Critical flaw in vm2 Node.js allows sandbox escape and arbitrary code execution

Ravi LakshmananJanuary 28, 2026Vulnerabilities / Open Source A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system. This vulnerability is tracked as CVE-2026-22709 and has a CVSS score of 9.8 out of 10.0 in the […]

Mustang Panda Deploys Latest COOLCLIENT Backdoor to Government Cyberattacks

In the 2025 cyber espionage attack, Chinese-linked threat actors were observed using the latest version of a backdoor called COOLCLIENT to facilitate comprehensive data theft from infected endpoints. The activity was attributed to Mustang Panda (also known as Earth Preta, Fireant, HoneyMyte, Polaris, and Twill Typhoon), and the intrusions were primarily targeted at government agencies […]

Falsely reusing passwords: A risky and often overlooked workaround

When security teams discuss credential-related risks, they typically focus on threats like phishing, malware, and ransomware. These attack techniques continue to evolve and are gaining the attention they deserve. However, one of the most persistent and underappreciated risks to organizational security remains far more common. Reusing nearly identical passwords continues to bypass security controls and […]

Google warns of active exploitation of WinRAR vulnerability CVE-2025-8088

Ravi LakshmananJanuary 28, 2026Vulnerability/Threat Intelligence Google revealed on Tuesday that multiple threat actors, including state adversaries and financially motivated groups, are exploiting critical patched security flaws in RARLAB WinRAR to gain initial access and deploy various payloads. “Although discovered and patched in July 2025, government-sponsored and financially motivated actors associated with Russia and China continue […]

Fake Python Spellchecker package on PyPI delivers hidden remote access Trojan

Ravi LakshmananJanuary 28, 2026Supply chain security/malware Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that contain the ability to deliver a remote access trojan (RAT) while masquerading as a spell checker. The packages named Spellcheckerpy and Spellcheckpy are currently not available for download, but they were previously downloaded over […]

Unmasking new TOAD attacks hidden in legitimate infrastructure

“Living off the land” has become a preferred tactic for threat actors in many attack scenarios. This time, an existing “innocuous” component is being used as part of a phishing campaign. By leveraging the reputation of trusted services like PayPal and Zoom, attackers can bypass traditional Secure Email Gateways (SEGs) that whitelist these domains. Recently, […]

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Ravi LakshmananJanuary 28, 2026Network security/zero day Fortinet has begun releasing security updates to address critical flaws affecting FortiOS that are being exploited in the wild. The vulnerability, assigned CVE identifier CVE-2026-24858 (CVSS score: 9.4), is described as an authentication bypass related to FortiOS single sign-on (SSO). This flaw also affects FortiManager and FortiAnalyzer. The company […]

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

Ravi LakshmananJanuary 27, 2026Mobile security/spyware Meta announced Tuesday that it is adding stricter account settings to WhatsApp to protect some users from advanced cyberattacks. This feature, similar to Lockdown Mode in Apple iOS and Advanced Protection in Android, is intended to protect individuals, such as journalists and public figures, from advanced spyware by trading some […]

Experts detect Pakistan-linked cyber attack targeting Indian government agencies

Ravi LakshmananJanuary 27, 2026Threat Intelligence/Cyber ​​Espionage Indian government agencies have been targeted in two campaigns conducted by threat actors operating in Pakistan using previously undocumented trade channels. These campaigns were codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, identified in September 2025. “While these campaigns share some similarities with APT36, a Pakistan-linked advanced persistent […]

ClickFix attack spreads using fake CAPTCHAs, Microsoft Scripts, and trusted web services

Cybersecurity researchers have detailed a new campaign that combines ClickFix-style fake CAPTCHAs with signed Microsoft Application Virtualization (App-V) scripts to distribute an information stealer called Amatera. “Rather than directly invoking PowerShell, attackers use this script to control how execution begins, avoiding more common and easily recognized execution paths,” Blackpoint researchers Jack Patrick and Sam Decker […]