AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories

Jan 15, 2026Ravie LakshmananCybersecurity / Hacking News The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep finding new ways to break in. Read on […]
Model security is the wrong framework – the real risk is workflow security

January 15, 2026hacker newsData security/artificial intelligence Even as AI co-pilots and assistants become part of daily operations, security teams are still focused on securing the models themselves. However, recent incidents suggest that the greater risk lies elsewhere: in the workflows surrounding these models. Two Chrome extensions masquerading as AI helpers were recently caught stealing ChatGPT […]
4 outdated habits that will destroy your SOC’s MTTR in 2026

Even though it’s 2026, many SOCs are still operating the same way they did a few years ago, with tools and processes designed for a completely different threat landscape. Given the growing volume and complexity of cyber threats, outdated practices can no longer fully support the needs of analysts, significantly slowing investigations and incident response. […]
Microsoft legal action disrupts RedVDS cybercrime infrastructure used for online fraud

Microsoft announced Wednesday that it has taken “coordinated legal action” in the United States and United Kingdom to disrupt a cybercrime subscription service called RedVDS that is said to have caused millions in fraudulent losses. The tech giant said the effort was part of a broader law enforcement operation in collaboration with law enforcement authorities […]
Palo Alto fixes GlobalProtect DoS flaw that could crash firewall without logging in

January 15, 2026Ravi LakshmananNetwork security/vulnerabilities Palo Alto Networks has released a security update for a high-severity security flaw affecting GlobalProtect Gateway and Portal. It states that a proof-of-concept (PoC) exploit exists for this flaw. This vulnerability is tracked as CVE-2026-0227 (CVSS score: 7.7) and is described as a denial of service (DoS) condition affecting GlobalProtect […]
Researchers null-root over 550 Kimwolf and Aisuru botnet command servers

Lumen Technologies’ Black Lotus Labs team announced that it had been null-routing traffic to more than 550 command and control (C2) nodes associated with the AISURU/Kimwolf botnet since early October 2025. AISURU and its Android counterpart Kimwolf have recently emerged as one of the largest botnets, capable of forcing enslaved devices to participate in distributed […]
AI agents are becoming a privilege escalation path

AI agents have rapidly moved from experimental tools to core components of daily workflows across security, engineering, IT, and operations. What began as personal code assistants, chatbots, and co-pilots to help individuals improve their productivity have evolved into shared agents across the organization embedded in critical processes. These agents can coordinate workflows across multiple systems. […]
Hackers exploit sideloading of c-ares DLLs to bypass security and deploy malware

Security experts have detailed an active malware campaign that exploits a DLL sideloading vulnerability in legitimate binaries related to the open source c-ares library to bypass security controls and deliver a wide range of commodity Trojans and stealers. “The attacker achieves evasion by combining the malicious libcares-2.dll with a signed version of the legitimate ahost.exe […]
Fortinet fixes critical FortiSIEM flaw that allows unauthenticated remote code execution

January 14, 2026Ravi LakshmananVulnerability/patch management Fortinet has released an update that fixes a critical security flaw affecting FortiSIEM that could allow an unauthenticated attacker to execute code on a susceptible instance. The operating system (OS) injection vulnerability tracked as CVE-2025-64155 is rated 9.4 out of 10.0 on the CVSS scoring system. “Improper Disabling of Special […]
64% of third-party applications access sensitive data without legitimate reason

The study, which analyzed 4,700 major websites, found that 64% of third-party applications now access sensitive data without a legitimate business reason, up from 51% in 2024. Malicious activity in the government sector jumped from 2% to 12.9%, with 1 in 7 education sites showing active compromise. Specific violators: Google Tag Manager (8% of violations), […]