New DynoWiper malware used in attempted sandworm attack on Poland’s power sector

Ravi LakshmananJanuary 24, 2026Malware/Critical Infrastructure The Russian state hacking group known as Sandworm is said to have been behind what was described as the “largest cyber attack” targeting Poland’s electricity system in the last week of December 2025. The country’s Energy Minister Milos Motyka said last week that the attack had failed. “The Cyberspace Command […]
Who authorized this agent? Rethinking access, accountability, and risk in the age of AI agents

AI agents are accelerating the way we get work done. Schedule meetings, access data, trigger workflows, write code, and take actions in real-time to boost productivity beyond human speed across your enterprise. And there comes a moment when all security teams are finally faced with the following question: “Wait… who approved this?” Unlike users and […]
CISA adds actively exploited VMware vCenter flaw CVE-2024-37079 to KEV catalog

Ravi LakshmananJanuary 24, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting Broadcom VMware vCenter Server patched in June 2024 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of real-world exploitation. The vulnerability in question is CVE-2024-37079 (CVSS score: 9.8). This refers to […]
CISA updates KEV catalog to fix four actively exploited software vulnerabilities

Rabi LakshmananJanuary 23, 2026Vulnerabilities/Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of them being exploited in the wild. Here is the list of vulnerabilities: CVE-2025-68645 (CVSS score: 8.8) – PHP remote file include vulnerability in Synacor Zimbra Collaboration […]
Fortinet Verifies Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls

Rabi LakshmananJanuary 23, 2026Network security/vulnerabilities Fortinet has officially confirmed that it is working to fully resolve the FortiCloud SSO authentication bypass vulnerability following reports of new exploit activity on fully patched firewalls. “Over the past 24 hours, we have identified a number of cases in which devices were fully upgraded to the latest release at […]
TikTok establishes joint venture in the U.S. to continue business pursuant to 2025 Executive Order

Ravi LakshmananJanuary 23, 2026Regulatory Compliance/National Security TikTok officially announced Friday that it has formed a joint venture that will allow the wildly popular video-sharing application to continue operating in the United States. The new venture, named TikTok USDS Joint Venture LLC, was established pursuant to an executive order signed by US President Donald Trump in […]
Phishing attack uses stolen credentials to install LogMeIn RMM for permanent access

Rabi LakshmananJanuary 23, 2026Email security/endpoint security Cybersecurity researchers have detailed a new dual-vector campaign that leverages stolen credentials to deploy legitimate remote monitoring and management (RMM) software to gain persistent remote access to compromised hosts. “Instead of deploying custom viruses, attackers are circumventing security boundaries by weaponizing necessary IT tools that administrators trust,” said Jeewan […]
Microsoft warns of multi-stage AitM phishing and BEC attacks targeting energy companies

Microsoft has warned of a multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) campaign targeting multiple organizations in the energy sector. “The campaign exploited the SharePoint file sharing service to deliver a phishing payload and relied on creating inbox rules to maintain persistence and avoid user awareness,” the Microsoft Defender Security Research Team said. […]
New Osiris ransomware emerges as a new variant that uses POORTRY drivers in BYOVD attacks

Cybersecurity researchers have revealed details of a new ransomware family called Osiris that targeted major food service franchise operators in Southeast Asia in November 2025. According to Symantec and the Carbon Black Threat Hunter Team, the attack used a malicious driver called POORTRY as part of a known technique known as BYOVD (Bring Your Own […]
Critical flaw in GNU InetUtils telnetd allows attacker to bypass login and gain root access

Ravi LakshmananJanuary 22, 2026Vulnerabilities / Linux A serious security flaw has been revealed in the GNU InetUtils Telnet daemon (telnetd) that went unnoticed for nearly 11 years. This vulnerability is tracked as CVE-2026-24061 and is rated 9.8 out of 10.0 on the CVSS scoring system. This affects all versions of GNU InetUtils from version 1.9.3 […]