OpenAI shows ads on ChatGPT to logged in US adults on Free and Go plans

January 17, 2026Ravi LakshmananArtificial intelligence/data privacy OpenAI announced Friday that it will begin showing ads on ChatGPT to U.S. adult users who are logged in on both the free and ChatGPT Go tiers in the coming weeks, as the artificial intelligence (AI) company expands access to low-cost subscriptions globally. “People should know that their data […]

GootLoader malware uses 500 to 1,000 concatenated ZIP archives to evade detection

January 16, 2026Ravi LakshmananMalvertising/Threat Intelligence A JavaScript (also known as JScript) malware loader called GootLoader has been observed using malicious ZIP archives designed to evade detection efforts by concatenating 500 to 1,000 archives. “Adversaries are creating fraudulent archives as an anti-analysis technique,” Aaron Walton, a security researcher at Expel, said in a report shared with […]

Five malicious Chrome extensions impersonate Workday and NetSuite to take over accounts

Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that impersonate human resources (HR) and enterprise resource planning (ERP) platforms such as Workday, NetSuite, and SuccessFactors to take control of victims’ accounts. “The extensions work together to steal authentication tokens, block incident response functionality, and enable complete account takeover through session hijacking,” […]

Your digital footprint can end right at your doorstep

January 16, 2026hacker newsPrivacy/Data Protection Lock the door at night. You avoid sketchy calls. You are careful about what you post on social media. But what happens to the information about you that has already been published without your permission? your name. home address. telephone number. past work. Dear family. Old username. Everything is still […]

LOTUSLITE backdoor targets US policy agencies using Venezuela-themed spear phishing

January 16, 2026Ravi LakshmananMalware/Cyber ​​Espionage Security experts have revealed details of a new campaign targeting U.S. government and policy actors using politically-themed decoys to deliver a backdoor known as LOTUSLITE. The targeted malware campaign utilizes decoys related to recent geopolitical developments between the United States and Venezuela to distribute a ZIP archive (“US deciding what’s […]

China-linked APT exploits Sitecore zero-day to attack critical U.S. infrastructure

January 16, 2026Ravi LakshmananZero Day/Cyber ​​Espionage Threat actors believed to be aligned with China have been observed targeting critical infrastructure sectors in North America since at least the last year. Cisco Talos, which is tracking this activity under the name UAT-8837, has assessed with medium confidence that this is a Chinese-aligned Advanced Persistent Threat (APT) […]

Cisco patches zero-day RCE exploited by China-linked APT in secure email gateway

January 16, 2026Ravi LakshmananVulnerabilities / Web Security Cisco on Thursday released a security update for maximum severity security flaws affecting Cisco AsyncOS software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This comes nearly a month after the company disclosed that it had been attacked by a zero-day attack by a […]

AWS CodeBuild misconfiguration exposed GitHub repository to potential supply chain attacks

A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could result in a complete takeover of a cloud service provider’s own GitHub repository containing the AWS JavaScript SDK, potentially putting all AWS environments at risk. The vulnerability has been codenamed “CodeBreach” by cloud security company Wiz. This issue was fixed by AWS in September 2025 […]

Critical flaw in WordPress Modular DS plugin can be actively exploited to gain administrator access

January 15, 2026Ravi LakshmananWeb security/vulnerabilities According to Patchstack, a maximum severity security flaw in a WordPress plugin called Modular DS is being exploited in the wild. This vulnerability is tracked as CVE-2026-23550 (CVSS score: 10.0) and is described as a case of unauthenticated privilege escalation affecting all versions of the plugin prior to 2.5.1. Version […]

Researchers uncover a re-prompting attack that allows data to be extracted from Microsoft Copilot with a single click

January 15, 2026Ravi LakshmananPrompt injection / enterprise security Cybersecurity researchers have revealed details of a new attack method called “Reprompt.” This attack technique could allow malicious attackers to steal sensitive data from artificial intelligence (AI) chatbots such as Microsoft Copilot with a single click, completely bypassing corporate security controls. “It only takes one click on […]