Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories

Ravie LakshmananJan 22, 2026Cybersecurity / Hacking News Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them. What stands out is how little friction attackers now […]
Close the most common gaps in Google Workspace security

hacker newsJanuary 22, 2026Email security/SaaS security Security teams at agile, fast-growing companies are often tasked with the same mission: ensuring security without slowing down the business. Most teams inherit a technology stack that is optimized for exponential growth, not resilience. In these environments, the security team is a help desk, compliance expert, and incident response […]
Malicious PyPI package impersonates SymPy and deploys XMRig Miner to Linux hosts

Rabi LakshmananJanuary 22, 2026Cryptojacking/Malware A new malicious package discovered in the Python Package Index (PyPI) was found to impersonate a popular symbolic mathematics library and deploy a malicious payload, including a cryptocurrency miner, to Linux hosts. The package, named sympy-dev, mimics SymPy and copies SymPy’s project description exactly in an attempt to trick unsuspecting users […]
SmarterMail authentication bypass exploited 2 days after patch release

Rabi LakshmananJanuary 22, 2026Vulnerabilities / Email Security A new security flaw in SmarterTools SmarterMail email software is now being exploited in the wild two days after a patch was released. This vulnerability currently does not have a CVE identifier and is tracked by watchTowr Labs as WT-2026-0001. Patched by SmarterTools with build 9511 on January […]
Automated FortiGate attack exploits FortiCloud SSO to change firewall configuration

Ravi LakshmananJanuary 22, 2026Network security/vulnerabilities Cybersecurity firm Arctic Wolf warned of a “new cluster of automated malicious activity” involving unauthorized firewall configuration changes on Fortinet FortiGate devices. The group said the campaign began on January 15, 2026, adding that it bears similarities to a December 2025 campaign in which malicious SSO logins on FortiGate appliances […]
Cisco fixes actively exploited zero-day CVE-2026-20045 in Unified CM and Webex

Rabi LakshmananJanuary 22, 2026Vulnerability/Zero-day Cisco has released a new patch to address what it describes as a “critical” security vulnerability affecting multiple unified communications (CM) products and Webex Calling dedicated instances. This vulnerability is actively being exploited in the wild as a zero-day attack. Vulnerability CVE-2026-20045 (CVSS score: 8.2) could allow an unauthenticated, remote attacker […]
North Korea’s ‘PurpleBravo’ campaign targets 3,136 IP addresses with fake job interviews

As many as 3,136 individual IP addresses have been identified associated with possible targets of the Contagious Interview campaign, which claims to include 20 potential victim organizations across the artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development sectors in Europe, South Asia, the Middle East, and Central America. This new discovery […]
Zoom and GitLab release security updates that fix RCE, DoS, and 2FA bypass flaws

Rabi LakshmananJanuary 21, 2026Vulnerability/Network Security Zoom and GitLab have released security updates that resolve a number of security vulnerabilities that could lead to a denial of service (DoS) or remote code execution. The most serious issue is a critical security flaw affecting the Zoom Node Multimedia Router (MMR) that could allow meeting participants to conduct […]
How smart MSSPs leverage AI to increase profits with half their staff

hacker newsJanuary 21, 2026Artificial intelligence/automation In 2026, all managed security providers will be challenged by the same problem. Clients who have too many alerts, too few analysts, and require “CISO-level protection” on small business budgets. truth? Most MSSPs are running harder, not smarter. And it’s breaking their limits. A quiet revolution is taking place there. […]
Exposure assessment platforms signal a shift in focus

Gartner® doesn’t create new categories lightly. Typically, new acronyms emerge only when it becomes mathematically impossible to complete an industry-wide “to-do list.” The introduction of the Exposure Assessment Platform (EAP) category therefore appears to be a formal acknowledgment that traditional vulnerability management (VM) is no longer a viable way to protect modern enterprises. The transition […]