Prioritize, validate, and key results

hacker newsJanuary 27, 2026Attack surface management/cyber risk Cybersecurity teams want to go further than just considering threats and vulnerabilities in isolation. It’s not just about what could go wrong (vulnerabilities) and who could attack (threats), but also where they might intersect in a real-world environment to expose you to real exploitable risks. Which exposures really […]

Critical vulnerability in Grist-Core allows RCE attacks via spreadsheet formulas

Ravi LakshmananJanuary 27, 2026Vulnerability / Cloud Security A critical security flaw has been disclosed in Grist‑Core, an open source self-hosted version of the Grist relational spreadsheet database, that could allow remote code execution. This vulnerability is tracked as CVE-2026-24002 (CVSS score: 9.1) and codenamed “Cellbreak” by Cyera Research Labs. “A malicious formula could turn a […]

China-linked hackers will use PeckBirdy JavaScript C2 framework starting in 2023

Ravi LakshmananJanuary 27, 2026Web security/malware Cybersecurity researchers have discovered a JScript-based command and control (C2) framework called PeckBirdy. This framework has been used by Chinese-aligned APT actors to target multiple environments since 2023. According to Trend Micro, this flexible framework is being used against malicious activity targeting China’s gambling industry as well as government and […]

Microsoft Office Zero Day (CVE-2026-21509) – Emergency patch issued for active exploit

Ravi LakshmananJanuary 27, 2026Zero-day/vulnerabilities Microsoft on Monday issued an out-of-band security patch for a high-severity zero-day vulnerability in Microsoft Office that was exploited in the attack. This vulnerability is tracked as CVE-2026-21509 and has a CVSS score of 7.8 out of 10.0. This is described as a bypass of Microsoft Office security features. “Microsoft Office’s […]

Indian users targeted by tax phishing campaign distributing Blackmoon malware

Ravi LakshmananJanuary 26, 2026Cyber ​​espionage/malware Cybersecurity researchers have discovered an ongoing campaign targeting users in India using multi-stage backdoors as part of a suspected cyber espionage campaign. According to the eSentire Threat Response Unit (TRU), this activity involves using phishing emails impersonating the Indian Income Tax Department to trick victims into downloading malicious archives, ultimately […]

Malicious VS Code AI extension installed 1.5 million times steals developer source code

Ravi LakshmananJanuary 26, 2026AI security/vulnerabilities Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also have secret capabilities that siphon developer data to servers based in China. These extensions have been installed a total of 1.5 million times and are still […]

Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More

Ravie LakshmananJan 26, 2026Hacking News / Cybersecurity Security failures rarely arrive loudly. They slip in through trusted tools, half-fixed problems, and habits people stop questioning. This week’s recap shows that pattern clearly. Attackers are moving faster than defenses, mixing old tricks with new paths. “Patched” no longer means safe, and every day, software keeps becoming […]

Winning against AI-based attacks requires a combined defensive approach

hacker newsJanuary 26, 2026Endpoint security/artificial intelligence If there’s one constant in cybersecurity, it’s that adversaries are constantly innovating. The rise of aggressive AI is changing attack strategies and making attacks harder to detect. Google’s Threat Intelligence Group recently reported that attackers are using large language models (LLMs) to hide code, generate malicious scripts on the […]

Konni hacker deploys AI-generated PowerShell backdoor against blockchain developers

Ravi LakshmananJanuary 26, 2026Malware/Endpoint Security A North Korean threat actor known as Konni has been observed targeting developers and engineering teams in the blockchain space using PowerShell malware generated using artificial intelligence (AI) tools. Check Point Research said in a technical report released last week that the phishing campaign targeted Japan, Australia and India, highlighting […]

Multi-stage phishing campaign targeting Russia with Amnesia RAT and ransomware

A new multi-stage phishing campaign was observed targeting users in Russia using ransomware and a remote access Trojan called Amnesia RAT. “This attack begins with a social engineering lure delivered via business-themed documents designed to appear routine and harmless,” Fortinet FortiGuard Labs researcher Cara Lin said in technical details released this week. “These documents and […]