Flaw in Chainlit AI framework allows data theft via file reading and SSRF bugs

Ravi LakshmananJanuary 21, 2026Vulnerability / Artificial Intelligence A security vulnerability has been discovered in the popular open source artificial intelligence (AI) framework Chainlit. This vulnerability could allow an attacker to steal sensitive data and potentially allow lateral movement within a susceptible organization. Zafran Security said the high-severity flaws, collectively referred to as ChainLeak, could be […]

VoidLink Linux malware framework built with AI assistance reaches 88,000 lines of code

A recently discovered sophisticated Linux malware framework known as VoidLink is believed to have been developed by a single person with the assistance of artificial intelligence (AI) models. This is due to new findings from Check Point Research, which identify operational security mistakes by the malware’s creators and shed light on the origin of the […]

LastPass warns of fake maintenance messages targeting users’ master passwords

Rabi LakshmananJanuary 21, 2026Email security/malware LastPass is warning users that a new phishing campaign is active that impersonates the password management service and aims to trick users into giving up their master passwords. The campaign, which began around January 19, 2026, sends phishing emails claiming upcoming maintenance and prompting you to create a local backup […]

CERT/CC warns that bug in binary parser could allow Node.js privileged code execution

Ravi LakshmananJanuary 21, 2026Open source/vulnerabilities A security vulnerability has been disclosed in the popular binary parser npm library that could be successfully exploited to execute arbitrary JavaScript. This vulnerability is tracked as CVE-2026-1245 (CVSS score: N/A) and affects all versions of the module prior to version 2.3.0, which resolves the issue. A patch for this […]

North Korea-linked hackers target developers through malicious VS Code projects

North Korean threat actors associated with the long-running Contagion Interview campaign have been observed using malicious Microsoft Visual Studio Code (VS Code) projects as decoys that provide backdoors to compromised endpoints. According to Jamf Threat Labs, the latest findings demonstrate the continued evolution of new tactics first discovered in December 2025. “This activity included the […]

Three flaws in Anthropic MCP Git server allow file access and code execution

Rabi LakshmananJanuary 20, 2026Vulnerability / Artificial Intelligence A series of three security vulnerabilities have been disclosed in mcp-server-git, the official Git Model Context Protocol (MCP) server maintained by Anthropic. This can be exploited to read or delete arbitrary files and execute code under certain conditions. “These flaws can be exploited through prompt injection, meaning that […]

Hackers use LinkedIn messages to spread RAT malware through DLL sideloading

Ravi LakshmananJanuary 20, 2026Malware/Threat Intelligence Cybersecurity researchers have discovered a new phishing campaign that exploits private social media messages to propagate malicious payloads. This is likely intended to deploy a remote access trojan (RAT). ReliaQuest said in a report shared with The Hacker News that the activity delivers “weaponized files via dynamic link library (DLL) […]

The hidden risks of orphaned accounts

hacker newsJanuary 20, 2026Enterprise Security / AI Security The problem: residual identity As organizations grow and evolve, employees, contractors, services, and systems come and go, but often those accounts remain. These abandoned or “orphaned” accounts lie dormant across applications, platforms, assets, and cloud consoles. They persist not because of neglect but because of fragmentation. Traditional […]

Evelyn Stealer malware exploits VS Code extension to steal developer credentials and cryptography

Ravi LakshmananJanuary 20, 2026Cloud security / developer security Cybersecurity researchers have revealed details of a malware campaign that targets software developers with a new information theft tool called Evelyn Stealer, armed with the Microsoft Visual Studio Code (VS Code) extension ecosystem. “This malware is designed to exfiltrate sensitive information such as developer credentials and cryptocurrency-related […]

Cloudflare fixes ACME validation bug, allows WAF bypass to origin server

Rabi LakshmananJanuary 20, 2026Web security/vulnerabilities Cloudflare has addressed a security vulnerability that affects Automated Certificate Management Environment (ACME) validation logic and allows access to origin servers by bypassing security controls. “The vulnerability was due to the way our edge network handled requests addressed to the ACME HTTP-01 challenge path (/.well-known/acme-challenge/*),” said Hrushikesh Deshpande, Andrew Mitchell, […]