New StackWarp hardware flaw breaks AMD SEV-SNP protection for Zen 1-5 CPUs

Ravi LakshmananJanuary 19, 2026Hardware security/vulnerabilities A team of academics from Germany’s CISPA Helmholtz Center for Information Security has revealed details of a new hardware vulnerability affecting AMD processors. The security flaw, codenamed StackWarp, could allow a malicious attacker with privileged control over a host server to execute malicious code within a Confidential Virtual Machine (CVM), […]

CrashFix Chrome extension serves ModeloRAT using ClickFix-style browser crash lures

Cybersecurity researchers have revealed details of an ongoing campaign called KongTuke that uses a malicious Google Chrome extension masquerading as an ad blocker to intentionally crash web browsers, uses ClickFix-like lures to trick victims into executing arbitrary commands, and delivers a previously undocumented remote access Trojan (RAT) called ModeloRAT. This new escalation of ClickFix is […]

Security bug in StealC malware panel allows researchers to monitor threat actor operations

Ravi LakshmananJanuary 19, 2026Malware/Threat Intelligence Cybersecurity researchers have revealed a cross-site scripting (XSS) vulnerability in the web-based control panel used by StealC information stealer operators. This allows us to gather important insights into one of the attackers who use the malware in production. “By exploiting this, they were able to collect system fingerprints, monitor active […]

CISO guide to AI security investments

AI is reshaping the enterprise landscape, and security budgets are struggling to keep up. As organizations rush to adopt AI, security teams face increasing pressure to protect these systems without clear guidance on where to invest their limited resources. The challenge is not just to protect AI, but to do so strategically. CISOs are faced […]

Black Basta ransomware leader added to EU’s Most Wanted and INTERPOL Red Notices

Ravi LakshmananJanuary 17, 2026Law enforcement/cybercrime Law enforcement authorities in Ukraine and Germany have identified two Ukrainian nationals suspected of working for the Russia-linked ransomware-as-a-service (RaaS) group Black Basta. Additionally, authorities noted that the group’s alleged leader, 35-year-old Russian Oleg Evgenievich Nefedov (Нефедов Олег Евгеньевич), has been added to the European Union’s Most Wanted List and […]

OpenAI shows ads on ChatGPT to logged in US adults on Free and Go plans

January 17, 2026Ravi LakshmananArtificial intelligence/data privacy OpenAI announced Friday that it will begin showing ads on ChatGPT to U.S. adult users who are logged in on both the free and ChatGPT Go tiers in the coming weeks, as the artificial intelligence (AI) company expands access to low-cost subscriptions globally. “People should know that their data […]

GootLoader malware uses 500 to 1,000 concatenated ZIP archives to evade detection

January 16, 2026Ravi LakshmananMalvertising/Threat Intelligence A JavaScript (also known as JScript) malware loader called GootLoader has been observed using malicious ZIP archives designed to evade detection efforts by concatenating 500 to 1,000 archives. “Adversaries are creating fraudulent archives as an anti-analysis technique,” Aaron Walton, a security researcher at Expel, said in a report shared with […]

Five malicious Chrome extensions impersonate Workday and NetSuite to take over accounts

Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that impersonate human resources (HR) and enterprise resource planning (ERP) platforms such as Workday, NetSuite, and SuccessFactors to take control of victims’ accounts. “The extensions work together to steal authentication tokens, block incident response functionality, and enable complete account takeover through session hijacking,” […]

Your digital footprint can end right at your doorstep

January 16, 2026hacker newsPrivacy/Data Protection Lock the door at night. You avoid sketchy calls. You are careful about what you post on social media. But what happens to the information about you that has already been published without your permission? your name. home address. telephone number. past work. Dear family. Old username. Everything is still […]

LOTUSLITE backdoor targets US policy agencies using Venezuela-themed spear phishing

January 16, 2026Ravi LakshmananMalware/Cyber ​​Espionage Security experts have revealed details of a new campaign targeting U.S. government and policy actors using politically-themed decoys to deliver a backdoor known as LOTUSLITE. The targeted malware campaign utilizes decoys related to recent geopolitical developments between the United States and Venezuela to distribute a ZIP archive (“US deciding what’s […]