grok From Making Sexual Images

Data Privacy Teams Face Staffing Shortages and Budget Constraints, ISACA Warns

Cloudflare Acquires AI Data Marketplace Human Native

Former U.S. Special Forces Officer Is Now a Startup CEO—His Cybersecurity Company Has Raised $22 Million
Verizon’s Hourslong Wireless Outage Tied to Software Update

Grubhub Confirms Hackers Stole Data in Recent Security Breach

Anchorage Police Department Takes Servers Offline After Cyberattack on Service Provider

Contagious Claude Code Bug Anthropic Ignored Promptly Spreads to Cowork

WhisperPair: Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking

Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

Trio of Critical Bugs Spotted in Delta Industrial PLCs

CodeBuild Flaw Put AWS Console Supply Chain At Risk

Germany Turns to Israel for a ‘Cyber Dome’ Amid Rising Threats

1/14/2026

PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces

Ukraine Appoints Digital Chief as Defense Minister to Drive Military Reform

Western Cyber Agencies Warn About Threats to Industrial Operational Technology

Beijing Tells Chinese Firms to Stop Using U.S. and Israeli Cybersecurity Software, Sources Say

Lawmakers to Restart Efforts to Revive Lapsed Cyber Intel Bill

Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers

Criminal Subscription Service Behind AI-Powered Cyber-Attacks Taken Out By Microsoft

Verizon Outage Knocks Out U.S. Mobile Service, Including Some 911 Calls

France Fines Telcos €42M for Sub-Par Security Prior to 24M Customer Breach

Palantir Is Trying to ‘Destroy’ Percepta Through Legal Action, Startup’s Execs Say in Filing

Google’s Personal Intelligence links Gmail, Photos and Search to Gemini

California AG to Probe Musk’s Grok for Nonconsensual Deepfakes

Ugandan Officials Turn Off Internet on Eve of National Elections
Victorian Department of Education Says Hackers Stole Students’ Data

Monroe University Says 2024 Data Breach Affects 320,000 People

South Korean Giant Kyowon Confirms Data Theft in Ransomware Attack

Cloud Marketplace Pax8 Accidentally Exposes Data on 1,800 MSP Partners

Reprompt Attack Hijacked Microsoft Copilot Sessions for Data Theft

Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs

DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation

Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution

Krebs: Patch Tuesday, January 2026 Edition

Federal Agencies Ordered to Patch Microsoft Desktop Windows Manager Bug

Microsoft Updates Windows DLL That Triggered Security Alerts

1/13/2026

Massive Cyberattack on Polish Power System in December Failed, Minister Says

Hill Warning: Don’t Put Cyber Offense Before Defense

Trump Renominates Sean Plankey for CISA Director

Ukraine Parliament Approves Resignation of Security Service Chief in Major Reshuffle

Kremlin-Linked Hackers Pose as Charities to Spy on Ukraine’s Military

Senior Military Cyber Operator Removed From Russia Task Force

More Than 40 Countries Impacted by North Korea IT Worker Scams, Crypto Thefts

Oracle Hack Still Generating Ransom Demands

India’s Smartphone Security Proposal Faces Backlash Over Privacy Concerns

Quantum Software Company Haiqu Raises $11 Million

AI and Automation Could Erase 10.4 Million U.S. Roles by 2030

What’s the Deal With Physical AI? Why the Next Frontier of Tech Is Already All Around You

Teen Hackers Recruited Through Fake Job Ads

Tennessee Man to Plead Guilty to Hacking Supreme Court’s Electronic Case Filing System

Dutch Cops Cuff Alleged AVCheck Malware Kingpin in Amsterdam
Target Employees Confirm Leaked Source Code Is Authentic

Suspected Ransomware Attack Threatens One of South Korea’s Largest Companies, Kyowon Group

Everest Ransomware Group Claims Nissan Breach, Demands Response

Central Maine Healthcare Breach Exposed Data of Over 145,000 People

Belgian Hospital AZ Monica Shuts Down Servers After Cyberattack

VoidLink: New Chinese-Made Malware Framework Targets Linux-Based Cloud Environments

Global Magecart Campaign Targets Six Card Networks

SHADOW#REACTOR Campaign Uses Text-Only Staging to Deploy Remcos RAT

Convincing LinkedIn Comment-Reply Tactic Used in New Phishing

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Popular Python Libraries Used in Hugging Face Models Subject to Poisoned Metadata Attack

Adobe Patches Critical Apache Tika Bug in ColdFusion

Microsoft January 2026 Patch Tuesday Fixes 3 Zero-Days, 114 Flaws

Microsoft Releases Windows 10 KB5073724 Extended Security Update

New Windows Updates Replace Expiring Secure Boot Certificates

1/12/2026

Internet Monitoring Experts Say Iran Blackout Likely to Continue

Sweden Detains Ex-Military IT Consultant Suspected of Spying for Russia

Hungary Grants Asylum to Former Polish Minister Implicated in Spyware Probe

World Economic Forum: Cyber-Fraud Overtakes Ransomware as Business Leaders’ Top Cyber-Security Concern

Illicit Crypto Activity Hits Record $158bn in 2025

Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud

Ofcom Officially Investigating X as Grok’s Nudify Button Stays Switched On

Palo Alto Networks Introduces New Vibe Coding Security Governance Framework

Hacker Gets Seven Years for Breaching Rotterdam and Antwerp Ports

‘Violence-As-A-Service’ Suspect Arrested in Iraq, Extradition Underway

Kentucky Sues Character.AI, Alleging It Harms Children and Violates Data Law

Anthropic Brings Claude to Healthcare with HIPAA-Ready Enterprise Tools
University of Hawaii Cancer Center Hit by Ransomware Attack

Spanish Energy Giant Endesa Discloses Data Breach Affecting Customers

‘Bad Actor’ Hijacks Apex Legends Characters in Live Matches

Target’s Dev Server Offline After Hackers Claim to Steal Source Code

Armenia Probes Alleged Sale of 8 Million Government Records on Hacker Forum

Fintech Firm Betterment Confirms Data Breach After Hackers Send Fake Crypto Scam Notification to Users

Instagram Denies Breach After Many Receive Emails Asking to Reset Password

Facebook Login Thieves Now Using Browser-In-Browser Trick

Hidden Telegram Proxy Links Can Reveal Your IP Address in One Click

n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens

CISA Orders Feds to Patch Gogs RCE Flaw Exploited in Zero-Day Attacks

Apple Confirms Google Gemini Will Power Siri, Says Privacy Remains a Priority

Torq Raises $140 Million for Agentic AI-Powered Cybersecurity Platform

1/9-11/2026

China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines

Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

World Economic Forum: Deepfake Face-Swapping Tools Are Creating Critical Security Risks

Krebs: Who Benefited from the Aisuru and Kimwolf Botnets?

Europol Leads Global Crackdown on Black Axe Cybercrime Gang, 34 Arrested

X Didn’t Fix Grok’s ‘Undressing’ Problem. It Just Makes People Pay for It

Lawmakers Call On App Stores to Remove Grok, X Over Sexualized Deepfakes

Illinois Man Charged With Hacking Snapchat Accounts to Steal Nude Photos

Ireland Recalls Almost 13,000 Passports Over Missing ‘IRL’ Code

California Bans Data Broker Reselling Health Data of Millions

Stellar Gains, Heavy Losses: Cybersecurity Stocks Had a Mixed Year

Here’s What Cloud Security’s Future Holds for the Year Ahead
BreachForums Hacking Forum Database Leaked, Exposing 324,000 Accounts

Ransomware Attack on Texas Gas Station Firm Gulshan Management Services Leaks 377,000 User Records

At Least $26 Million in Crypto Stolen From Truebit Platform as Crypto Crime Landscape Evolves

AI-Powered Truman Show Operation Industrializes Investment Fraud

Betterment’s Financial App Sends Customers a $10,000 Crypto Scam Message

Warning Over Scams Targeting Manx Email Accounts

Instagram Says It Fixed the Issue That Let Someone Send All Those Password Reset Emails

FBI Warns of North Korean QR Phishing Campaigns

Hackers Target Misconfigured Proxies to Access Paid LLM Services

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024

UK Government Exempting Itself From Flagship Cyber Law Inspires Little Confidence

Former NSA Insider Kosiba Brought Back as Spy Agency’s No. 2

1/8/2026

China Hacked Email Systems of U.S. Congressional Committee Staff

U.S. To Leave Global Forum on Cyber Expertise

NSA Cyber Directorate Gets New Acting Leadership

Venezuela Raid Highlights Cyber Vulnerability of Critical Infrastructure

ChatGPT Health Feature Draws Concern From Privacy Critics Over Sensitive Medical Data

Grok Is Generating Sexual Content Far More Graphic Than What’s on X

CrowdStrike Buys Identity Security Startup SGNL for $740 Million in Latest Deal Push

Cyera Valued at $9 Billion as Data Security Firm Raises $400 Million

EU Antitrust Regulators to Decide on Google’s Wiz Deal by February 10

Texas Court Blocks Samsung From Tracking TV Viewing, Then Vacates Order

Ransomware Attacks Kept Climbing in 2025 as Gangs Refused to Stay Dead

Two-Fifths of 50% of Breaches Take Two Weeks to Recover From

Russia Frees French Researcher in Prisoner Swap for Alleged Ransomware Hacker
China-Linked UAT-7290 Targets Telecom Networks in South Asia

Iran-Linked Hacker Group Claims to Have Hacked, Surveilled Senior Mossad Agent

More Than 100,000 Households Warned After Cyber Attack on Kensington and Chelsea Council

Sedgwick Breach Linked to TridentLocker Ransomware Attack

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

GoBruteforcer Botnet Targets Linux Servers

Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages

New Zero-Click Attack Lets ChatGPT User Steal Data

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited

Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances

Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release

Cisco Switches Hit by Reboot Loops Due to DNS Client Bug

Microsoft to Enforce MFA for Microsoft 365 Admin Center Sign-Ins

1/7/2026

Cyberattacks Likely Part of Military Operation in Venezuela

European Space Agency Calls Cops as Crims Lift Off 500 GB of Files, Say Security Black Hole Still Open

Taiwan Says China’s War Games Sought to Undermine Global Support for the Island

China Intensifies Cyber-Attacks on Taiwan as Energy Sector Sees Tenfold Spike

Grok AI Still Being Used to Digitally Undress Women and Children Despite Suspension Pledge

IBM’s AI Agent Bob Easily Duped to Run Malware, Researchers Show

Google Search AI Hallucinations Push Google to Hire “AI Answers Quality” Engineers

Personal LLM Accounts Drive Shadow AI Data Leak Risks

Cloudy Outlook for Cyber Jobs as AI Fills Security Gaps

Stalkerware Operator Pleads Guilty in Rare Prosecution

Alleged Cyber Scam Kingpin Arrested, Extradited to China
MFA Failure Enables Infostealer Breach At 50 Enterprises

Illinois Department of Human Services Reports Yearslong Data Breach

Cyberattack Under Investigation by Coles County School District (IL)

Spanish Airline Iberia Attributes Recent Data Breach Claims to November Incident

Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches

Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud

Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads

Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing

Critical jsPDF Flaw Lets Hackers Steal Secrets via Generated PDFs

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication

Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control

1/6/2026

Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government

UK Launches New Cyber Unit to Bolster Defences Against Cyber Threats

UK Government Admits Years of Cyber Policy Have Failed, Announces Reset

Ring’s Mobile Security Trailer Provides 360-Degree Coverage Anywhere

Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

Jaguar Land Rover Wholesale Volumes Down 43% After Cyberattack

Startup Trends Shaking Up Browsers, SOC Automation, AppSec

Cybersecurity Predictions 2026: An AI Arms Race and Malware Autonomy
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat

Hospitality Sector Hit By PHALT#BLYX ClickFix Malware Campaign

Cloud File-Sharing Sites Targeted for Corporate Data Theft Attacks

High-Severity Flaw in Open WebUI Affects AI Connections

New D-Link Flaw in Legacy DSL Routers Actively Exploited in Attacks

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers

Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover

1/5/2026

Russian Hackers Target European Hospitality Industry With ‘Blue Screen of Death’ Malware

The French University Where Spies Go for Training

As Supply-Chain Cyber Risks Mount, Can AI Help?

EU Looking ‘Very Seriously’ at Taking Action Against X Over Grok

Finland Arrests Two Crew Members of Ship Suspected of Cable Break

Playing Koi: Palo Alto Isn’t Saying if It Will Buy Security Start-up

VSCode IDE Forks Expose Users to “Recommended Extension” Attacks
New Zealand Orders Review Into ManageMyHealth Cyberattack

Aurora College Working to Get Systems Back Up After Cyber Attack

Cyberattack Forces British High School to Close

Ledger Customers Impacted by Third-Party Global-E Data Breach

U.S. Broadband Provider Brightspeed Investigates Breach Claims

NordVPN Denies Breach Claims, Says Attackers Have “Dummy Data”

VVS Stealer Uses Advanced Obfuscation to Target Discord Users

1/2-4/2026

Inside the Operation: How the U.S. Moved to Capture Nicolás Maduro

Trump Suggests U.S. Used Cyberattacks to Turn Off Lights in Venezuela During Strikes

Krebs: The Kimwolf Botnet is Stalking Your Local Network

8 WhatsApp Features to Boost Your Security and Privacy

How to Protect Your iPhone or Android Device From Spyware

Trump Admin Sends Heart Emoji to Commercial Spyware Makers With Lifted Predator Sanctions

Bitfinex Crypto Thief Who Was Serving Five Years Thanks Trump for Early Release

Palo Alto Networks Security-Intel Boss Calls AI Agents 2026’s Biggest Insider Threat

Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats
Cybercrook Claims to Be Selling Infrastructure Info About Three Major U.S. Utilities

Hackers Claim to Hack Resecurity, Firm Says It Was a Honeypot

Sedgwick Confirms Cyber Incident Affecting Its Major Federal Contractor Subsidiary

Trust Wallet Links $8.5 Million Crypto Theft to Shai-Hulud NPM Attack

Covenant Health Says May Data Breach Impacted Nearly 478,000 Patients

Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign

Over 10K Fortinet Firewalls Exposed to Actively Exploited 2FA Bypass

12/30-31/2025

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

Finland Seizes Ship Suspected of Damaging Subsea Cable in Baltic Sea

Washington Wants to Get Tough on Nation-State Hackers. Are Infrastructure Operators Ready?

Fears Mount That U.S. Federal Cybersecurity Is Stagnating—Or Worse

Two Cybersecurity Employees Plead Guilty to Carrying Out Ransomware Attacks

Meta Created ‘Playbook’ to Fend Off Pressure to Crack Down on Scammers, Documents Show

Hong Kong’s Newest Anti-Scam Technology: Over-The-Counter Banking

New York’s Incoming Mayor Zohran Mamdani Bans Raspberry Pi at His Inauguration Party

And Flipper Zero

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

Disney Will Pay $10 Million to Settle Children’s Data Privacy Lawsuit

Coupang to Split $1.17 Billion Among 33.7 Million Data Breach Victims
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

European Space Agency Hit Again as Cybercrims Claim 200 GB Data up for Sale

Hackers Drain $3.9M From Unleash Protocol After Multisig Hijack

DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide

Zoom Stealer Browser Extensions Harvest Corporate Meeting Intelligence

New ERRTraffic Service Enables ClickFix Attacks via Fake Browser Glitches

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry

RondoDox Botnet Exploits React2Shell Flaw to Breach Next.js Servers

US, Australia Say ‘MongoBleed’ Bug Being Exploited

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass