Microsoft fixes 114 Windows flaws in January 2026 patch, 1 of which is actively being exploited

Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability it announced was being actively exploited in the wild. Of the 114 deficiencies, 8 are rated as critical and 106 are rated as important. As many as 58 vulnerabilities were classified as privilege escalation, followed by 22 […]
Critical vulnerability in Node.js could cause server crash via async_hooks stack overflow

January 14, 2026Ravi LakshmananApplication security/vulnerabilities Node.js has released an update that fixes an issue described as a critical security issue that affects “virtually all production Node.js apps.” Exploitation of this issue could lead to a denial of service (DoS) condition. “Node.js/V8 makes a best-effort attempt to recover from stack space exhaustion due to catchable errors, […]
PLUGGYAPE malware uses Signal and WhatsApp to target Ukrainian Armed Forces

January 14, 2026Ravi LakshmananCyber espionage/threat intelligence The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed details of a new cyberattack targeting the Armed Forces between October and December 2025 with malware known as PLUGGYAPE. This activity is believed with medium confidence to be the work of a Russian hacker group tracked as Void Blizzard […]
Long-running web skimming campaign steals credit cards from online checkout pages

January 13, 2026Ravi Lakshmanan Web security/data theft Cybersecurity researchers have discovered a large-scale web skimming campaign that has been active since January 2022, targeting several major payment networks, including American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. “Enterprise organizations that are customers of these payment providers are likely to be most affected,” […]
Malicious Chrome extension steals MEXC API keys by pretending to be a trading tool

January 13, 2026Ravi LakshmananWeb security/online fraud Cybersecurity researchers have detailed a malicious Google Chrome extension that can steal API keys related to MEXC, a centralized cryptocurrency exchange (CEX) available in more than 170 countries, while masquerading as a tool to automate transactions on the platform. The extension is called MEXC API Automator (ID: pppdfgkfdemgfknfnhpkibbkabhghhfh), has […]
From MCP and tool access to shadow API key sprawl

January 13, 2026hacker newsArtificial Intelligence/Automation Security AI agents no longer just write code. they are doing it. With tools like Copilot, Claude Code, and Codex, you can now build, test, and deploy software end-to-end in minutes. This speed is reshaping engineering, but it’s also creating security gaps that most teams don’t realize until something breaks. […]
New advanced Linux VoidLink malware targets cloud and container environments

January 13, 2026Ravi LakshmananThreat Intelligence/Cyber Espionage Cybersecurity researchers have revealed details of a previously undocumented, feature-rich malware framework codenamed VoidLink that is specifically designed for long-term, stealthy access to Linux-based cloud environments. According to a new report from Check Point Research, cloud-native Linux malware frameworks consist of a set of custom loaders, implants, rootkits, and […]
What should we learn from how attackers leverage AI in 2025?

January 13, 2026hacker newsThreat Intelligence/Identity Security Old strategy, new scale: While defenders chase trends, attackers optimize fundamentals. The security industry loves to talk about “new” threats. Attacks using AI. Quantum-resistant encryption. Zero Trust Architecture. But if you look around, it seems like the most effective attacks in 2025 will be pretty much the same as […]
ServiceNow fixes critical AI platform flaw that allows unauthenticated user impersonation

January 13, 2026Ravi LakshmananVulnerabilities / SaaS Security ServiceNow has revealed details of a critical security flaw affecting the ServiceNow AI platform that is currently being patched. This flaw could allow an unauthenticated user to impersonate another user and perform arbitrary actions as that user. This vulnerability was tracked as CVE-2025-12420 and had a CVSS score […]
New malware campaign delivers Remcos RAT via multi-stage Windows attack

January 13, 2026Ravi LakshmananMalware/Endpoint Security Cybersecurity researchers have revealed details of a new campaign called “SHADOW#REACTOR.” The campaign utilizes an evasive multi-stage attack chain to distribute a commercially available remote administration tool called Remcos RAT to establish persistent and covert remote access. “The infection chain follows a tightly tailored execution path: an obfuscated VBS launcher […]