CISA warns that Gogs vulnerability that allows code execution is being actively exploited

January 13, 2026Ravi LakshmananVulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw affecting Gogs to its Known Exploited Vulnerabilities (KEV) catalog, warning that it can be actively exploited. This vulnerability is tracked as CVE-2025-8110 (CVSS score: 8.7) and is related to a path traversal case in the repository […]

n8n supply chain attack exploits community nodes to steal OAuth tokens

January 12, 2026Ravi LakshmananVulnerability/Workflow Automation Threat actors have been observed uploading a set of eight packages to the npm registry masquerading as integrations targeting the n8n workflow automation platform to steal developers’ OAuth credentials. One such package, named ‘n8n-nodes-hfgjf-irtuinvcm-lasdqewriit’, mimics the Google Ads integration, prompting users to link their ad accounts in a seemingly legitimate […]

AI Automation Exploits, Telecom Espionage, Prompt Poaching & More

Jan 12, 2026Ravie LakshmananHacking News / Cybersecurity This week made one thing clear: small oversights can spiral fast. Tools meant to save time and reduce friction turned into easy entry points once basic safeguards were ignored. Attackers didn’t need novel tricks. They used what was already exposed and moved in without resistance. Scale amplified the […]

GoBruteforcer botnet exploits weak credentials to target crypto project databases

A new wave of GoBruteforcer attacks targets the databases of cryptocurrencies and blockchain projects, putting them into botnets that can brute force user passwords for services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux servers. “The current wave of campaigns is being driven by two factors: the mass reuse of AI-generated server deployments that […]

Anthropic launches Claude AI for healthcare with secure medical record access

January 12, 2026Ravi LakshmananArtificial intelligence/healthcare Anthropic has become the latest artificial intelligence (AI) company to announce a new suite of features that will give users of its Claude platform a deeper understanding of their health information. Under an initiative called Claude for Healthcare, Claude Pro and Max plan subscribers in the U.S. can choose to […]

Researchers uncover service providers facilitating industrial-scale pig butchering scams

Cybersecurity researchers have highlighted two service providers that provide online criminal networks with the tools and infrastructure needed to facilitate the Pig Butchering as a Service (PBaaS) economy. Since at least 2016, Chinese-speaking criminal groups have set up industrial-scale fraud centers across Southeast Asia and created special economic zones specializing in fraudulent investment and identity […]

MuddyWater launches RustyWater RAT via spearphishing across Middle East sector

January 10, 2026Ravi LakshmananCyber ​​espionage/malware The Iranian threat actor known as MuddyWater is believed to have engaged in spear-phishing campaigns targeting diplomatic, maritime, financial, and communications institutions in the Middle East using a Rust-based implant known by the codename RustyWater. “The campaign uses icon spoofing and malicious Word documents to deliver a Rust-based implant capable […]

Europol arrests 34 Spanish Black Ax members for €5.9 million fraud and organized crime

January 10, 2026Ravi LakshmananCybercrime/Financial Crime Europol announced on Friday that it had arrested 34 people in Spain suspected of being members of the international criminal organization Black Ax. As part of an operation carried out by the Spanish National Police in collaboration with the Bavarian Criminal Police and Europol, 28 people were arrested in Seville, […]

China-linked hackers exploit VMware ESXi zero-day to escape virtual machines

January 9, 2026Ravi LakshmananVirtualization/Vulnerability Chinese-speaking attackers are suspected of using compromised SonicWall VPN appliances as an initial access vector to deploy a VMware ESXi exploit that may have been developed in February 2024. Cybersecurity firm Huntress, which observed the activity in December 2025 and stopped it before it could reach its final stage, said it […]

Russia’s APT28 runs credential theft campaign targeting energy and policy organizations

January 9, 2026Ravi LakshmananEmail Security/Threat Intelligence Russian state-sponsored threat actors have been implicated in a series of new credential harvesting attacks targeting individuals associated with Turkey’s Energy and Nuclear Research Institute, as well as staff affiliated with European think tanks and organizations in North Macedonia and Uzbekistan. This activity is believed to be by APT28 […]