3/12/2026

Stryker Tells SEC That Timeline for Recovery From Cyberattack Unknown

Stryker Cyberattack Adds to Fears of New Front in Iran War

How ‘Handala’ Became the Face of Iran’s Hacker Counterattacks

What Role Has Cyber Warfare Played in Iran?

New Data Shows Increase in FBI Searches of Americans’ Data Last Year

U.S. Lawmakers Move to Kill the FBI’s Warrantless Wiretap Access

Police Scotland Fined After Sharing Victim’s Phone Data

U.S. Charges Another Ransomware Negotiator Linked to BlackCat Attacks

Operation Lightning Takes Down SocksEscort Proxy Network Blamed for Tens of Millions in Fraud

U.S. Sanctions North Korea IT Worker Networks in Laos, Vietnam

China’s CERT Warns OpenClaw Can Inflict Nasty Wounds

Israeli Cyber Firm Onyx Security Launches Operations With $40 Million Funding Round

UK Regulators Demand Social Media Platforms Make It Harder for Kids Under 13 to Access Sites
Lloyds, Bank of Scotland and Halifax Apps Showed Customers Other Users’ Transactions

Telus Says It Is Investigating Hack of Its Systems

England Hockey Investigating Ransomware Data Breach

INC Ransomware Group Holds Healthcare Hostage in Oceania

Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays

PixRevolution Malware Hijacks Brazil’s PIX Transfers in Real Time

Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets

Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks

CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed

CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws

Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit

Veeam Warns of Critical Flaws Exposing Backup Servers to RCE Attacks

Google Paid $17.1 Million for Vulnerability Reports in 2025

3/11/2026

Krebs: Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

Iran Plots ‘Infrastructure Warfare’ Against Multiple U.S. Tech Giants

Iran-Linked Hackers Claim Cyberattack on Albania’s Parliament Email Systems

Iranian Influence Operation Using Fake Personas to Deceive U.S. Instagram Users Disrupted, Meta Says

Meta Ramps up Efforts to Disrupt Industrialized Scamming

AI Cyber Startup Kai Raises $125 Million

Senators Propose Federal AI Commission Days After Anthropic Ban

Researchers Discover Major Security Gaps in LLM Guardrails

Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes

Foreign Hacker in 2023 Compromised Epstein Files Held by FBI, Source and Documents Show
238,000 Impacted by Bell Ambulance Data Breach

UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

New Phantomraven npm Attack Wave Steals Dev Data via 88 Packages

Xygeni GitHub Action Compromised Via Tag Poison

SQLi Flaw in Elementor Ally Plugin Impacts 250k+ WordPress Sites

Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

Krebs: Microsoft Patch Tuesday, March 2026 Edition

France: National Cybersecurity Agency Reports Ransomware Attack Drop in 2025

Cyber-Attacks on UK Firms Increase at Four Times Global Rate

WhatsApp Introduces Parent-Managed Accounts for Pre-Teens

3/10/2026

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

Finnish Intelligence Warns of Persistent Cyber Espionage From Russia, China

Israeli Cyber Authority Uses AI to Mock Iranian Hackers, Counter Psychological Warfare

Cybercrime Isn’t Just a Cover for Iran’s Government Goons – It’s a Key Part of Their Operations

GPS Attacks Near Iran Are Wreaking Havoc on Delivery and Mapping Apps

Signal Issues Scam Warning to Users After Hackers Target Officials

Your Data Has Been Breached! (And This Notice Is a Scam!)

Cloud Attackers Now Prefer Vulnerability Exploits Over Credentials, Google Cloud Finds

U.S. Judiciary to Fast-Track Court Records System Upgrade After Hacking

Meta Acquires AI Agent Social Network Moltbook

OpenAI’s Promptfoo Deal Plugs Agentic AI Testing Gap

Microsoft Brings Phishing-Resistant Windows Sign-Ins via Entra Passkeys
KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

New BeatBanker Android Malware Poses as Starlink App to Hijack Devices

New ‘BlackSanta’ EDR Killer Spotted Targeting HR Departments

Crooks Compromise WordPress Sites to Push Infostealers via Fake CAPTCHA Prompts

New ‘Zombie ZIP’ Technique Lets Malware Slip Past Security Tools

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

HPE Warns of Critical AOS-CX Flaw Allowing Admin Password Resets

Critical Microsoft Excel Bug Weaponizes Copilot Agent for Zero-Click Information Disclosure Attack

UK Plans to Shift Fraud Fight Onto Telecoms, Tech Companies

Rudd Confirmed to Head NSA, Cyber Command After Near Year-Long Vacancy

3/9/2026

Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

Dutch Gov’t Warns of Russian Signal, WhatsApp Account Hijacking Attacks

Krebs: How AI Assistants are Moving the Security Goalposts

AI vs AI: Agent Hacked McKinsey’s Chatbot and Gained Full Read-Write Access in Just Two Hours

FBI Warns of Phishing Attacks Impersonating U.S. City, County Officials

UK Launches New Crackdown Unit to Tackle Cyber-Fraud at the Source

White House Floats Victims Restoration Program for Millions Affected by Cyber Fraud

New White House Cyber Strategy Pledges to Ease Regulations, ‘Impose Costs’ on Bad Actors

CrowdStrike Sues Rival AiStrike for Trademark Infringement
ShinyHunters Claims More High-Profile Victims in Latest Salesforce Customers Data Heist

Ericsson U.S. Discloses Data Breach After Service Provider Hack

Ontario Health Agency Vendor Suffered Major Ransomware Attack in 2025

Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data

Microsoft Teams Phishing Targets Employees With A0Backdoor Malware

Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft

Google: Cloud Attacks Exploit Flaws More Than Weak Credentials

Are We Ready for Auto Remediation With Agentic AI?

Trump Nominee Lt. Gen. Joshua Rudd to Lead Cyber Command, NSA Clears Key Senate Hurdle

3/6-8/2026

FBI Investigates Breach of Surveillance and Wiretap Systems

China Suspected in Breach of FBI Surveillance Network

China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks

Mojtaba Khamenei to Succeed His Father as Iran’s Supreme Leader

Iran Internet Blackout Reaches 6th Day as Rights Groups Call for End to Digital Shutdown

The Future of Iran’s Internet Is More Uncertain Than Ever

Iran’s MuddyWater Hackers Hit US Firms with New ‘Dindoor’ Backdoor

White House Publishes Long-Awaited Cybersecurity Strategy

Trump Signs Executive Order Aimed at Cybercrime Gangs

CBP Used Online Ad Data to Track Phone Locations

Online Age-Verification Tools Spread Across U.S. For Child Safety, but Adults Are Being Surveilled

Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester

Palantir Rallies 15% for the Week as Iran War Boosts Prospects, Muting Anthropic Concern

AI Agents Now Help Attackers, Including North Korea, Manage Their Drudge Work

Speakeasies to Shadow AI: Banning AI Browsers Will Fail

EU Court Adviser Says Banks Must Immediately Refund Phishing Victims

Ghanain Man Pleads Guilty to Role in $100 Million Fraud Ring
TfL Hack in 2024 Affected Around 10 Million People, BBC Can Reveal

DeKalb County (IN) Officials Release Data Breach Notice to Residents

Tennis Player Shares Threats Sent to Personal Phone, WTA Tour Says No Breach of Private Data

Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting India

Bing AI Promoted Fake OpenClaw GitHub Repo Pushing Info-Stealing Malware

Fake Claude Code Install Guides Push Infostealers in InstallFix Attacks

Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT

Termite Ransomware Breaches Linked to ClickFix CastleRAT Attacks

Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

Hackers Abuse .arpa DNS and ipv6 to Evade Phishing Defenses

Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog

CISA Warns Feds to Patch iOS Flaws Exploited in Crypto-Theft Attacks

OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model

Ransomware’s New Target: The Systems Built to Recover From It

Indonesia to Ban Children Under 16 From Social Media

3/5/2026

Israel Says It Knocked Out Iran’s Cyber Warfare Headquarters

How Israel’s Cyber Chief Is Navigating Through the Dystopian Cyber-AI Period

Iran’s Pro-Regime Hackers Cannot Back Up Their Claims of Successful Cyber Attacks

How a Music Streaming CEO Built an Open-Source Global Threat Map in His Spare Time

Trump, Bondi Face Lawsuit Over Approval of ByteDance TikTok U.S. Asset Sale

Police Dismantles Online Gambling Ring Exploiting Ukrainian Women

FBI Arrests Suspect Linked to $46M Crypto Theft From U.S. Marshals

62 People Indicted by Taiwanese Prosecutors Over Ties to Cyber Scam Company Prince Group

Phobos Ransomware Admin Pleads Guilty to Wire Fraud Conspiracy
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware

Italian Prosecutors Confirm Journalist Was Hacked With Paragon Spyware

Passaic County (NJ) IT Systems Hacked as Officials Warn Other NJ Towns May Be Targeted

Wikipedia Hit by Self-Propagating JavaScript Worm That Vandalized Pages

ContextCrush Flaw Exposes AI Development Tools to Attacks

AI-Driven Insider Risk Now a “Critical Business Threat,” Report Warns

Cisco Flags More SD-WAN Flaws as Actively Exploited in Attacks

WordPress Membership Plugin Bug Exploited to Create Admin Accounts

Google Says 90 Zero-Days Were Exploited in Attacks Last Year

3/4/2026

Multi-Stage “BadPaw” Malware Campaign Targets Ukraine

APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2

Surge in Attacks on Surveillance Cameras Linked to Iranian Hackers

149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict

How Vulnerable Are Computers to an 80-Year-Old Spy Technique? Congress Wants Answers

Spyware-Grade Coruna iOS Exploit Kit Now Used in Crypto Theft Attacks

Kaspersky Dismisses Claims Coruna iPhone Exploit Kit Is Connected to NSA-Linked Operation

Anthropic ‘Made a Mistake’ in Pentagon Talks and Should ‘Correct Course,’ FCC Boss Says

U.S. and EU Police Shut Down LeakBase, a Site Accused of Sharing Stolen Passwords and Hacking Tools

Microsoft Helps Bust Global Hacking Service Tycoon 2FA
Mississippi Medical Center Reopens Clinics Hit by Ransomware Attack

Hacker Mass-Mails HungerRush Extortion Emails to Restaurant Patrons

Fake LastPass Support Email Threads Try to Steal Vault Passwords

Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux

Cisco Warns of Max Severity Secure FMC Flaws Giving Root Access

Mail2Shell Zero-Click Attack Lets Hackers Hijack FreeScout Mail Servers

CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog

Bitwarden Adds Support for Passkey Login on Windows 11

Calls for Global Digital Estate Standard as Posthumous Deepfake Fraud Risk Grows

Stranger Things Meets Cybersecurity: Lessons from the Hive Mind

3/3/2026

Hack of Cameras, AI Use: Wide Cyberattack on Iran Preceded Khamenei Killing

Israel: RedAlert Spyware Campaign Exploits Wartime Panic With Trojanized App

Iranian Cyber Threat Actor Targets Iraqi Government Officials in AI-Powered Campaign

Iranian Drone Strikes Hit Amazon Data Centers in Gulf, Disrupting Cloud Services

Leaked Database Sheds Light on Iranian Crypto Sanctions Evasion

The Lead U.S. Cyber Agency Is Stretched Thin as Iran Hacking Threat Escalates

Cyberwarriors Elevated to Big Leagues in U.S. War With Iran

U.S. Banks on High Alert for Cyberattacks as Iran War Escalates

A Possible U.S. Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals

How Journalists Are Reporting From Iran With No Internet

With Developer Verification, Google’s Apple Envy Threatens to Dismantle Android’s Open Legacy

Western Allies Form 6G Security Coalition Amid Tech Rivalry With China

Google Urges Supreme Court to Strike Down Geofence Warrants as Unconstitutional
LexisNexis Confirms Data Breach as Hackers Leak Stolen Files

Paint Maker Giant AkzoNobel Confirms Cyberattack on u.s. Site

Star Citizen Game Dev Discloses Breach Affecting User Data

Until Last Month, Attackers Could’ve Stolen Info From Perplexity Comet Users Just by Sending a Calendar Invite

Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

AI and Deepfakes Supercharge Sophisticated Cyber-Attacks, Says Cloudflare

Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited

Google Chrome Shifts to Two-Week Release Cycle for Increased Stability

Huge “Shadow Layer” of Organizations Hit by Supply Chain Attacks

Half of U.S. CISOs Work the Equivalent of a Six-Day Week

Chat at Your Own Risk! Data Brokers Are Selling Deeply Personal Bot Transcripts

Turns Out Most Cybercriminals Are Old Enough to Know Better

California Fines National High School Ticketing Platform $1.1 Million for Privacy Violations

3/2/2026

Cyber Command Disrupted Iranian Comms, Sensors, Top General Says

Expect Iran to Launch Cyber-Attacks Globally, Warns Google Head of Threat Intel

UK Warns of Iranian Cyberattack Risks Amid Middle-East Conflict

Iran-Backed Hackers Aim for Economic Disruption

Hybrid Middle East Conflict Triggers Surge in Global Cyber Activity

Attacks on GPS Spike Amid U.S. and Israeli War on Iran

Space Has Become ‘War-Fighting Domain’ as Militaries Race to Orbit, SES Chief Says

CyberStrikeAI Tool Adopted by Hackers for AI-Powered Attacks

Florida Woman Imprisoned for Massive Microsoft License Fraud Scheme

Alabama Man Pleads Guilty to Hacking, Extorting Hundreds of Women

German Court Convicts Alleged Mastermind Behind Global Investment Scam Network
Anthropic Confirms Claude Is Down in a Worldwide Outage Across All Platforms

Cyberattack Briefly Disrupts Russian Internet Regulator and Defense Ministry Websites

Russian Propaganda Network Uses ChatGPT to Plan Influence Operations in Africa

APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday

North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT

Alleged India-Linked Espionage Campaign Targeted Pakistan, Bangladesh, Sri Lanka

Phish of the Day: Microsoft OAuth Scams Abuse Redirects for Malware Delivery

Fake Google Security Site Uses PWA App to Steal Credentials, MFA Codes

New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel

Chrome Unveils Plan For Quantum-Safe HTTPS Certificates

2/27-3/1/2026

Iran’s Supreme Leader Ayatollah Ali Khamenei Killed in Major Attack by U.S. and Israel

Ahead of Strikes, Trump Was Told Iran Attack Is High Risk, High Reward

Israel Hacked Popular Iranian Prayer App to Urge Defections, Resistance

Hackers Hit Iranian Apps, Websites After U.S.-Israeli Strikes

Why the U.S. and Israel Struck When They Did: A Chance to Kill Iran’s Leaders

This Is the System That Intercepted Iran’s Missiles Over the UAE

The 5 Big ‘Known Unknowns’ of Donald Trump’s New War With Iran

Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute

CISA Is Getting a New Acting Director After Less Than a Year: Nick Andersen is Replacing Madhu Gottumukkala

New York State Elevates Its Cyber Chief to a Broader New Security Role

Krebs: Who is the Kimwolf Botmaster “Dort”?

‘Silent Failure at Scale’: The AI Risk That Can Tip the Business World Into Disorder

Data Broker Breaches Fueled Nearly $21 Billion in Identity-Theft Losses

DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams

Ukrainian Man Pleads Guilty to Running AI-Powered Fake ID Site

‘Project Compass’ Cracks Down on ‘The Com’: 30 Members of Notorious Cybercrime Gang Arrested

Intellexa Founder, Three Others Sentenced to 8 Years in Prison Over Greek Spyware Scandal

Meta Files Lawsuits Against Brazil, China, Vietnam Advertisers Over Celeb-Bait Scams
South Korea’s Tax Office Apologizes for Leaking Seed Phrase to Seized Crypto

Personal Data Stolen in Ransomware Attack on Hong Kong’s Ngong Ping 360 Attraction

University of Hawaii Cancer Center Hack Exposed Social Security Numbers Of Up To 1.15 Million

North Korea’s APT37 Expands Toolkit to Breach Air-Gapped Networks

Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms

ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks

Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor

QuickLens Chrome Extension Steals Crypto, Shows ClickFix Attack

900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks

CISA Warns That RESURGE Malware Can Be Dormant on Ivanti Devices

ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

UK Vulnerability Monitoring Service Cuts Unresolved Security Flaws by 75%

Microsoft Testing Windows 11 Batch File Security Improvements

EU Lawmakers Propose That Youth Under 16 Be Barred From Social Media Without Parental Consent

Instagram to Start Alerting Parents When Children Search for Terms Relating to Self-Harm

Life Mirrors Art: Ransomware Hits Hospitals on Television (TV) & In Real Life (IRL)

Samsung TVs to Stop Collecting Texans’ Data Without Express Consent

2/26/2026

UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor

Ransomware Payment Rate Drops to Record Low as Attacks Surge

Scattered Lapsus$ Hunters Auditioning Female Voices to Sharpen Social Engineering

This AI Agent Is Designed to Not Go Rogue

Momentum Builds for Offensive Private-Sector Cyber Roles

NATO Says iPhones & iPads Are Secure Enough to Handle Classified Data

Greece’s Watergate: Four Convicted Over Spyware Scandal That Shook Greece

Former Air Force Officer Arrested for Conspiring With Hacker to Provide Flight Training to Chinese Military

Justice Department Exposed Cooperating Witnesses in Epstein Files

New York Sues Valve for Promoting Illegal Gambling via Game Loot Boxes
Olympique Marseille Confirms ‘Attempted’ Cyberattack After Data Leak

European DYI Chain ManoMano Data Breach Impacts 38 Million Customers

ShinyHunters Hacking Group Begins Leaking Customer Data in Dutch Telecom Odido Hack

Aeternum Botnet Shifts Command Control to Polygon Blockchain

New AirSnitch Attack Breaks Wi-Fi Encryption in Homes, Offices, and Enterprises

Previously Harmless Google API Keys Now Expose Gemini AI Data

Critical Juniper Networks PTX Flaw Allows Full Router Takeover

Trend Micro Warns of Critical Apex One Code Execution Flaws

Exploitable Vulnerabilities Present in 87% of Organizations

Microsoft Expands Windows Restore to More Enterprise Devices

Wyden Blocks Rudd Confirmation to Lead Cyber Command, NSA

2/25/2026

Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries

Chinese Cyberspies Breached Dozens of Telecom Firms, Gov’t Agencies

Iran-Linked Group Claims Hack of Israel’s Largest Healthcare Network

Critical Cisco SD-WAN Bug Exploited in Zero-Day Attacks Since 2023

U.S. Orders Diplomats to Fight Data Sovereignty Initiatives

How Mexico’s ‘CJNG’ Drug Cartel Embraced AI, Drones, and Social Media

Here’s What a Google Subpoena Response Looks Like, Courtesy of the Epstein Files

ADT Just Bought the Company That Invented Wi-Fi Motion Sensing

Cyber Startups Ride AI Wave to Funding Highs

Israeli AI-Cyber Firm Gambit Security Raises $61 Million

Nvidia Beats Back Bubble Fears With Record $68 Billion in Sales in Fourth Quarter

Former Defense Contractor Boss Gets 7+ Years for Selling Zero Days

Inside the Story of the U.S. Defense Contractor Who Leaked Hacking Tools to Russia

Moscow Man Accused of Posing as FSB Officer to Extort Conti Ransomware Gang
Popular Sex Toy Company Tenga Admits Hacker Stole Sensitive Customer Information

Medical Device Maker UFP Technologies Warns of Data Stolen in Cyberattack

Health Insurance Tech Provider TriZetto Says More Than 3 Million Impacted by 2024 Breach

Phishing Campaign ‘Diesel Vortex’ Targets Freight and Logistics Orgs in the U.S., Europe

New York City Transit Union Purportedly Targeted by Qilin

Malicious NuGet Package Targets Stripe Developers

Fake ‘Interview’ Repos Lure Next.js Devs Into Running Secret-Stealing Malware

CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability

Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration

Zyxel Warns of Critical RCE Flaw Affecting Over a Dozen Routers

U.S. Cybersecurity Agency CISA Reportedly in Dire Shape Amid Trump Cuts and Layoffs

FTC Says It Won’t Enforce COPPA Against Proper Use of Age Verification Tools

Discord Puts Global Age Verification Policy on Hold After Backlash

Chinese Prosecutors Raise Alarm About Growth of Domestic IP Theft

2/24/2026

North Korean Lazarus Group Expands Ransomware Activity With Medusa

Phishing Operation With Links to Russia, Armenia Compromised Western Cargo Companies, Researchers Find

Chinese AI Firms Hit Claude with Distillation Attacks, Anthropic Warns

AI Has Gotten Good at Finding Bugs, Not So Good at Swatting Them

AI Is Transformative, but Won’t Replace Established Software Anytime Soon

Cost of Insider Incidents Surges 20% to Nearly $20m

UK Fines Reddit $19 Million for Using Children’s Data Unlawfully

Marquis Sues Firewall Provider SonicWall, Alleges Security Failings With Its Firewall Backup Led to Ransomware Attack

Binance Fired Staff Who Flagged $1 Billion Moving to Sanctioned Iran Entities

U.S. ‘Committed’ to Fighting Transnational Gangs Behind Southeast Asian Scam Compounds: FBI

U.S. Sanctions Russian Exploit Broker for Buying Cyber Tools Stolen From Defense Contractor

Ukraine Pushes Tighter Telegram Regulation, Citing Russian Recruitment of Locals
CarGurus Data Breach Exposes Information of 12.4 Million Accounts

Conduent Data Breach Grows, Affecting at Least 25M People

Wynn Resorts Says Hackers Stole Employee Data

ShinyHunters Extortion Gang Claims Odido Breach Affecting Millions

University of Mississippi Medical Center Clinics Remain Closed Nearly a Week After Cyber Attack

Crypto Platform Step Finance Shutting Down After $40 Million Theft

Multifaceted Phishing Scheme Deceives Bitpanda Customers

UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware

UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors

1Campaign Platform Helps Malicious Google Ads Evade Detection

Android Mental Health Apps With 14.7m Installs Filled With Security Flaws

RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN

Critical SolarWinds Serv-U Flaws Offer Root Access to Servers

2/23/2026

APT28 Targeted European Entities Using Webhook-Based Macro Malware

Ukraine Says Cyberattacks on Energy Grid Now Used to Guide Missile Strikes

Ransomware Gangs Advancing Moscow’s Geopolitical Aims, Romanian Cyber Chief Warns

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

Cybersecurity Stocks Drop for a Second Day as New Anthropic Tool Fuels AI Disruption Fears

IQM Quantum Computers to List Shares in Us at Initial $1.8 Billion Valuation

Suspected Anonymous Members Detained in Spain Over Post-Flood DDoS Blitz
Air Côte d’Ivoire Confirms Cyberattack Following Ransomware Claims

Ad Tech Firm Optimizely Confirms Data Breach Affecting Customers After Vishing Attack

Supply Chain Shai-Hulud-Like Worm Targets Developers via npm and AI Tools

Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb

PayPal Fraud Investigation Reveals Sophisticated Python Malware

CISA: Two Recently Patched RoundCube Webmail Flaws Now Exploited in Attacks

Global Data Protection Authorities Warn Generative AI Companies Against Replicating Real People

2/20-22/2026

UAE Foils Cyber Attacks, State News Agency Says

Hackers Breach Contractor Linked to Ukraine’s Central Bank Collectible Coin Store

Russia Stepping up Hybrid Attacks, Preparing for Long Standoff With West, Dutch Intelligence Warns

Dramatic Escalation in Frequency and Power of DDoS Attacks

Predator Spyware Hooks iOS SpringBoard to Hide Mic, Camera Activity

Krebs: ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

DHS Wants a Single Search Engine to Flag Faces and Fingerprints Across Agencies

New Cybersecurity Rules for U.S. Defense Industry Create Barrier for Some Small Suppliers

Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case

Two Former Google Engineers and Spouse Indicted Over Trade Secret Transfers to Iran
ShinyHunters Demands $1.5m Not to Leak Vegas Casino Wynn Resorts and Resort Chain Data

Japanese Tech Giant Advantest Hit by Ransomware Attack

AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries

PayPal App Code Error Leaked Personal Info and a ‘Few’ Unauthorized Transactions

ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware

Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems

Arkanix Stealer Pops up as Short-Lived AI Info-Stealer Experiment

BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

Romanian Hacker Faces up to 7 Years for Breaching Oregon Emergency Management Dept

2/19/2026

Researchers Warn Volt Typhoon Still Embedded in U.S. Utilities and Some Breaches May Never Be Found

Nation-State Hackers Hit Businesses For Commercial Edge

Industrial Control System Vulnerabilities Hit Record Highs

The AI Security Nightmare Is Here and It Looks Suspiciously Like Lobster

Researchers Reveal Six New OpenClaw Vulnerabilities

How to Organize Safely in the Age of Surveillance

Crims Hit a $20M Jackpot via Malware-Stuffed ATMs

INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown

Nigerian Man Gets Eight Years in Prison for Hacking Tax Firms

UK to Demand Social Platforms Take Down Abusive Intimate Images Within 48 Hours

West Virginia Sues Apple for Alleged Child Sexual Abuse Material Failures

Google Blocked Over 1.75 Million Play Store App Submissions From Obtaining Excessive Access in 2025

Orange Shares Hit 16-Year High on Profit Beat, New Targets and M&A Hopes
Cyberattack Cripples University of Mississippi Medical Center Systems, Forces Clinic Closures

Attackers Breach France’s National Bank Account Database

Rhysida Ransomware Gang Threatens Cheyenne and Arapaho Tribes After Shutting Down Schools

Microsoft Error Sees Confidential Emails Exposed to AI Tool Copilot

Bug in Student Admissions Website Ravenna Hub Exposed Children’s Personal Information

Billions of Records Exposed by Unsecured IDMerit Database

Industrial-Scale Fake Coretax Apps Drive $2m Fraud in Indonesia

Starkiller: New ‘Commercial-Grade’ Phishing Kit Bypasses MFA

Hackers Target Microsoft Entra Accounts in Device Code Vishing Attacks

Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users

PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence

Remcos RAT Expands Real-Time Surveillance Capabilities

Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center

2/18/2026

New Backdoor Found in Android Tablets Targeting Users in Russia, Germany and Japan

Predator Spyware Used to Infect Phone Belonging to Angolan Journalist

Parents Angered by Lack of Online Safety Strategy

Spain Orders NordVPN, ProtonVPN to Block LaLiga Piracy Sites

Glendale Man Gets 5 Years in Prison for Role in Darknet Drug Ring

Fraudster Hacked Hotel System, Paid 1 Cent for Luxury Rooms, Spanish Cops Say

Texas Sues TP-Link Over China Links and Security Vulnerabilities

Poland Bans Chinese-Made Cars From Entering Military Sites

Hacking Conference Def Con Bans Three People Linked to Jeffrey Epstein
A Vast Trove of Exposed Social Security Numbers May Put Millions at Risk of Identity Theft

Data Breach at Fintech Firm Figure Affects Nearly 1 Million Accounts

ShinyHunters Allegedly Drove off With 1.7m Cargurus Records

Cryptojacking Campaign Exploits Driver to Boost Monero Mining

Telegram Channels Expose Rapid Weaponization of SmarterMail Flaws

Fed Agencies Ordered to Patch Dell Bug by Saturday After Exploitation Warning

Dell’s Hard-Coded Flaw: A Nation-State Goldmine

Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution

Critical Infra Honeywell CCTVs Vulnerable to Auth Bypass Flaw

2/17/2026

China Remains Embedded in U.S. Energy Networks ‘For the Purpose of Taking It Down’

Chinese Hackers Exploiting Dell Zero-Day Flaw Since Mid-2024

A Defector Explains the Remote-Work Scam Helping North Korea Pay for Nukes

Low-Skilled Cybercriminals Use AI to Perform “Vibe Extortion” Attacks

Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies

Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers

Significant Rise in Ransomware Attacks Targeting Industrial Operations

Wrongly Sent Emails ‘Most Common Data Breach’

Palo Alto Networks Slumps 6% as Third Quarter Profit Guidance Falls Short

U.S. Lawyers Fire Up Privacy Class Action Accusing Lenovo of Bulk Data Transfers to China

Poland Arrests Suspect Linked to Phobos Ransomware Operation
Hackers Target Supporters of Iran Protests in New Espionage Campaign

Citizen Lab: Kenyan Authorities Used Cellebrite to Break Into Phone of Dissident

Fake Milano Cortina Sites Target Thousands With Discount Scams, Cybersecurity Firm Says

SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates

RMM Abuse Explodes as Hackers Ditch Malware

Flaws in Popular VSCode Extensions Expose Developers to Attacks

Notepad++ Boosts Update Security With ‘Double-Lock’ Mechanism

Android 17 Beta Introduces Secure-By-Default Architecture

Apple Expands RCS Encryption and Memory Protections in iOS 26.4

Ireland Now Also Investigating X Over Grok-Made Sexual Images

2/13-16/2026

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations

China May Be Rehearsing a Digital Siege, Taiwan Warns

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs

UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors

Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third

NATO Must Impose Costs on Russia, China Over Cyber and Hybrid Attacks, Says Deputy Chief

Europe Must Adapt to ‘Permanent’ Cyber and Hybrid Threats, Sweden Warns

EU Can’t Be ‘Naive’ About Enemies Shutting Down Critical Infrastructure, Warns Tech Official

Space Emerges as New Front in Great Power Competition, Officials Warn

AI Coding Platform’s Flaws Allow BBC Reporter to Be Hacked

Vulnerabilities in Password Managers Allow Hackers to View and Change Passwords

The El Paso No-Fly Debacle Is Just the Beginning of a Drone Defense Mess

Robot Dogs Are on Going on Patrol at the 2026 World Cup in Mexico

Ring Ends Partnership Plans With Flock Days After Privacy Blowback From Super Bowl Ad

Dutch Cops Arrest Man After Sending Him Confidential Files by Mistake

Louis Vuitton, Dior, and Tiffany Fined $25 Million Over Data Breaches

U.S. Needs to Impose ‘Real Costs’ on Bad Actors, State Department Cyber Official Says
Washington Hotel in Japan Discloses Ransomware Infection Incident

Canada Goose Ruffles Feathers Over 600K Record Dump, Says Leak Is Old News

Eurail Says Stolen Traveler Data Now up for Sale on Dark Web

Over 500,000 Vkontakte Accounts Hijacked Through Malicious Chrome Extensions

Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft

Snail Mail Letters Target Trezor and Ledger Users in Crypto-Theft Attacks

Pastebin Comments Push ClickFix JavaScript Attack to Hijack Crypto Swaps

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

New ClickFix Attack Abuses Nslookup to Retrieve Powershell Payload via DNS

Claude LLM Artifacts Abused to Push Mac Infostealers in ClickFix Attack

Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens

OysterLoader Evolves With New C2 Infrastructure and Obfuscation

CISA Flags Critical Microsoft Sccm Flaw as Exploited in Attacks

CISA Gives Feds 3 Days to Patch Actively Exploited BeyondTrust Flaw

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released

Starlink Restrictions Hit Russian Forces as Moscow Seeks Workarounds

Infosec Exec Sold Eight Zero-Day Exploit Kits to Russia, Says DOJ

2/12/2026

Palo Alto Chose Not to Tie China to Hacking Campaign for Fear of Retaliation From Beijing, Sources Say

Nation-State Hackers Embrace Gemini AI for Malicious Campaigns, Google Finds

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Kim Jong Un Chooses Teen Daughter as Heir, Says Seoul

Cloudflare Rises 5% as AI Agent Wave Led by Viral Moltbot Boosts Security Demand

Check Point Software Lifts Profit Outlook as AI-Driven Cyber Threats Surge

AI Skills Represent Dangerous New Attack Surface, Says TrendAI

Those ‘Summarize With AI’ Buttons May Be Lying to You

Crypto-Funded Human Trafficking Is Exploding

Guthrie Doorbell Video Delayed by Difficult Data Recovery, but Privacy Advocates Still Worry

FTC Push for Age Verification a ‘Major Landmark’ for Spread of the Tool

WhatsApp Says Russia Tried to Fully Block Platform, Push Users to State App
Odido Data Breach Exposes Personal Info of 6.2 Million Customers

Romania’s Oil Pipeline Operator Conpet Confirms Data Stolen in Attack

Fake AI Chrome Extensions With 300K Users Steal Credentials, Emails

World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks

83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure

Critical BeyondTrust RCE Flaw Now Exploited in Attacks, Patch Now

WordPress Plugin With 900K Installs Vulnerable to Critical RCE Flaw

Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Other Devices

Microsoft: New Windows LNK Spoofing Issues Aren’t Vulnerabilities

Bitwarden Introduces ‘Cupid Vault’ for Secure Password Sharing

A Hard Truth in Munich: Cyber Defense Runs Through Silicon Valley

U.S. Wants Cyber Partnerships to Send ‘Coordinated, Strategic Message’ to Adversaries

2/11/2026

APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities

Krebs: Kimwolf Botnet Swamps Anonymity Network I2P

Posting AI-Generated Caricatures on Social Media Is Risky, Infosec Killjoys Warn

CBP Signs Clearview AI Deal to Use Face Recognition for ‘Tactical Targeting’

AI Rising: Do We Know Enough About the Data Populating It?

40 State AGs Warn House KOSA Bill Falls Short of Protecting Children Online

Police Arrest Seller of JokerOTP MFA Passcode Capturing Tool

Moscow Moves to Throttle Telegram as Kremlin Pushes Its Own Messaging App

UK Blames Legacy Systems as Ministers Promise No Repeat of Afghan Breach
Georgia Healthcare Company ApolloMD Data Breach Impacts More Than 620,000

Tulsa International Airport Hit With Ransomware Attack

LummaStealer Infections Surge After Castleloader Malware Campaigns

Crazy Ransomware Gang Abuses Employee Monitoring Tool in Attacks

First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials

Microsoft Fixes Notepad Flaw That Could Trick Users Into Clicking Malicious Markdown Links

Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms

Interim CISA Chief: ‘When the Government Shuts Down, Cyber Threats Do Not’

Is Spyware Hiding on Your Phone? How to Find Out and Remove It – Fast

2/10/2026

DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies

North Korean Hackers Use New macOS Malware in Crypto-Theft Attacks

“Digital Parasite” Warning as Attackers Favor Stealth for Extortion

White House to Meet With GOP Lawmakers on FISA Section 702 Renewal

Cyber Command, NSA Nominee Rudd Advances to Senate Floor

British Army Splashes $86M on AI Gear to Speed up the Battlefield Kill Chain

Fugitive Behind $73M ‘Pig Butchering’ Scheme Gets 20 Years in Prison

Google Secures EU Antitrust Approval for $32 Billion Wiz Acquisition

Microsoft Announces New Mobile-Style Windows Security Controls
Nearly 17,000 Volvo Staff Dinged in Supplier Breach

Phorpiex Phishing Delivers Low-Noise Global Group Ransomware

New Mobile Spyware ZeroDayRAT Targets Android and iOS

Malicious 7-Zip Site Distributes Installer Laced With Proxy Tool

Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools

New Linux Botnet SSHStalker Uses Old-School IRC for C2 Comms

Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution

Krebs: Patch Tuesday, February 2026 Edition

Microsoft Is Keeping Secure Boot Alive With Windows Updates

What Organizations Need to Change When Managing Printers

2/9/2026

China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign

Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

Senegal Confirms Breach of National ID Card Department After Ransomware Claims

EU, Dutch Government Announce Hacks Following Ivanti Zero-Days

European Commission Discloses Breach That Exposed Staff Data

Leaked Technical Documents Show China Rehearsing Cyberattacks on Neighbors’ Critical Infrastructure

Iran’s Digital Surveillance Machine Is Almost Complete

AI Is Here to Replace Nuclear Treaties. Scared Yet?

Researchers Find 40,000+ Exposed OpenClaw Instances

Social Media Platforms Earn Billions from Scam Ads

Hacked, Leaked, Exposed: Why You Should Never Use Stalkerware Apps

Two Connecticut Men Charged In Alleged $3m Gambling Fraud Scheme
Hackers Breach SmarterTools Network Using Flaw in Its Own Software

SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers

Discord Faces Backlash Over Age Checks After Data Breach Exposed 70,000 IDs

Payment Tech Provider for Texas, Florida Governments BridgePay Working With FBI to Resolve Ransomware Attack

Suspected Sabotage Disrupts Trains in Northern Italy as Winter Games Begin

TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure

VoidLink Malware Exhibits Multi-Cloud Capabilities and AI Code

New Zero-Click Flaw in Claude Desktop Extensions, Anthropic Declines Fix

BeyondTrust Warns of Critical RCE Flaw in Remote Support Software

Microsoft: Exchange Online Flags Legitimate Emails as Phishing

Russia Grants Asylum to Spanish Professor Wanted for Alleged Pro-Moscow Cyber Operations

2/6-8/2026

German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists

Norwegian Intelligence Discloses Country Hit by Salt Typhoon Campaign

Unsettled Cyber Intel Law Erodes Private-Sector Trust

U.S. Software Stocks Slammed on Mounting Fears Over AI Disruption, Lose $1 Trillion in Week

NYC Explores Using AI Cameras to Spot Subway Fare Evaders

EU Says TikTok Faces Large Fine Over “Addictive Design”

Illinois Man Pleads Guilty to Hacking Nearly 600 Women’s Snapchat Accounts
DKnife: Chinese-Made Malware Kit Targets Chinese-Based Routers and Edge Devices

Flickr Emails Users About Data Breach, PINs It on 3rd Party

Payments Platform BridgePay Confirms Ransomware Attack Behind Outage

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

CISA Warns of SmarterMail RCE Flaw Used in Ransomware Attacks

OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub Skills

New Tool Blocks Imposter Attacks Disguised as Safe Commands

2/5/2026

Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends

Protests Don’t Impede Iranian Spying on Expats, Syrians, Israelis

Russian Hackers Attacking European Maritime and Transport Orgs Using Microsoft Office Exploit

Asia-Based Government Spies TGR-STA-1030 Quietly Broke Into Critical Networks Across 37 Countries

ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are

Smartphones Now Involved in Nearly Every Police Investigation

AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+

UNICEF Calls for Criminalization of AI Content Depicting Child Sex Abuse

Dark Patterns Undermine Security, One Click at a Time

CISA Gives Federal Agencies One Year to Rip Out End-Of-Life Devices
Spain’s Ministry of Science Shuts Down Systems After Breach Claims

Romanian Oil Pipeline Operator Conpet Discloses Cyberattack

Italian University la Sapienza Goes Offline After Cyberattack

Substack Data Breach Exposed Users’ Emails and Phone Numbers

Data Breach at Govtech Giant Conduent Balloons, Affecting Millions More Americans

Betterment Breach May Expose 1.4m Users After Social Engineering Attack

Zendesk Spam Wave Returns, Floods Users With ‘Activate Account’ Emails

AISURU/Kimwolf Botnet Launches Record-Setting 31.4 Tbps DDoS Attack

Ransomware Gang Uses ISPsystem VMs for Stealthy Payload Delivery

Malicious Commands in GitHub Codespaces Enable RCE

2/4/2026

U.S. Used Cyber Weapons to Disrupt Iranian Air Defenses During 2025 Strikes

Ukraine Tightens Controls on Starlink Terminals to Counter Russian Drones

Italy Foiled Russia-Linked Cyberattacks on Embassies, Olympic Sites, Minister Says

How 2026 Winter Olympics Security Is Preparing for the Opening Ceremony

China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns

OpenClaw’s AI ‘Skill’ Extensions Are a Security Nightmare

Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models

Google Cloud’s Customer Chief Returns to Microsoft as Head of Security

With AI Accountability Stalling, Boards Must Push Tech Giants for Greater Transparency

Super Bowl Prepares for Potential AI Cybersecurity Threat

Owner of Incognito Dark Web Drugs Market Gets 30 Years in Prison

DragonForce Ransomware Gang Goes Full ‘Godfather’ With Cartel
Hackers Compromise NGINX Servers to Redirect User Traffic

Coinbase Confirms Insider Breach Linked to Leaked Support Tool Screenshots

Cybercrime Group Claims Responsibility for Penn Email Hack, Leaks Additional Internal Files

Hackers Publish Personal Information Stolen During Harvard, UPenn Data Breaches

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers

Global SystemBC Botnet Found Active Across 10,000 Infected Systems

New Technical Markers Reveal Expanding ShadowSyndicate Cybercriminal Infrastructure

EDR Killer Tool Uses Signed Kernel Driver From Forensic Software

Nitrogen Ransomware Is So Broken Even the Crooks Can’t Unlock Your Files

CISA Warns of Five-Year-Old GitLab Flaw Exploited in Attacks

CISA: VMware ESXi Flaw Now Exploited in Ransomware Attacks

Critical n8n Flaws Disclosed Along With Public Exploits

2/3/2026

Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days

Poland Detains Defense Ministry Employee on Suspicion of Spying for Russia

U.S. Senator Says AT&T, Verizon Blocking Release of Salt Typhoon Security Assessment Reports

CISA Official Says CIRCIA Cyber Reporting Update Is ‘Weeks’ Away

CISA Updated Ransomware Intel on 59 Bugs Last Year Without Telling Defenders

Trump Administration Eyes 10-Year Extension of Cybersecurity Law

How Data Brokers Can Fuel Violence Against Public Servants

X Marks the Raid: French Cops Swoop on Musk’s Paris Ops

UK ICO Launches Investigation into X Over AI Generated Non-Consensual Sexual Imagery

UK Investigating First Suspected Breach of Cyber Sanctions

Polish Cops Bail 20-Year-Old Bedroom Botnet Operator

Varonis to Acquire AllTrue as AI Security Concerns Mount

OpenAI CEO Altman Dismisses Moltbook as Likely Fad, Backs the Tech Behind It

The Rise of Moltbook Suggests Viral AI Prompts May Be the Next Big Security Threat
Iron Mountain: Data Breach Mostly Limited to Marketing Materials

Step Finance Says Compromised Execs’ Devices Led to $40M Crypto Theft

New Password-Stealing Phishing Campaign Targets Corporate Dropbox Credentials

Wave of Citrix NetScaler Scans Use Thousands of Residential Proxies

Researchers Warn of New “Vect” RaaS Variant

DockerDash Exposes AI Supply Chain Weakness In Docker’s Ask Gordon

Critical React Native Metro Dev Server Bug Under Attack as Researchers Scream Into the Void

Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package

CISA Flags Critical SolarWinds RCE Flaw as Exploited in Attacks

SQL Injection Flaw Affects 40,000 WordPress Sites

8-Minute Access: AI Accelerates Breach of AWS Environment

Microsoft Finally Sends TLS 1.0 and 1.1 to the Cloud Retirement Home

California City Turns off Flock Cameras After Company Shared Data Without Authorization

Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox

Spain Will Ban Social Media for Kids Under 16

2/2/2026

Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks

Notepad++ Updates Got Hijacked for Months and Could Have Spied for China

Spyware Maker Is Hijacking Diplomatic Efforts to Limit Commercial Hacking, Civil Society Warns

From Clawdbot to Moltbot to OpenClaw: Meet the AI Agent Generating Buzz and Fear Globally

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

Malicious MoltBot Skills Used to Push Password-Stealing Malware

Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users

Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site

Hackers Recruit Unhappy Insiders to Bypass Data Security

Drone Sightings Have Doubled Near UK Military Bases, Warns British Government
Krebs: Please Don’t Feed the Scattered Lapsus ShinyHunters

Hackers Attempt to Extort Parents After School Refuses to Pay Ransom Fee

StopICE Hacked to Send Alarming Text Messages, Admins Accuse Border Patrol Agent of Sabotage

Panera Bread Breach Impacts 5.1 Million Accounts, Not 14 Million Customers

McDonald’s Is Not Lovin’ Your BigMac, Happy Meal, and McNuggets McPasswords

NationStates Confirms Data Breach, Shuts Down Game Site

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos

NSA Publishes New Zero Trust Implementation Guidelines

Netherlands Latest European Country to Mull Social Media Ban for Children

1/30-2/1/2026

Labyrinth Chollima Evolves into Three North Korean Hacking Groups

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

RedKitten: New AI-Developed Malware SloppyMIO Campaign Targets Iranian Protests

I Mocked the Saudi Leader on YouTube – Then My Phone Was Hacked and I Was Beaten up in London

Informant Told FBI That Jeffrey Epstein Had a ‘Personal Hacker’

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

Coupang CEO Questioned by Police Investigating Obstruction of Probe Into Data Breach

Thoma Bravo Explores Sale of Identity Software Firm Imprivata, Sources Say

Operation Switch Off Dismantles Major Pirate TV Streaming Services

Department of Justice Seizes Domains for Bulgarian Piracy Sites

Crypto Wallets Received a Record $158 Billion in Illicit Funds Last Year
New Britain (CT) ‘Network Disruption’ Was Due to Ransomware Attack, Mayor Says

Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms

Cloud Storage Payment Scam Floods Inboxes With Fake Renewals

National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat

Exposed MongoDB Instances Still Targeted in Data Extortion Attacks

Researcher Reveals Evidence of Private Instagram Profiles Leaking Photos

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

New Apple Privacy Feature Limits Location Tracking on iPhones, iPads

AI Security Startup CEO Posts a Job. Deepfake Candidate Applies, Inner Turmoil Ensues.

Open-Source AI Is a Global Security Nightmare Waiting to Happen, Say Researchers

1/29/2026

Latvia Says Russia Remains Its Top Cyber Threat as Attacks Hit Record High

Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid

Operation Winter SHIELD: FBI Issues Call to Arms for Organizations to Improve Cybersecurity

Google Disrupts Extensive Residential Proxy Networks IPIDEA

Ransomware Victim Numbers Rise, Despite Drop in Active Extortion Groups

How Can CISOs Respond to Ransomware Getting More Violent?

Patch or Perish: Vulnerability Exploits Now Dominate Intrusions

An AI Toy Exposed 50,000 Logs of Its Chats With Kids to Anyone With a Gmail Account

Open-Source AI Models Vulnerable to Criminal Misuse, Researchers Warn

U.S. Software Stocks Slump as AI Disruption Fears Take Over

ICE Is Using Palantir’s AI Tools to Sort Through Tips

Italy’s Winter Games Security Plan Keeps U.S. ICE in Advisory Role

Cybersecurity Teams Embrace AI, Just Not at the Scale Marketing Suggests

AV Vendor eScan Goes to War With Security Shop Morphisec Over Update Server Scare

France Fines National Employment Agency €5m Over 2024 Data Breach
Cyberattack on Large Russian Bread Factory The Vladimir Bread Factory Disrupts Supply Deliveries

ShinyHunters Swipes Right on 10M Records in Alleged Dating App Match Group Data Grab

Match Group Breach Exposes Data from Hinge, Tinder, OkCupid, and Match

Contractor Data Breach at TriZetto Provider Solutions May Have Exposed the Protected Health Info of Thousands of Central Oregonians

Fintech Marquis Blames Ransomware Breach on SonicWall Cloud Backup Hack

Initial Access Hackers TA584 Switch to Tsundere Bot for Ransomware Attacks

Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries

Hugging Face Abused to Spread Thousands of Android Malware Variants

Aisuru Botnet Sets New Record with 31.4 Tbps DDoS Attack

Ivanti Warns of Two EPMM flaws Exploited in Zero-Day Attacks

Google Rolls Out Android Theft Protection Feature Updates

New Apple Feature Will Block Cell Networks From Capturing Precise Location Data

New Microsoft Teams Feature Will Let You Report Suspicious Calls

NSA Pick Champions Foreign Spying Law as Nomination Advances

1/28/2026

Cyberattack on Polish Energy Grid Impacted Around 30 Facilities

Ransomware Crims Forced to Take Off-RAMP as FBI Seizes Forum

Virginia Man & Empire Cybercrime Market Owner, with Partner from Florida, Pleads Guilty to Drug Conspiracy

Teen Swatting Suspects Arrested in Hungary and Romania

Slovakian Man Pleads Guilty to Operating Darknet Marketplace

OpenAI’s ChatGPT’s Ad Costs Are on Par With Live NFL Broadcasts

Ex-Palantir Engineer Raises $40 Million for Cyber Startup Outtake, With Backing From Microsoft CEO Nadella

Trump’s Acting Cybersecurity Chief Madhu Gottumukkala Uploaded Sensitive Government Docs to ChatGPT
eScan Confirms Update Server Breached to Push Malicious Update

Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign

Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation

Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware

Autonomous System Uncovers Long-Standing OpenSSL Flaws

SolarWinds Warns of Critical Web Help Desk RCE, Auth Bypass Flaws

Critical and High Severity n8n Sandbox Flaws Allow RCE

UK Leaders Warned Country Risks ‘Absorbing’ Cyber and Hybrid Attacks Without Offensive Deterrence

FTC Commissioner Says Online Age Verification ‘Offers a Better Way’ to Protect Kids

1/27/2026

Chinese Mustang Panda Hackers Deploy Infostealers via CoolClient Backdoor

PeckBirdy Framework Tied to China-Aligned Cyber Campaigns

Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

Over 80% of Ethical Hackers Now Use AI

Revealed: Leaked Chats Expose the Daily Life of a Scam Compound’s Enslaved Workforce

He Leaked the Secrets of a Southeast Asian Scam Compound. Then He Had to Get Out Alive

WhatsApp’s New ‘Lockdown’ Settings Add Another Layer of Protection Against Cyberattacks

France to Replace U.S. Videoconferencing Wares With Unfortunately Named Sovereign Alternative

Private Equity Firm Audax Group Seeks Over $1.5 Billion for BlueCat Networks

U.S. Charges 31 More Suspects Linked to Tren de Aragua ATM Malware Attacks

Chinese Money Launderers Moved More Than $16 Billion of Illicit Crypto in 2025, Report Finds
Let Them Eat Sourdough: ShinyHunters Claims Panera Bread as Stolen Credentials Victim

Nike Investigates Data Breach After Extortion Gang Leaks Files

Russian Security Systems Firm Delta Hit by Cyberattack, Services Disrupted

Ransomware Attacks Hits Winona County (MN)

Have I Been Pwned: SoundCloud Data Breach Impacts 29.8 Million Accounts

New Malware Service ‘Stanley’ Guarantees Phishing Extensions on Chrome Web Store

WinRAR Path Traversal Flaw Still Exploited by Numerous Hackers

Fortinet Blocks Exploited FortiCloud SSO Zero Day Until Patch is ready

Pyodide Sandbox Escape Enables Remote Code Execution in Grist-Core

Critical Sandbox Escape Flaw Found in Popular vm2 NodeJS Library

Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

UK Plans Sweeping Overhaul of Policing Amid Surge in Online Crimes

1/26/2026

Krebs: Who Operates the Badbox 2.0 Botnet?

Deepfake ‘Nudify’ Technology Is Getting Darker—And More Dangerous

EU Launches Investigation Into X Over Grok-Generated Sexual Images

2025 Was a Wake-up Call to Protect Human Decisions, Not Just Systems

CISA Releases List of Post-Quantum Cryptography Product Categories

Upwind Raises $250 Million to Expand Cloud Security

Law Firm Investigates Coupang Security Failures Ahead of Class Action Deadline

Google Agrees to Pay $68 Million to Settle Voice Recording Lawsuit

Judge Awards British Critic of Saudis $4.1 Million, Finds the Regime Hacked His Devices
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware

New ClickFix Attacks Abuse Windows App-V Scripts to Push Malware

eScan Antivirus Supply Chain Breach Delivers Signed Malware

Researchers Uncover “Haxor” SEO Poisoning Marketplace

Cloudflare Misconfiguration Behind Recent BGP Route Leak

Hackers Can Bypass npm’s Shai-Hulud Defenses via Git Dependencies

Microsoft Patches Actively Exploited Office Zero-Day Vulnerability

Supreme Court to Hear Facebook Pixel Tracking Case

Romania Probes Two Suspects Over Alleged Hitman-For-Hire Website

1/23-25/2026

New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

Konni Hackers Target Blockchain Engineers With AI-Built Malware

Millions of People Imperiled Through Sign-in Links Sent by SMS

Gmail’s Spam Filter and Automatic Sorting Are Broken

Ring Can Verify Videos Now, but That Might Not Help You With Most AI Fakes

TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order

U.S. to Deport Venezuelans Who Emptied Bank ATMs Using Malware

UK Border Tech Budget Swells by £100M as Home Office Targets Small Boat Crossings

Germany Expels Russian Diplomat Accused of Spying on Ukraine War Effort

China Investigates Top General Zhang Youxia in Rare Purge of Senior Military Leaders

U.S. Storm Leaves 850,000 Without Power, Forces 10,000 Flight Cancellations
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware

Cyberattack Disrupts Digital Systems at Renowned Dresden Museum Network

149 Million Usernames and Passwords Exposed by Unsecured Database

ShinyHunters Claims Okta Customer Breaches, Leaks Data Belonging to 3 Orgs

Nike Probing Potential Security Incident as Hackers Threaten to Leak Data

Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access

Malicious AI Extensions on VSCode Marketplace Steal Developer Data

Fortinet Confirms Critical FortiCloud Auth Bypass Not Fully Patched

CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities

CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog

Hackers Get $1,047,000 for 76 Zero-Days at Pwn2Own Automotive 2026

1/22/2026

From a Whisper to a Scream: Europe Frets About Overreliance on U.S. Tech

Risky Chinese Electric Buses Spark Aussie Gov’t Review

Spanish Judge Closes NSO Group Spyware Probe Due to Lack of Cooperation From Israel

Claude’s New AI File-Creation Feature Ships With Security Risks Built In

Crims Compromised Energy Firms’ Microsoft Accounts, Sent 600 Phishing Emails

Microsoft Teams to Add Brand Impersonation Warnings to Calls

1Password Is Introducing a New Phishing Prevention Feature

House of Lords Backs Legislation to Ban Social Media for Children Under 16

Bank of England: Financial Sector Failing to Implement Basic Cybersecurity Controls

Over 160,000 Companies Notify Regulators of GDPR Breaches

Europe’s GDPR Cops Dished Out €1.2B in Fines Last Year as Data Breaches Piled Up

INC Ransomware Opsec Fail Allowed Data Recovery for 12 U.S. Orgs
Hackers Breach Fortinet FortiGate Devices, Steal Firewall Configs

Fortinet Firewalls Hit With Malicious Configuration Changes

Jordan Used Cellebrite Phone-Hacking Tools Against Activists Critical of Gaza War, Report Finds

Okta SSO Accounts Targeted in Vishing-Based Data Theft Attacks

New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts

SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release

RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites

Critical Appsmith Flaw Enables Account Takeovers

Hackers Exploit 29 Zero-Days on Second Day of Pwn2Own Automotive

Curl Ending Bug Bounty Program After Flood of AI Slop Reports

1/21/2026

North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

Phishing and Spoofed Sites Remain Primary Entry Points For Olympics

Hackers Exploit Security Testing Apps to Breach Fortune 500 Firms

Fortinet Admins Report Patched FortiGate Firewalls Getting Hacked

New Android Malware Uses AI to Click on Hidden Browser Ads

Greek Police Arrest Scammers Using Fake Cell Tower Hidden in Car Trunk

Ireland Wants to Give Its Cops Spyware, Ability to Crack Encrypted Messages

EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act

UK’s NCC Group to Sell Escode for $369.4 Million
Everest Ransomware Gang Said to Be Sitting on Mountain of Under Armour Data

Online Retailer PcComponentes Says Data Breach Claims are Fake

Peruvian Loan Scam Harvests Cards and PINs via Fake Applications

LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Cisco Fixes Unified Communications RCE Zero Day Exploited in Attacks

Tesla Hacked, 37 Zero-Days Demoed at Pwn2Own Automotive 2026

Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch

1/20/2026

North Korea-Linked Hackers Target Developers via Malicious VS Code Projects

EU Plan to Phase-Out High-Risk Tech Draws Fire From China’s Huawei

Greece, Israel to Cooperate on Anti-Drone Systems, Cybersecurity, Greek Minister Says

Krebs: Kimwolf Botnet Lurking in Corporate, Gov’t Networks

UK Launches Landmark ‘Report Fraud’ Service to Tackle Cybercrime and Fraud

Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

Cyber Risks Among CEOs’ Top Worries Amid Weak Short Term Growth Outlook

AI Supercharges Attacks in Cybercrime’s New ‘Fifth Wave’

VoidLink Cloud Malware Shows Clear Signs of Being AI-Generated

True Agentic AI Is Years Away – Here’s Why and How We Get There

Supreme Court to Consider Whether Geofence Warrants Are Constitutional

UK Says It Will Consider Banning Social Media for Children
Hackers Target Afghan Government Workers With Fake Correspondence From Senior Officials

Linkedin Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs

Numerous Mass Spam Attacks Leverage Zendesk Instances

UStrive Security Lapse Exposed Personal Data of Its Users, Including Children

Minnesota Department of Human Services Data Breach Affects Over 300K Individuals

Everest Ransomware Claims McDonalds India Breach Involving Customer Data

Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto

ACF Plugin Bug Gives Hackers Admin on 50,000 WordPress Sites

Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers

Chainlit Security Flaws Highlight Infrastructure Risks in AI Apps

Prompt Injection Bugs Found in Official Anthropic Git MCP Server

Lawmakers Move to Extend Two Cyber Programs (Again) in Funding Proposal

1/19/2026

Iran to Consider Lifting Internet Ban; State TV Hacked to Air Anti-Regime Messages

Russian Hacktivists Intensify Disruptive Cyber Pressure on UK Orgs

Read the Texts Between Trump and Norway’s Prime Minister

How Crypto Criminals Stole $700 Million From People – Often Using Age-Old Tricks
Ingram Micro Admits Summer Ransomware Raid Exposed Thousands of Staff Records

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Researchers Uncover PDFSIDER Malware Built for Long-Term, Covert System Access

Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites

1/16-18/2026

China-Linked Hackers Exploited Sitecore Zero-Day for Initial Access

Trump Says Iran Has Told Him ‘Killing Has Stopped’ as He Pulls Back From Strike Threats

Donald Trump Calls off Iran Strikes After Steve Witkoff, Araghchi Texts

By Asking Trump to Delay Iran Attacks, Netanyahu Exposes Israel’s Air Defense Holes

Anti-Regime Activists Hack Iran’s National Broadcaster, Transmit Pahlavi’s Calls to Protest

Canada Will Regret Allowing Chinese EVs Into Their Market, U.S. Says

EU Moves to Force the Phase-Out of Chinese Suppliers From Key Infrastructure

A Faceless Hacker Stole My Therapy Notes – Now My Deepest Secrets Are Online Forever

Jordanian Initial Access Broker Pleads Guilty to Helping Target 50 Companies

Police Raid Homes of Alleged Black Basta Hackers, Hunt Suspected Russian Ringleader

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
Canadian Investment Regulatory Organization (CIRO) Confirms Data Breach Exposed Info on 750,000 Canadian Investors

Tens of Millions of French Citizen Records Exposed

TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals

RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation Wave

Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection

Malicious GhostPoster Browser Extensions Found with 840,000 Installs

Hackers Now Exploiting Critical Fortinet FortiSIEM Flaw in Attacks

StealC Hackers Hacked as Researchers Hijack Malware Control Panels

Cisco Finally Fixes AsyncOS Zero-Day Exploited Since November

I’m Sorry Dave, I’m Afraid I Can’t Do That! PCs Refuse to Shut Down After Microsoft Patch

1/15/2026

Chinese-Linked Hackers Target U.S. Entities With Venezuelan-Themed Malware

ICE Agent Doxxing Site DDoS-ed Via Russian Servers

Hackers Increasingly Shun Encryption in Favour of Pure Data Theft and Extortion

Former CISA Director Jen Easterly Will Lead RSAC Conference

FTC Bans GM From Selling Drivers’ Location Data for Five Years

Google to Pay $8.25 Million to Settle Lawsuit Alleging Children’s Privacy Violations

Elon Musk’s X Says It Will Block Grok From Making Sexual Images

Data Privacy Teams Face Staffing Shortages and Budget Constraints, ISACA Warns

Cloudflare Acquires AI Data Marketplace Human Native

Former U.S. Special Forces Officer Is Now a Startup CEO—His Cybersecurity Company Has Raised $22 Million
Verizon’s Hourslong Wireless Outage Tied to Software Update

Grubhub Confirms Hackers Stole Data in Recent Security Breach

Anchorage Police Department Takes Servers Offline After Cyberattack on Service Provider

Contagious Claude Code Bug Anthropic Ignored Promptly Spreads to Cowork

WhisperPair: Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking

Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

Trio of Critical Bugs Spotted in Delta Industrial PLCs

CodeBuild Flaw Put AWS Console Supply Chain At Risk

Germany Turns to Israel for a ‘Cyber Dome’ Amid Rising Threats

1/14/2026

PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces

Ukraine Appoints Digital Chief as Defense Minister to Drive Military Reform

Western Cyber Agencies Warn About Threats to Industrial Operational Technology

Beijing Tells Chinese Firms to Stop Using U.S. and Israeli Cybersecurity Software, Sources Say

Lawmakers to Restart Efforts to Revive Lapsed Cyber Intel Bill

Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers

Criminal Subscription Service Behind AI-Powered Cyber-Attacks Taken Out By Microsoft

Verizon Outage Knocks Out U.S. Mobile Service, Including Some 911 Calls

France Fines Telcos €42M for Sub-Par Security Prior to 24M Customer Breach

Palantir Is Trying to ‘Destroy’ Percepta Through Legal Action, Startup’s Execs Say in Filing

Google’s Personal Intelligence links Gmail, Photos and Search to Gemini

California AG to Probe Musk’s Grok for Nonconsensual Deepfakes

Ugandan Officials Turn Off Internet on Eve of National Elections
Victorian Department of Education Says Hackers Stole Students’ Data

Monroe University Says 2024 Data Breach Affects 320,000 People

South Korean Giant Kyowon Confirms Data Theft in Ransomware Attack

Cloud Marketplace Pax8 Accidentally Exposes Data on 1,800 MSP Partners

Reprompt Attack Hijacked Microsoft Copilot Sessions for Data Theft

Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs

DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation

Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution

Krebs: Patch Tuesday, January 2026 Edition

Federal Agencies Ordered to Patch Microsoft Desktop Windows Manager Bug

Microsoft Updates Windows DLL That Triggered Security Alerts

1/13/2026

Massive Cyberattack on Polish Power System in December Failed, Minister Says

Hill Warning: Don’t Put Cyber Offense Before Defense

Trump Renominates Sean Plankey for CISA Director

Ukraine Parliament Approves Resignation of Security Service Chief in Major Reshuffle

Kremlin-Linked Hackers Pose as Charities to Spy on Ukraine’s Military

Senior Military Cyber Operator Removed From Russia Task Force

More Than 40 Countries Impacted by North Korea IT Worker Scams, Crypto Thefts

Oracle Hack Still Generating Ransom Demands

India’s Smartphone Security Proposal Faces Backlash Over Privacy Concerns

Quantum Software Company Haiqu Raises $11 Million

AI and Automation Could Erase 10.4 Million U.S. Roles by 2030

What’s the Deal With Physical AI? Why the Next Frontier of Tech Is Already All Around You

Teen Hackers Recruited Through Fake Job Ads

Tennessee Man to Plead Guilty to Hacking Supreme Court’s Electronic Case Filing System

Dutch Cops Cuff Alleged AVCheck Malware Kingpin in Amsterdam
Target Employees Confirm Leaked Source Code Is Authentic

Suspected Ransomware Attack Threatens One of South Korea’s Largest Companies, Kyowon Group

Everest Ransomware Group Claims Nissan Breach, Demands Response

Central Maine Healthcare Breach Exposed Data of Over 145,000 People

Belgian Hospital AZ Monica Shuts Down Servers After Cyberattack

VoidLink: New Chinese-Made Malware Framework Targets Linux-Based Cloud Environments

Global Magecart Campaign Targets Six Card Networks

SHADOW#REACTOR Campaign Uses Text-Only Staging to Deploy Remcos RAT

Convincing LinkedIn Comment-Reply Tactic Used in New Phishing

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Popular Python Libraries Used in Hugging Face Models Subject to Poisoned Metadata Attack

Adobe Patches Critical Apache Tika Bug in ColdFusion

Microsoft January 2026 Patch Tuesday Fixes 3 Zero-Days, 114 Flaws

Microsoft Releases Windows 10 KB5073724 Extended Security Update

New Windows Updates Replace Expiring Secure Boot Certificates

1/12/2026

Internet Monitoring Experts Say Iran Blackout Likely to Continue

Sweden Detains Ex-Military IT Consultant Suspected of Spying for Russia

Hungary Grants Asylum to Former Polish Minister Implicated in Spyware Probe

World Economic Forum: Cyber-Fraud Overtakes Ransomware as Business Leaders’ Top Cyber-Security Concern

Illicit Crypto Activity Hits Record $158bn in 2025

Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud

Ofcom Officially Investigating X as Grok’s Nudify Button Stays Switched On

Palo Alto Networks Introduces New Vibe Coding Security Governance Framework

Hacker Gets Seven Years for Breaching Rotterdam and Antwerp Ports

‘Violence-As-A-Service’ Suspect Arrested in Iraq, Extradition Underway

Kentucky Sues Character.AI, Alleging It Harms Children and Violates Data Law

Anthropic Brings Claude to Healthcare with HIPAA-Ready Enterprise Tools
University of Hawaii Cancer Center Hit by Ransomware Attack

Spanish Energy Giant Endesa Discloses Data Breach Affecting Customers

‘Bad Actor’ Hijacks Apex Legends Characters in Live Matches

Target’s Dev Server Offline After Hackers Claim to Steal Source Code

Armenia Probes Alleged Sale of 8 Million Government Records on Hacker Forum

Fintech Firm Betterment Confirms Data Breach After Hackers Send Fake Crypto Scam Notification to Users

Instagram Denies Breach After Many Receive Emails Asking to Reset Password

Facebook Login Thieves Now Using Browser-In-Browser Trick

Hidden Telegram Proxy Links Can Reveal Your IP Address in One Click

n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens

CISA Orders Feds to Patch Gogs RCE Flaw Exploited in Zero-Day Attacks

Apple Confirms Google Gemini Will Power Siri, Says Privacy Remains a Priority

Torq Raises $140 Million for Agentic AI-Powered Cybersecurity Platform

1/9-11/2026

China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines

Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

World Economic Forum: Deepfake Face-Swapping Tools Are Creating Critical Security Risks

Krebs: Who Benefited from the Aisuru and Kimwolf Botnets?

Europol Leads Global Crackdown on Black Axe Cybercrime Gang, 34 Arrested

X Didn’t Fix Grok’s ‘Undressing’ Problem. It Just Makes People Pay for It

Lawmakers Call On App Stores to Remove Grok, X Over Sexualized Deepfakes

Illinois Man Charged With Hacking Snapchat Accounts to Steal Nude Photos

Ireland Recalls Almost 13,000 Passports Over Missing ‘IRL’ Code

California Bans Data Broker Reselling Health Data of Millions

Stellar Gains, Heavy Losses: Cybersecurity Stocks Had a Mixed Year

Here’s What Cloud Security’s Future Holds for the Year Ahead
BreachForums Hacking Forum Database Leaked, Exposing 324,000 Accounts

Ransomware Attack on Texas Gas Station Firm Gulshan Management Services Leaks 377,000 User Records

At Least $26 Million in Crypto Stolen From Truebit Platform as Crypto Crime Landscape Evolves

AI-Powered Truman Show Operation Industrializes Investment Fraud

Betterment’s Financial App Sends Customers a $10,000 Crypto Scam Message

Warning Over Scams Targeting Manx Email Accounts

Instagram Says It Fixed the Issue That Let Someone Send All Those Password Reset Emails

FBI Warns of North Korean QR Phishing Campaigns

Hackers Target Misconfigured Proxies to Access Paid LLM Services

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024

UK Government Exempting Itself From Flagship Cyber Law Inspires Little Confidence

Former NSA Insider Kosiba Brought Back as Spy Agency’s No. 2

1/8/2026

China Hacked Email Systems of U.S. Congressional Committee Staff

U.S. To Leave Global Forum on Cyber Expertise

NSA Cyber Directorate Gets New Acting Leadership

Venezuela Raid Highlights Cyber Vulnerability of Critical Infrastructure

ChatGPT Health Feature Draws Concern From Privacy Critics Over Sensitive Medical Data

Grok Is Generating Sexual Content Far More Graphic Than What’s on X

CrowdStrike Buys Identity Security Startup SGNL for $740 Million in Latest Deal Push

Cyera Valued at $9 Billion as Data Security Firm Raises $400 Million

EU Antitrust Regulators to Decide on Google’s Wiz Deal by February 10

Texas Court Blocks Samsung From Tracking TV Viewing, Then Vacates Order

Ransomware Attacks Kept Climbing in 2025 as Gangs Refused to Stay Dead

Two-Fifths of 50% of Breaches Take Two Weeks to Recover From

Russia Frees French Researcher in Prisoner Swap for Alleged Ransomware Hacker
China-Linked UAT-7290 Targets Telecom Networks in South Asia

Iran-Linked Hacker Group Claims to Have Hacked, Surveilled Senior Mossad Agent

More Than 100,000 Households Warned After Cyber Attack on Kensington and Chelsea Council

Sedgwick Breach Linked to TridentLocker Ransomware Attack

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

GoBruteforcer Botnet Targets Linux Servers

Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages

New Zero-Click Attack Lets ChatGPT User Steal Data

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited

Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances

Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release

Cisco Switches Hit by Reboot Loops Due to DNS Client Bug

Microsoft to Enforce MFA for Microsoft 365 Admin Center Sign-Ins

1/7/2026

Cyberattacks Likely Part of Military Operation in Venezuela

European Space Agency Calls Cops as Crims Lift Off 500 GB of Files, Say Security Black Hole Still Open

Taiwan Says China’s War Games Sought to Undermine Global Support for the Island

China Intensifies Cyber-Attacks on Taiwan as Energy Sector Sees Tenfold Spike

Grok AI Still Being Used to Digitally Undress Women and Children Despite Suspension Pledge

IBM’s AI Agent Bob Easily Duped to Run Malware, Researchers Show

Google Search AI Hallucinations Push Google to Hire “AI Answers Quality” Engineers

Personal LLM Accounts Drive Shadow AI Data Leak Risks

Cloudy Outlook for Cyber Jobs as AI Fills Security Gaps

Stalkerware Operator Pleads Guilty in Rare Prosecution

Alleged Cyber Scam Kingpin Arrested, Extradited to China
MFA Failure Enables Infostealer Breach At 50 Enterprises

Illinois Department of Human Services Reports Yearslong Data Breach

Cyberattack Under Investigation by Coles County School District (IL)

Spanish Airline Iberia Attributes Recent Data Breach Claims to November Incident

Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches

Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud

Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads

Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing

Critical jsPDF Flaw Lets Hackers Steal Secrets via Generated PDFs

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication

Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control

1/6/2026

Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government

UK Launches New Cyber Unit to Bolster Defences Against Cyber Threats

UK Government Admits Years of Cyber Policy Have Failed, Announces Reset

Ring’s Mobile Security Trailer Provides 360-Degree Coverage Anywhere

Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

Jaguar Land Rover Wholesale Volumes Down 43% After Cyberattack

Startup Trends Shaking Up Browsers, SOC Automation, AppSec

Cybersecurity Predictions 2026: An AI Arms Race and Malware Autonomy
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat

Hospitality Sector Hit By PHALT#BLYX ClickFix Malware Campaign

Cloud File-Sharing Sites Targeted for Corporate Data Theft Attacks

High-Severity Flaw in Open WebUI Affects AI Connections

New D-Link Flaw in Legacy DSL Routers Actively Exploited in Attacks

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers

Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover

1/5/2026

Russian Hackers Target European Hospitality Industry With ‘Blue Screen of Death’ Malware

The French University Where Spies Go for Training

As Supply-Chain Cyber Risks Mount, Can AI Help?

EU Looking ‘Very Seriously’ at Taking Action Against X Over Grok

Finland Arrests Two Crew Members of Ship Suspected of Cable Break

Playing Koi: Palo Alto Isn’t Saying if It Will Buy Security Start-up

VSCode IDE Forks Expose Users to “Recommended Extension” Attacks
New Zealand Orders Review Into ManageMyHealth Cyberattack

Aurora College Working to Get Systems Back Up After Cyber Attack

Cyberattack Forces British High School to Close

Ledger Customers Impacted by Third-Party Global-E Data Breach

U.S. Broadband Provider Brightspeed Investigates Breach Claims

NordVPN Denies Breach Claims, Says Attackers Have “Dummy Data”

VVS Stealer Uses Advanced Obfuscation to Target Discord Users

1/2-4/2026

Inside the Operation: How the U.S. Moved to Capture Nicolás Maduro

Trump Suggests U.S. Used Cyberattacks to Turn Off Lights in Venezuela During Strikes

Krebs: The Kimwolf Botnet is Stalking Your Local Network

8 WhatsApp Features to Boost Your Security and Privacy

How to Protect Your iPhone or Android Device From Spyware

Trump Admin Sends Heart Emoji to Commercial Spyware Makers With Lifted Predator Sanctions

Bitfinex Crypto Thief Who Was Serving Five Years Thanks Trump for Early Release

Palo Alto Networks Security-Intel Boss Calls AI Agents 2026’s Biggest Insider Threat

Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats
Cybercrook Claims to Be Selling Infrastructure Info About Three Major U.S. Utilities

Hackers Claim to Hack Resecurity, Firm Says It Was a Honeypot

Sedgwick Confirms Cyber Incident Affecting Its Major Federal Contractor Subsidiary

Trust Wallet Links $8.5 Million Crypto Theft to Shai-Hulud NPM Attack

Covenant Health Says May Data Breach Impacted Nearly 478,000 Patients

Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign

Over 10K Fortinet Firewalls Exposed to Actively Exploited 2FA Bypass