Researchers discover NodeCordRAT hidden in npm Bitcoin-themed packages

January 8, 2026Rabi LakshmananMalware/Cloud Security Cybersecurity researchers discovered three malicious npm packages designed to deliver previously undocumented malware called NodeCordRAT. Below are the names of all removed packages as of November 2025. These were uploaded by a user named ‘wenmoonx’. “The bitcoin-main-lib and bitcoin-lib-js packages run a postinstall.cjs script during installation, which installs bip40, a […]
Coolify discloses 11 critical flaws that allow full server compromise on self-hosted instances

January 8, 2026Rabi LakshmananVulnerabilities / Container Security Cybersecurity researchers have detailed multiple-severity security flaws affecting Coolify, an open-source self-hosting platform. This could lead to authentication bypass or remote code execution. Here is the list of vulnerabilities: CVE-2025-66209 (CVSS Score: 10.0) – Command injection vulnerability in the database backup feature allows an authenticated user with database […]
OpenAI launches ChatGPT Health with isolated and encrypted health data controls

January 8, 2026Ravi LakshmananPrivacy / Artificial Intelligence Artificial intelligence (AI) company OpenAI on Wednesday announced the launch of ChatGPT Health, a dedicated space where users can have conversations with chatbots about their health. That’s why the Sandbox experience gives users the option to securely connect their medical records and wellness apps like Apple Health, Function, […]
CISA reports bugs in Microsoft Office and HPE OneView as being actively exploited

January 8, 2026Rabi LakshmananVulnerabilities / KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws affecting Microsoft Office and Hewlett Packard Enterprise’s (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2009-0556 (CVSS Score: 8.8) – Code injection […]
Black Cat behind SEO-tainting malware campaign targeting popular software search

January 7, 2026Ravi LakshmananCybercrime/Software Security A cybercriminal organization known as Black Cat is believed to be involved in search engine optimization (SEO) poisoning campaigns that use fraudulent sites promoting popular software to trick users into downloading backdoors that can steal sensitive data. According to a report published by the China National Computer Network Emergency Response […]
Critical vulnerability in n8n (CVSS 10.0) allows unauthenticated attacker to gain complete control

January 7, 2026Rabi LakshmananVulnerability/Automation Cybersecurity researchers have detailed yet another maximum-severity security flaw in n8n, a popular workflow automation platform. This flaw allows an unauthenticated, remote attacker to gain complete control of a susceptible instance. This vulnerability is tracked as CVE-2026-21858 (CVSS score: 10.0) and codenamed “Ni8mare” by Cyera Research Labs. Security researcher Dor Attias […]
Learn how AI-powered Zero Trust detects attacks without files or indicators

January 7, 2026hacker newsThreat detection/endpoint security Security teams are still catching malware. The question is, what are they not catching? Currently, there are an increasing number of attacks that do not arrive as files. It does not drop binaries. Traditional alerts are not triggered. Instead, it runs silently through tools already present in your environment, […]
n8n warns of CVSS 10.0 RCE vulnerability affecting self-hosted and cloud versions

January 7, 2026Rabi LakshmananVulnerability / Cloud Security Open source workflow automation platform n8n has warned of a maximum severity security flaw that, if successfully exploited, could lead to authenticated remote code execution (RCE). This vulnerability has been assigned CVE identifier CVE-2026-21877 and is rated 10.0 by the CVSS scoring system. “Under certain conditions, it may […]
The future of cybersecurity includes non-human employees

January 7, 2026hacker newsEnterprise security/artificial intelligence Non-human employees are becoming the future of cybersecurity, and businesses need to prepare accordingly. As organizations expand artificial intelligence (AI) and cloud automation, non-human identities (NHI) such as bots, AI agents, service accounts, and automation scripts are rapidly increasing. In fact, in ConductorOne’s 2025 Future of Identity Security report, […]
Veeam fixes critical RCE vulnerability in CVSS 9.0 for backup and replication

January 7, 2026Ravi LakshmananVulnerabilities / Enterprise Security Veeam has released a security update that addresses multiple flaws in its backup and replication software, including a “critical” issue that could lead to remote code execution (RCE). This vulnerability is tracked as CVE-2025-59470 and has a CVSS score of 9.0. “This vulnerability allows a backup or tape […]