Why the secret of JavaScript bundles is still overlooked

API key leaks are no longer uncommon, and so are subsequent breaches. So why are sensitive tokens still so easily exposed? To find out, Intruder’s research team investigated what traditional vulnerability scanners actually cover and built a new secret detection method to address gaps in existing approaches. Applying this at scale by scanning 5 million […]

Tudou Guaranteed Marketplace Stops Telegram Trading After Processing Over $12 Billion

Ravi LakshmananJanuary 20, 2026Cryptocurrency/Artificial Intelligence A Telegram-based guarantee marketplace known for promoting a wide range of illegal services appears to be winding down its operations, according to new research from Elliptic. Blockchain intelligence company Tudou Warranty said it has effectively ceased trading through its public Telegram group after a period of significant growth. The market […]

Google Gemini Prompt Injection Flaw Exposes Private Calendar Data via Malicious Invites

Cybersecurity researchers have detailed a security flaw that leverages indirect prompted injection targeting Google Gemini as a way to bypass authorization guardrails and use Google Calendar as a data extraction mechanism. According to Liad Eliyahu, head of research at Miggo Security, the vulnerability allowed an attacker to bypass Google Calendar’s privacy controls by hiding a […]

Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More

Ravie LakshmananJan 19, 2026Hacking News / Cybersecurity In cybersecurity, the line between a normal update and a serious incident keeps getting thinner. Systems that once felt reliable are now under pressure from constant change. New AI tools, connected devices, and automated systems quietly create more ways in, often faster than security teams can react. This […]

The High (and Hidden) Costs for Cloud-First Businesses

Just a few years ago, the cloud was touted as the “magic pill” for any cyber threat or performance issue. Many were lured by the “always-on” dream, trading granular control for the convenience of managed services. In recent years, many of us have learned (often the hard way) that public cloud service providers are not […]

New StackWarp hardware flaw breaks AMD SEV-SNP protection for Zen 1-5 CPUs

Ravi LakshmananJanuary 19, 2026Hardware security/vulnerabilities A team of academics from Germany’s CISPA Helmholtz Center for Information Security has revealed details of a new hardware vulnerability affecting AMD processors. The security flaw, codenamed StackWarp, could allow a malicious attacker with privileged control over a host server to execute malicious code within a Confidential Virtual Machine (CVM), […]

CrashFix Chrome extension serves ModeloRAT using ClickFix-style browser crash lures

Cybersecurity researchers have revealed details of an ongoing campaign called KongTuke that uses a malicious Google Chrome extension masquerading as an ad blocker to intentionally crash web browsers, uses ClickFix-like lures to trick victims into executing arbitrary commands, and delivers a previously undocumented remote access Trojan (RAT) called ModeloRAT. This new escalation of ClickFix is […]

Security bug in StealC malware panel allows researchers to monitor threat actor operations

Ravi LakshmananJanuary 19, 2026Malware/Threat Intelligence Cybersecurity researchers have revealed a cross-site scripting (XSS) vulnerability in the web-based control panel used by StealC information stealer operators. This allows us to gather important insights into one of the attackers who use the malware in production. “By exploiting this, they were able to collect system fingerprints, monitor active […]

CISO guide to AI security investments

AI is reshaping the enterprise landscape, and security budgets are struggling to keep up. As organizations rush to adopt AI, security teams face increasing pressure to protect these systems without clear guidance on where to invest their limited resources. The challenge is not just to protect AI, but to do so strategically. CISOs are faced […]

Black Basta ransomware leader added to EU’s Most Wanted and INTERPOL Red Notices

Ravi LakshmananJanuary 17, 2026Law enforcement/cybercrime Law enforcement authorities in Ukraine and Germany have identified two Ukrainian nationals suspected of working for the Russia-linked ransomware-as-a-service (RaaS) group Black Basta. Additionally, authorities noted that the group’s alleged leader, 35-year-old Russian Oleg Evgenievich Nefedov (Нефедов Олег Евгеньевич), has been added to the European Union’s Most Wanted List and […]