Cisco fixes actively exploited zero-day CVE-2026-20045 in Unified CM and Webex

Rabi LakshmananJanuary 22, 2026Vulnerability/Zero-day Cisco has released a new patch to address what it describes as a “critical” security vulnerability affecting multiple unified communications (CM) products and Webex Calling dedicated instances. This vulnerability is actively being exploited in the wild as a zero-day attack. Vulnerability CVE-2026-20045 (CVSS score: 8.2) could allow an unauthenticated, remote attacker […]

North Korea’s ‘PurpleBravo’ campaign targets 3,136 IP addresses with fake job interviews

As many as 3,136 individual IP addresses have been identified associated with possible targets of the Contagious Interview campaign, which claims to include 20 potential victim organizations across the artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development sectors in Europe, South Asia, the Middle East, and Central America. This new discovery […]

Zoom and GitLab release security updates that fix RCE, DoS, and 2FA bypass flaws

Rabi LakshmananJanuary 21, 2026Vulnerability/Network Security Zoom and GitLab have released security updates that resolve a number of security vulnerabilities that could lead to a denial of service (DoS) or remote code execution. The most serious issue is a critical security flaw affecting the Zoom Node Multimedia Router (MMR) that could allow meeting participants to conduct […]

How smart MSSPs leverage AI to increase profits with half their staff

hacker newsJanuary 21, 2026Artificial intelligence/automation In 2026, all managed security providers will be challenged by the same problem. Clients who have too many alerts, too few analysts, and require “CISO-level protection” on small business budgets. truth? Most MSSPs are running harder, not smarter. And it’s breaking their limits. A quiet revolution is taking place there. […]

Exposure assessment platforms signal a shift in focus

Gartner® doesn’t create new categories lightly. Typically, new acronyms emerge only when it becomes mathematically impossible to complete an industry-wide “to-do list.” The introduction of the Exposure Assessment Platform (EAP) category therefore appears to be a formal acknowledgment that traditional vulnerability management (VM) is no longer a viable way to protect modern enterprises. The transition […]

Flaw in Chainlit AI framework allows data theft via file reading and SSRF bugs

Ravi LakshmananJanuary 21, 2026Vulnerability / Artificial Intelligence A security vulnerability has been discovered in the popular open source artificial intelligence (AI) framework Chainlit. This vulnerability could allow an attacker to steal sensitive data and potentially allow lateral movement within a susceptible organization. Zafran Security said the high-severity flaws, collectively referred to as ChainLeak, could be […]

VoidLink Linux malware framework built with AI assistance reaches 88,000 lines of code

A recently discovered sophisticated Linux malware framework known as VoidLink is believed to have been developed by a single person with the assistance of artificial intelligence (AI) models. This is due to new findings from Check Point Research, which identify operational security mistakes by the malware’s creators and shed light on the origin of the […]

LastPass warns of fake maintenance messages targeting users’ master passwords

Rabi LakshmananJanuary 21, 2026Email security/malware LastPass is warning users that a new phishing campaign is active that impersonates the password management service and aims to trick users into giving up their master passwords. The campaign, which began around January 19, 2026, sends phishing emails claiming upcoming maintenance and prompting you to create a local backup […]

CERT/CC warns that bug in binary parser could allow Node.js privileged code execution

Ravi LakshmananJanuary 21, 2026Open source/vulnerabilities A security vulnerability has been disclosed in the popular binary parser npm library that could be successfully exploited to execute arbitrary JavaScript. This vulnerability is tracked as CVE-2026-1245 (CVSS score: N/A) and affects all versions of the module prior to version 2.3.0, which resolves the issue. A patch for this […]

North Korea-linked hackers target developers through malicious VS Code projects

North Korean threat actors associated with the long-running Contagion Interview campaign have been observed using malicious Microsoft Visual Studio Code (VS Code) projects as decoys that provide backdoors to compromised endpoints. According to Jamf Threat Labs, the latest findings demonstrate the continued evolution of new tactics first discovered in December 2025. “This activity included the […]