Microsoft begins phasing out NTLM with three-phase plan to migrate Windows to Kerberos

Ravi LakshmananFebruary 2, 2026Kerberos / Enterprise Security Microsoft has announced a three-phase approach to phasing out New Technology LAN Manager (NTLM) as part of its efforts to migrate Windows environments to more powerful Kerberos-based options. The development comes more than two years after the tech giant revealed plans to retire its legacy technology due to […]
Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats

Ravie LakshmananFeb 02, 2026Hacking News / Cybersecurity Every week brings new discoveries, attacks, and defenses that shape the state of cybersecurity. Some threats are stopped quickly, while others go unseen until they cause real damage. Sometimes a single update, exploit, or mistake changes how we think about risk and protection. Every incident shows how defenders […]
Protecting the middle market throughout the threat lifecycle

hacker newsFebruary 2, 2026Threat detection/endpoint security For mid-market organizations, cybersecurity is always a balancing act. Proactive and proactive security measures are essential to protect against the growing attack surface. Combined with effective threat-blocking protection, it plays a key role in stopping cyber-attacks before they cause damage. The challenge is that many security tools add complexity […]
Notepad++ official update mechanism is hijacked and malware is distributed to specific users

Ravi LakshmananFebruary 2, 2026Threat Intelligence/Malware Administrators of Notepad++ have revealed that state-sponsored attackers have hijacked the utility’s update mechanism and instead redirected update traffic to a malicious server. “This attack [an] “This resulted in an infrastructure-level compromise that allowed a malicious attacker to intercept and redirect update traffic destined for notepad-plus-plus.org. This compromise occurred at […]
eScan antivirus update server compromised and delivers multi-stage malware

The update infrastructure for eScan antivirus, a security solution developed by Indian cybersecurity company MicroWorld Technologies, was compromised by an unknown attacker and a persistent downloader was distributed to business and consumer systems. “The malicious update was distributed through eScan’s legitimate update infrastructure, resulting in multi-stage malware being deployed to business and consumer endpoints around […]
Open VSX supply chain attack uses compromised development accounts to spread GlassWorm

Ravi LakshmananFebruary 2, 2026Developer tools/malware Cybersecurity researchers have revealed details of a supply chain attack targeting the Open VSX registry. In this attack, an unknown attacker compromised legitimate developer resources and pushed malicious updates to downstream users. “On January 30, 2026, four established Open VSX extensions published by the oorzc author had malicious versions published […]
Iran-linked RedKitten cyber campaign targets human rights NGOs and activists

Farsi-speaking attackers aligned with Iran’s national interests are suspected of being behind a new campaign targeting non-governmental organizations and individuals involved in a recent record of human rights abuses. This activity, observed by HarfangLab in January 2026, is codenamed RedKitten. This is said to coincide with unrest that began across Iran towards the end of […]
Mandiant discovers ShinyHunters-style Vishing attack that steals MFA and compromises SaaS platforms

Ravi LakshmananJanuary 31, 2026Social Engineering/SaaS Security Mandiant, a Google company, said Friday that it has seen “expanded threat activity” using tradecraft consistent with extortion-themed attacks organized by a group of financially motivated hackers known as Shiny Hunters. This attack utilizes sophisticated voice phishing (also known as vishing) and a fake credential aggregator site that imitates […]
CERT Polska details coordinated cyberattacks on over 30 wind and solar farms

Ravi LakshmananJanuary 31, 2026Network security/SCADA CERT Polska, Poland’s computer emergency response team, has uncovered a coordinated cyberattack targeting more than 30 wind and solar power plants, private companies in the manufacturing industry, and large combined heat and power plants (CHPs) that provide heat to almost 500,000 customers in the country. This incident occurred on December […]
Researchers discover Chrome extension that exploits affiliate links to steal ChatGPT access

Cybersecurity researchers have discovered a malicious Google Chrome extension with the ability to hijack affiliate links, steal data, and collect OpenAI ChatGPT authentication tokens. One of the extensions in question is Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj), which claims to be a tool for browsing Amazon without sponsored content. It was uploaded to the Chrome Web […]