Cybersecurity researchers have discovered a new campaign attributed to a China-linked threat actor known as UAT-8099 that took place between late 2025 and early 2026. The activity, discovered by Cisco Talos, has targeted vulnerable Internet Information Services (IIS) servers located across Asia, but with a specific focus on targets in Thailand and Vietnam. The scale … Read More “China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware – The Hacker News” »
Author: [email protected] (The Hacker News)
The RedKitten campaign distributes lures designed to target people seeking information about missing persons or political dissidents in Iran – Read More –
Behind the scenes of law enforcement in cyber: what do we know about caught cybercriminals? What brought them in, where do they come from and what was their function in the crimescape? Introduction: One view on the scattered fight against cybercrime The growing sophistication and diversification of cybercrime have compelled law enforcement agencies worldwide to … Read More “Badges, Bytes and Blackmail – The Hacker News” »
Cyber fraudsters targeting corporate finance departments costs businesses millions a year – Read More –
Much of the public conversation about the U.S. “winning” the AI race with China centers exclusively on each nations’ ability to develop and implement leading AI models. But amid escalating cyber threats, the rising reality is that the race will not be won merely by the nation with the most advanced technology, but the one … Read More “Cybersecurity can be America’s secret weapon in the AI race – CyberScoop” »
Multiple vulnerabilities have been discovered in Ivanti Endpoint Manager Mobile which could allow for remote code execution. Ivanti Endpoint Manager Mobile is a mobile management software engine that enables IT to set policies for mobile devices, applications and content. Successful exploitation of these vulnerabilities could allow for remote code execution in the context of the … Read More “Multiple Vulnerabilities in Ivanti Endpoint Manager Mobile Could Allow for Remote Code Execution – Cyber Security Advisories – MS-ISAC” »
SmarterTools has addressed two more security flaws in SmarterMail email software, including one critical security flaw that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-24423, carries a CVSS score of 9.3 out of 10.0. “SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API … Read More “SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score – The Hacker News” »
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup – The Hacker News
A former Google engineer accused of stealing thousands of the company’s confidential documents to build a startup in China has been convicted in the U.S., the Department of Justice (DoJ) announced Thursday. Linwei Ding (aka Leon Ding), 38, was convicted by a federal jury on seven counts of economic espionage and seven counts of theft … Read More “Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup – The Hacker News” »
The Middle East and Africa (MEA) region is experiencing a rapid industrial change. The use of Operational Technology (OT)… The post OT & IoT Security in MEA: Why Industrial Cyber Risks Are Surging appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks, one of which has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog. The critical-severity vulnerabilities are listed below – CVE-2026-1281 (CVSS … Read More “Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released – The Hacker News” »
Imagine the scene. It’s a cold Monday morning in Moscow. You walk out to your car, coffee in hand, ready to face the day. You press the button to unlock your car, and … nothing happens. You try again. Still nothing. The alarm starts blaring. You can’t turn it off. Read more in my article … Read More “Hacking attack leaves Russian car owners locked out of their vehicles – GRAHAM CLULEY” »
CVE-2025-12758: Unicode Variation Selectors Bypass in ‘validator’ library (isLength) – Full Disclosure
Posted by Karol Wrótniak on Jan 29 Summary ======= A vulnerability was discovered in the popular JavaScript library ‘validator’. The isLength() function incorrectly handles Unicode Variation Selectors (U+FE0E and U+FE0F). An attacker can inject thousands of these zero-width characters into a string, causing the library to report a much smaller perceived length than the … Read More “CVE-2025-12758: Unicode Variation Selectors Bypass in ‘validator’ library (isLength) – Full Disclosure” »
Posted by Andrey Stoykov on Jan 29 Hi. I would like to publish my paper for exploiting XAMPP installations. Thanks, Andrey – Read More – Full Disclosure
Posted by Andrey Stoykov on Jan 29 # Exploit Title: Elgg – Lack of Password Complexity # Date: 1/2026 # Exploit Author: Andrey Stoykov # Version: 6.3.3 # Tested on: Ubuntu 22.04 # Blog: https://msecureltd.blogspot.com/2026/01/friday-fun-pentest-series-48-weak.html // HTTP Request – Changing Password POST /action/usersettings/save HTTP/1.1 Host: elgg.local User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:148.0) … Read More “Weak Password Complexity – elggv6.3.3 – Full Disclosure” »
Posted by Andrey Stoykov on Jan 29 # Exploit Title: Elgg – Username Enumeration # Date: 1/2026 # Exploit Author: Andrey Stoykov # Version: 6.3.3 # Tested on: Ubuntu 22.04 # Blog: https://msecureltd.blogspot.com/2026/01/friday-fun-pentest-series-47-lack-of.html // HTTP Request – Resetting Password – Valid User POST /action/user/requestnewpassword HTTP/1.1 Host: elgg.local User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; … Read More “Username Enumeration – elggv6.3.3 – Full Disclosure” »
The ‘staggering’ cybersecurity weakness that isn’t getting enough focus, according to a top Secret Service official – CyberScoop
The internet domain registration system is a major weakness that malicious hackers can exploit, but is often being overlooked, a senior Secret Service official said Thursday. “It is staggering to me that we live in a world where domain registrars and registrars will do bulk registration of various spellings of a major institution’s brand name … Read More “The ‘staggering’ cybersecurity weakness that isn’t getting enough focus, according to a top Secret Service official – CyberScoop” »
A new joint investigation by SentinelOne SentinelLABS, and Censys has revealed that the open-source artificial intelligence (AI) deployment has created a vast “unmanaged, publicly accessible layer of AI compute infrastructure” that spans 175,000 unique Ollama hosts across 130 countries. These systems, which span both cloud and residential networks across the world, operate outside the – … Read More “Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries – The Hacker News” »
Following a federal raid on Fulton County, Georgia’s Elections Office, lawmakers and state election officials sharply criticized the Trump administration, accusing the White House of chasing baseless internet conspiracy theories about fraud in the 2020 election. Officials also warned the raid could set a precedent for similar federal actions targeting the 2026 midterm elections. According … Read More “Lawmakers, election officials blast Trump administration after Fulton County raid – CyberScoop” »
The U.S. government wants the rest of the world to adopt its artificial intelligence cybersecurity standards, a top official with the Office of the National Cyber Director said Thursday. As part of an effort to advance American AI, the administration will be “undertaking diplomacy efforts to promote American AI cybersecurity standards and norms, establishing industry … Read More “US wants to push its view of AI cybersecurity standards to the rest of the world – CyberScoop” »
Op Bizarre Bazaar: New LLMjacking Campaign Targets Unprotected Models – Hackread – Cybersecurity News, Data Breaches, AI, and More
Pillar Security Research has discovered Operation Bizarre Bazaar, a massive cyberattack campaign led by a hacker known as Hecker. Between December 2025 and January 2026, over 35,000 sessions were recorded targeting AI systems to steal compute power and resell access via silver.inc. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
Common Cloud Migration Security Mistakes (and How to Avoid Them) – Hackread – Cybersecurity News, Data Breaches, AI, and More
Common cloud migration security mistakes explained, from weak access controls to misconfigurations, plus practical steps organisations can take to avoid risk. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
The French data protection regulator said that France Travail’s response to a 2024 data breach violated GDPR – Read More –
The FBI outlines ten actions which organizations can take to defend networks against cybercriminal and nation-state threats – Read More –
Google has taken coordinated action against the massive IPIDEA residential proxy network, enhancing customer protections and disrupting cybercrime operations – Read More –
CISA urges action against insider threats with publication of a new infographic offering strategies to manage risks – Read More –
This startup aims to solve crypto’s broken key management problem – Hackread – Cybersecurity News, Data Breaches, AI, and More
Crypto security firm Sodot launches Exchange API Vault to stop API key theft, securing billions in assets while supporting low latency, high frequency trading. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
Malicious Google Ads Target Mac Users with Fake Mac Cleaner Pages – Hackread – Cybersecurity News, Data Breaches, AI, and More
Mac users searching for software on Google or other search engines should be extra careful. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
US Sentences Chinese National for Role in $36.9 Million Crypto Scam – Hackread – Cybersecurity News, Data Breaches, AI, and More
A Chinese national has been sentenced for his role in a massive $36.9 million cryptocurrency scam operated from… – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
This week’s updates show how small changes can create real problems. Not loud incidents, but quiet shifts that are easy to miss until they add up. The kind that affects systems people rely on every day. Many of the stories point to the same trend: familiar tools being used in unexpected ways. Security controls are … Read More “ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories – The Hacker News” »
The dark web forum administrator confirmed the takedown and said they had “no plans to rebuild” – Read More –
A study by OMICRON has revealed widespread cybersecurity gaps in the operational technology (OT) networks of substations, power plants, and control centers worldwide. Drawing on data from more than 100 installations, the analysis highlights recurring technical, organizational, and functional issues that leave critical energy infrastructure vulnerable to cyber threats. The findings are based on – … Read More “Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps – The Hacker News” »
Beyond the direct impact of cyberattacks, enterprises suffer from a secondary but potentially even more costly risk: operational downtime, any amount of which translates into very real damage. That’s why for CISOs, it’s key to prioritize decisions that reduce dwell time and protect their company from risk. Three strategic steps you can take this year … Read More “3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 – The Hacker News” »
A North Korea-backed threat group operating since 2009 has splintered into three distinct groups with specialized malware and objectives, CrowdStrike said in a report released Thursday. Labeled “Labyrinth Chollima” by the company, the group follows a divergence pattern CrowdStrike observed previously. Labyrinth Chollima has spawned two additional groups: Golden Chollima and Pressure Chollima. The spin-offs, … Read More “Long-running North Korea threat group splits into 3 distinct operations – CyberScoop” »
SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass – The Hacker News
SolarWinds has released security updates to address multiple security vulnerabilities impacting SolarWinds Web Help Desk, including four critical vulnerabilities that could result in authentication bypass and remote code execution (RCE). The list of vulnerabilities is as follows – CVE-2025-40536 (CVSS score: 8.1) – A security control bypass vulnerability that could allow an unauthenticated – Read … Read More “SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass – The Hacker News” »
Despite the seemingly widespread adoption of AI for security operations, security leaders primarily use it for “relatively basic use cases,” said a Sumo Logic study – Read More –
Cybersecurity is now the fifth fastest-growing occupation in the UK, says Socura – Read More –
One small step for Cyber Resilience Test Facilities, one giant leap for technology assurance – NCSC Feed
CRTFs are helping organisations to make informed, risk-based decisions on the adoption of technology products. – Read More – NCSC Feed
Google on Wednesday announced that it worked together with other partners to disrupt IPIDEA, which it described as one of the largest residential proxy networks in the world. To that end, the company said it took legal action to take down dozens of domains used to control devices and proxy traffic through them. As of … Read More “Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks – The Hacker News” »
In a period characterized by the acceleration of digital faster, more regulatory bodies and constant cyber threats, data protection… The post Designing an End-to-End Data Protection Architecture appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock – GRAHAM CLULEY
In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus, we go looking for professional hitmen online – only to uncover uncomfortable questions about … Read More “Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock – GRAHAM CLULEY” »
Lawmakers wonder when Trump administration will weigh on soon-expired surveillance powers – CyberScoop
There’s a growing question on Capitol Hill as the expiration of sweeping U.S. government surveillance powers looms: Where is the Trump administration? The Senate Judiciary Committee held a hearing Wednesday on the 2024 law that revised the surveillance authorities known as Section 702, a part of the Foreign Intelligence Surveillance Act. Advocates have said that … Read More “Lawmakers wonder when Trump administration will weigh on soon-expired surveillance powers – CyberScoop” »
Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers – CyberScoop
Fortinet customers are confronting another actively exploited zero-day vulnerability that allows attackers to bypass authentication in the single sign-on flow for FortiCloud and gain privileged access to multiple Fortinet firewall products and related services. The vendor issued a security advisory for the vulnerability — CVE-2026-24858 — warning that some instances of exploitation already occurred earlier … Read More “Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers – CyberScoop” »
A class of individuals who say they were victimized by nude or undressed deepfakes generated by Grok have filed a lawsuit against parent company xAI, calling the tool “a generative artificial intelligence chatbot that humiliates and sexually exploits women and girls by undressing them and posing them in sexual positions in deepfake images publicly posted … Read More “Undressed victims file class action lawsuit against xAI for Grok deepfakes – CyberScoop” »
How badly do you want to win an online argument? I certainly hope it’s not enough to put the life of the other person at risk. Police in Hungary and Romania have arrested four young men suspected of making hoax bomb threats and terrorising internet users through SWATting and doxing attacks. Read more in my … Read More “Four arrested in crackdown on Discord-based SWATting and doxing – GRAHAM CLULEY” »
Why RAMS Software Is Becoming Essential for Construction Safety and Compliance – Hackread – Cybersecurity News, Data Breaches, AI, and More
Digital RAMS software helps construction teams manage risk assessments, method statements, and safety compliance across sites with real-time access. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
Burner phones and lead-lined bags: a history of UK security tactics in China – Data and computer security | The Guardian
Starmer’s team is wary of spies but such fears are not new – with Theresa May once warned to get dressed under a duvet When prime ministers travel to China, heightened security arrangements are a given – as is the quiet game of cat and mouse that takes place behind the scenes as each country … Read More “Burner phones and lead-lined bags: a history of UK security tactics in China – Data and computer security | The Guardian” »
Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google – Hackread – Cybersecurity News, Data Breaches, AI, and More
The Google Threat Intelligence Group (GTIG) warns that nation-state actors and financially motivated threat actors are exploiting a… – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
The “coordinated” cyber attack targeting multiple sites across the Polish power grid has been attributed with medium confidence to a Russian state-sponsored hacking crew known as ELECTRUM. Operational technology (OT) cybersecurity company Dragos, in a new intelligence brief published Tuesday, described the late December 2025 activity as the first major cyber attack targeting distributed energy … Read More “Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid – The Hacker News” »
Russian Cybercrime Platform RAMP Forum Seized by FBI – Hackread – Cybersecurity News, Data Breaches, AI, and More
US authorities have seized the RAMP cybercrime forum, taking down both its clearnet and dark web domains in a major hit to the ransomware infrastructure. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly Clawdbot) on the official Extension Marketplace that claims to be a free artificial intelligence (AI) coding assistant, but stealthily drops a malicious payload on compromised hosts. The extension, named “ClawdBot Agent – AI Coding Assistant” (“clawdbot.clawdbot-agent”) – Read … Read More “Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware – The Hacker News” »