Malicious VS Code AI extension installed 1.5 million times steals developer source code

Ravi LakshmananJanuary 26, 2026AI security/vulnerabilities Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also have secret capabilities that siphon developer data to servers based in China. These extensions have been installed a total of 1.5 million times and are still […]
Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More

Ravie LakshmananJan 26, 2026Hacking News / Cybersecurity Security failures rarely arrive loudly. They slip in through trusted tools, half-fixed problems, and habits people stop questioning. This week’s recap shows that pattern clearly. Attackers are moving faster than defenses, mixing old tricks with new paths. “Patched” no longer means safe, and every day, software keeps becoming […]
Winning against AI-based attacks requires a combined defensive approach

hacker newsJanuary 26, 2026Endpoint security/artificial intelligence If there’s one constant in cybersecurity, it’s that adversaries are constantly innovating. The rise of aggressive AI is changing attack strategies and making attacks harder to detect. Google’s Threat Intelligence Group recently reported that attackers are using large language models (LLMs) to hide code, generate malicious scripts on the […]
Konni hacker deploys AI-generated PowerShell backdoor against blockchain developers

Ravi LakshmananJanuary 26, 2026Malware/Endpoint Security A North Korean threat actor known as Konni has been observed targeting developers and engineering teams in the blockchain space using PowerShell malware generated using artificial intelligence (AI) tools. Check Point Research said in a technical report released last week that the phishing campaign targeted Japan, Australia and India, highlighting […]
Multi-stage phishing campaign targeting Russia with Amnesia RAT and ransomware

A new multi-stage phishing campaign was observed targeting users in Russia using ransomware and a remote access Trojan called Amnesia RAT. “This attack begins with a social engineering lure delivered via business-themed documents designed to appear routine and harmless,” Fortinet FortiGuard Labs researcher Cara Lin said in technical details released this week. “These documents and […]
New DynoWiper malware used in attempted sandworm attack on Poland’s power sector

Ravi LakshmananJanuary 24, 2026Malware/Critical Infrastructure The Russian state hacking group known as Sandworm is said to have been behind what was described as the “largest cyber attack” targeting Poland’s electricity system in the last week of December 2025. The country’s Energy Minister Milos Motyka said last week that the attack had failed. “The Cyberspace Command […]
Who authorized this agent? Rethinking access, accountability, and risk in the age of AI agents

AI agents are accelerating the way we get work done. Schedule meetings, access data, trigger workflows, write code, and take actions in real-time to boost productivity beyond human speed across your enterprise. And there comes a moment when all security teams are finally faced with the following question: “Wait… who approved this?” Unlike users and […]
CISA adds actively exploited VMware vCenter flaw CVE-2024-37079 to KEV catalog

Ravi LakshmananJanuary 24, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting Broadcom VMware vCenter Server patched in June 2024 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of real-world exploitation. The vulnerability in question is CVE-2024-37079 (CVSS score: 9.8). This refers to […]
CISA updates KEV catalog to fix four actively exploited software vulnerabilities

Rabi LakshmananJanuary 23, 2026Vulnerabilities/Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of them being exploited in the wild. Here is the list of vulnerabilities: CVE-2025-68645 (CVSS score: 8.8) – PHP remote file include vulnerability in Synacor Zimbra Collaboration […]
Fortinet Verifies Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls

Rabi LakshmananJanuary 23, 2026Network security/vulnerabilities Fortinet has officially confirmed that it is working to fully resolve the FortiCloud SSO authentication bypass vulnerability following reports of new exploit activity on fully patched firewalls. “Over the past 24 hours, we have identified a number of cases in which devices were fully upgraded to the latest release at […]