Microsoft warns that incorrect email routing settings can allow internal domain phishing

January 7, 2026Ravi LakshmananEmail Security/Financial Fraud Phishing attackers exploit routing scenarios and misconfigured spoofing protections to impersonate an organization’s domain and distribute emails that appear to be sent internally. “Threat actors are leveraging this vector to deliver a variety of phishing messages related to various phishing-as-a-service (PhaaS) platforms, such as Tycoon 2FA,” the Microsoft Threat […]

Ongoing attack exploits critical RCE vulnerability in legacy D-Link DSL routers

January 7, 2026Ravi LakshmananNetwork security/vulnerabilities A newly discovered critical security flaw in legacy D-Link DSL gateway routers is being exploited in the wild. The vulnerability, tracked as CVE-2026-0625 (CVSS score: 9.3), involves a case of command injection into the ‘dnscfg.cgi’ endpoint due to improper sanitization of user-specified DNS configuration parameters. “An unauthenticated, remote attacker may […]

Two Chrome extensions found to be stealing ChatGPT and DeepSeek chats from 900,000 users

Cybersecurity researchers have discovered two new malicious extensions in the Chrome Web Store designed to leak OpenAI ChatGPT and DeepSeek conversations along with browsing data to servers under attacker control. Extensions with over 900,000 total users are named below. Chat GPT with GPT-5, Claude Sonnet, DeepSeek AI for Chrome (ID: fnmihdojmnkclgjpcoonokmkhjpjechg, 600,000 users) AI sidebar […]

Unpatched firmware flaw leaves TOTOLINK EX200 open to full remote device takeover

January 6, 2026Ravi LakshmananIoT security/vulnerabilities The CERT Coordination Center (CERT/CC) has detailed an unpatched security flaw affecting the TOTOLINK EX200 Wireless Range Extender. This flaw could allow a remote authenticated attacker to gain complete control of the device. This flaw, CVE-2025-65606 (CVSS score: N/A), is characterized as a flaw in the firmware upload error handling […]

Fake reservation email redirects hotel staff to fake BSoD page delivering DCRat

January 6, 2026Ravi LakshmananMalware/Endpoint Security Source: Securonics Cybersecurity researchers have revealed details of a new campaign called PHALT#BLYX that leverages ClickFix-style lures to display fake Blue Screen of Death (BSoD) error fixes in attacks targeting European hospitality businesses. According to cybersecurity firm Securonix, the end goal of the multi-stage campaign is to deliver a remote […]

What is identity dark matter?

January 6, 2026hacker newsSaaS Security / Enterprise Security The invisible half of the identity universe Identity existed in one place, such as an LDAP directory, HR system, or a single IAM portal. No more. Today, identities are fragmented across SaaS, on-premises, IaaS, PaaS, homegrown, and shadow applications. Each of these environments has its own accounts, […]

VS Code forks recommend missing extensions and pose supply chain risks with Open VSX

January 6, 2026Ravi LakshmananThreat Intelligence/Cloud Security Popular artificial intelligence (AI)-powered Microsoft Visual Studio Code (VS Code) forks such as Cursor, Windsurf, Google Antigravity, and Trae have been found to promote extensions that are not present in the Open VSX registry, potentially opening the door to supply chain risk if bad actors publish malicious packages with […]

New n8n vulnerability (9.9 CVSS) allows authenticated users to execute system commands

January 6, 2026Ravi LakshmananVulnerabilities / DevOps A critical new security vulnerability has been disclosed in n8n, an open source workflow automation platform, that could allow an authenticated attacker to execute arbitrary system commands on the underlying host. This vulnerability is tracked as CVE-2025-68668 and is rated 9.9 on the CVSS scoring system. This is described […]

Critical flaw in AdonisJS Bodyparser (CVSS 9.2) allows arbitrary file writing on the server

January 6, 2026Ravi LakshmananVulnerabilities / Web Security Users of the ‘@adonisjs/bodyparser’ npm package are advised to update to the latest version following disclosure of a critical security vulnerability that, if successfully exploited, could allow a remote attacker to write arbitrary files on the server. This flaw is tracked as CVE-2026-21440 (CVSS score: 9.2) and is […]

Russian-aligned hackers exploit Viber to target Ukraine’s military and government

January 5, 2026Ravi LakshmananCyber ​​Spy / Windows Security A Russian-aligned attacker known as UAC-0184 has been observed leveraging the Viber messaging platform to distribute malicious ZIP archives and target military and government agencies in Ukraine. “The organization will continue its high-intensity intelligence-gathering operations against the Ukrainian military and government sectors in 2025,” the 360 ​​Threat […]