New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

Ravie LakshmananJan 29, 2026Cybersecurity / Hacking News This week’s updates show how small changes can create real problems. Not loud incidents, but quiet shifts that are easy to miss until they add up. The kind that affects systems people rely on every day. Many of the stories point to the same trend: familiar tools being […]
Study of 100+ Energy Systems Reveals Critical Gaps in OT Cybersecurity

OMICRON’s investigation reveals widespread cybersecurity gaps in operational technology (OT) networks in substations, power plants, and control centers around the world. Based on data from more than 100 installations, this analysis highlights recurring technical, organizational, and functional issues that leave critical energy infrastructure vulnerable to cyberthreats. The findings are based on several years of implementing […]
3 decisions CISOs must make to prevent downtime risk in 2026

hacker newsJanuary 29, 2026Threat intelligence/incident response In addition to the direct impact of a cyberattack, businesses suffer from a secondary but potentially even more costly risk: operational downtime, no matter how much it occurs, leading to very real damage. Therefore, it is important for CISOs to prioritize decisions that reduce dwell time and protect the […]
SolarWinds fixes four critical web help desk flaws related to unauthenticated RCE and authentication bypass

Ravi LakshmananJanuary 29, 2026Vulnerabilities/Software Security SolarWinds has released a security update that addresses multiple security vulnerabilities impacting the SolarWinds Web Help Desk, including four critical vulnerabilities that could lead to authentication bypass and remote code execution (RCE). Here is the list of vulnerabilities: CVE-2025-40536 (CVSS Score: 8.1) – Security control bypass vulnerability that allows unauthenticated […]
Google disrupts IPIDEA, one of the world’s largest residential proxy networks

Google announced Wednesday that it has joined forces with other partners to disrupt IPIDEA. IPIDEA is one of the world’s largest residential proxy networks, the company says. To this end, the company said it has taken legal action to suspend dozens of domains used to control devices and proxy traffic passing through them. At the […]
TwinH: The AI Revolution Redefining Influence, Mentorship, and the Human Legacy

TwinH officially challenges the age-old limitation of ‘only having 24 hours in a day’. With the rise of this technology, biological clocks no longer bind professionals. The digital twin revolution has arrived, and it’s working while you sleep. Meet Your Digital Double: How TwinH is Redefining the Future for Teachers, Mentors, and Influencers For decades, […]
Fake Moltbot AI coding assistant on VS Code marketplace drops malware

Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly known as Clawdbot) on the official extension marketplace. The extension claims to be a free artificial intelligence (AI) coding assistant, but it secretly drops a malicious payload on compromised hosts. The extension was named “ClawdBot Agent – AIcoding […]
Russia’s Electrum linked to December 2025 cyber attack on Polish power grid

Ravi LakshmananJanuary 28, 2026Critical Infrastructure/Threat Intelligence A “coordinated” cyber attack targeting multiple sites across Poland’s electricity grid is believed with medium confidence to be the work of a Russian state-backed hacking group known as ELECTRUM. Operational technology (OT) cybersecurity firm Dragos said in a new intelligence brief released Tuesday that the late December 2025 activity […]
Two high-severity flaws in n8n allow authenticated remote code execution

Ravi LakshmananJanuary 28, 2026Vulnerability/Workflow Automation Cybersecurity researchers have uncovered two new security flaws in the n8n workflow automation platform, including a critical vulnerability that could allow remote code execution. The vulnerabilities discovered by the JFrog Security Research team are as follows: CVE-2026-1470 (CVSS Score: 9.9) – eval injection vulnerability that allows an authenticated user to […]
From triage to threat hunting: how AI accelerates SecOps

If you work in security operations, you’ll be familiar with the concept of an AI SOC agent. Early stories promised complete autonomy. Vendors have seized on the idea of “autonomous SOCs” and proposed a future where algorithms replace analysts. That future has not yet arrived. We have never seen mass layoffs or empty security operations […]