Three flaws in Anthropic MCP Git server allow file access and code execution

Rabi LakshmananJanuary 20, 2026Vulnerability / Artificial Intelligence A series of three security vulnerabilities have been disclosed in mcp-server-git, the official Git Model Context Protocol (MCP) server maintained by Anthropic. This can be exploited to read or delete arbitrary files and execute code under certain conditions. “These flaws can be exploited through prompt injection, meaning that […]

Hackers use LinkedIn messages to spread RAT malware through DLL sideloading

Ravi LakshmananJanuary 20, 2026Malware/Threat Intelligence Cybersecurity researchers have discovered a new phishing campaign that exploits private social media messages to propagate malicious payloads. This is likely intended to deploy a remote access trojan (RAT). ReliaQuest said in a report shared with The Hacker News that the activity delivers “weaponized files via dynamic link library (DLL) […]

The hidden risks of orphaned accounts

hacker newsJanuary 20, 2026Enterprise Security / AI Security The problem: residual identity As organizations grow and evolve, employees, contractors, services, and systems come and go, but often those accounts remain. These abandoned or “orphaned” accounts lie dormant across applications, platforms, assets, and cloud consoles. They persist not because of neglect but because of fragmentation. Traditional […]

Evelyn Stealer malware exploits VS Code extension to steal developer credentials and cryptography

Ravi LakshmananJanuary 20, 2026Cloud security / developer security Cybersecurity researchers have revealed details of a malware campaign that targets software developers with a new information theft tool called Evelyn Stealer, armed with the Microsoft Visual Studio Code (VS Code) extension ecosystem. “This malware is designed to exfiltrate sensitive information such as developer credentials and cryptocurrency-related […]

Cloudflare fixes ACME validation bug, allows WAF bypass to origin server

Rabi LakshmananJanuary 20, 2026Web security/vulnerabilities Cloudflare has addressed a security vulnerability that affects Automated Certificate Management Environment (ACME) validation logic and allows access to origin servers by bypassing security controls. “The vulnerability was due to the way our edge network handled requests addressed to the ACME HTTP-01 challenge path (/.well-known/acme-challenge/*),” said Hrushikesh Deshpande, Andrew Mitchell, […]

Why the secret of JavaScript bundles is still overlooked

API key leaks are no longer uncommon, and so are subsequent breaches. So why are sensitive tokens still so easily exposed? To find out, Intruder’s research team investigated what traditional vulnerability scanners actually cover and built a new secret detection method to address gaps in existing approaches. Applying this at scale by scanning 5 million […]

Tudou Guaranteed Marketplace Stops Telegram Trading After Processing Over $12 Billion

Ravi LakshmananJanuary 20, 2026Cryptocurrency/Artificial Intelligence A Telegram-based guarantee marketplace known for promoting a wide range of illegal services appears to be winding down its operations, according to new research from Elliptic. Blockchain intelligence company Tudou Warranty said it has effectively ceased trading through its public Telegram group after a period of significant growth. The market […]

Google Gemini Prompt Injection Flaw Exposes Private Calendar Data via Malicious Invites

Cybersecurity researchers have detailed a security flaw that leverages indirect prompted injection targeting Google Gemini as a way to bypass authorization guardrails and use Google Calendar as a data extraction mechanism. According to Liad Eliyahu, head of research at Miggo Security, the vulnerability allowed an attacker to bypass Google Calendar’s privacy controls by hiding a […]

Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More

Ravie LakshmananJan 19, 2026Hacking News / Cybersecurity In cybersecurity, the line between a normal update and a serious incident keeps getting thinner. Systems that once felt reliable are now under pressure from constant change. New AI tools, connected devices, and automated systems quietly create more ways in, often faster than security teams can react. This […]

The High (and Hidden) Costs for Cloud-First Businesses

Just a few years ago, the cloud was touted as the “magic pill” for any cyber threat or performance issue. Many were lured by the “always-on” dream, trading granular control for the convenience of managed services. In recent years, many of us have learned (often the hard way) that public cloud service providers are not […]