Unmasking new TOAD attacks hidden in legitimate infrastructure

“Living off the land” has become a preferred tactic for threat actors in many attack scenarios. This time, an existing “innocuous” component is being used as part of a phishing campaign. By leveraging the reputation of trusted services like PayPal and Zoom, attackers can bypass traditional Secure Email Gateways (SEGs) that whitelist these domains. Recently, […]
Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Ravi LakshmananJanuary 28, 2026Network security/zero day Fortinet has begun releasing security updates to address critical flaws affecting FortiOS that are being exploited in the wild. The vulnerability, assigned CVE identifier CVE-2026-24858 (CVSS score: 9.4), is described as an authentication bypass related to FortiOS single sign-on (SSO). This flaw also affects FortiManager and FortiAnalyzer. The company […]
WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

Ravi LakshmananJanuary 27, 2026Mobile security/spyware Meta announced Tuesday that it is adding stricter account settings to WhatsApp to protect some users from advanced cyberattacks. This feature, similar to Lockdown Mode in Apple iOS and Advanced Protection in Android, is intended to protect individuals, such as journalists and public figures, from advanced spyware by trading some […]
Experts detect Pakistan-linked cyber attack targeting Indian government agencies

Ravi LakshmananJanuary 27, 2026Threat Intelligence/Cyber Espionage Indian government agencies have been targeted in two campaigns conducted by threat actors operating in Pakistan using previously undocumented trade channels. These campaigns were codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, identified in September 2025. “While these campaigns share some similarities with APT36, a Pakistan-linked advanced persistent […]
ClickFix attack spreads using fake CAPTCHAs, Microsoft Scripts, and trusted web services

Cybersecurity researchers have detailed a new campaign that combines ClickFix-style fake CAPTCHAs with signed Microsoft Application Virtualization (App-V) scripts to distribute an information stealer called Amatera. “Rather than directly invoking PowerShell, attackers use this script to control how execution begins, avoiding more common and easily recognized execution paths,” Blackpoint researchers Jack Patrick and Sam Decker […]
Prioritize, validate, and key results

hacker newsJanuary 27, 2026Attack surface management/cyber risk Cybersecurity teams want to go further than just considering threats and vulnerabilities in isolation. It’s not just about what could go wrong (vulnerabilities) and who could attack (threats), but also where they might intersect in a real-world environment to expose you to real exploitable risks. Which exposures really […]
Critical vulnerability in Grist-Core allows RCE attacks via spreadsheet formulas

Ravi LakshmananJanuary 27, 2026Vulnerability / Cloud Security A critical security flaw has been disclosed in Grist‑Core, an open source self-hosted version of the Grist relational spreadsheet database, that could allow remote code execution. This vulnerability is tracked as CVE-2026-24002 (CVSS score: 9.1) and codenamed “Cellbreak” by Cyera Research Labs. “A malicious formula could turn a […]
China-linked hackers will use PeckBirdy JavaScript C2 framework starting in 2023

Ravi LakshmananJanuary 27, 2026Web security/malware Cybersecurity researchers have discovered a JScript-based command and control (C2) framework called PeckBirdy. This framework has been used by Chinese-aligned APT actors to target multiple environments since 2023. According to Trend Micro, this flexible framework is being used against malicious activity targeting China’s gambling industry as well as government and […]
Microsoft Office Zero Day (CVE-2026-21509) – Emergency patch issued for active exploit

Ravi LakshmananJanuary 27, 2026Zero-day/vulnerabilities Microsoft on Monday issued an out-of-band security patch for a high-severity zero-day vulnerability in Microsoft Office that was exploited in the attack. This vulnerability is tracked as CVE-2026-21509 and has a CVSS score of 7.8 out of 10.0. This is described as a bypass of Microsoft Office security features. “Microsoft Office’s […]
Indian users targeted by tax phishing campaign distributing Blackmoon malware

Ravi LakshmananJanuary 26, 2026Cyber espionage/malware Cybersecurity researchers have discovered an ongoing campaign targeting users in India using multi-stage backdoors as part of a suspected cyber espionage campaign. According to the eSentire Threat Response Unit (TRU), this activity involves using phishing emails impersonating the Indian Income Tax Department to trick victims into downloading malicious archives, ultimately […]