From MCP and tool access to shadow API key sprawl

January 13, 2026hacker newsArtificial Intelligence/Automation Security AI agents no longer just write code. they are doing it. With tools like Copilot, Claude Code, and Codex, you can now build, test, and deploy software end-to-end in minutes. This speed is reshaping engineering, but it’s also creating security gaps that most teams don’t realize until something breaks. […]
New advanced Linux VoidLink malware targets cloud and container environments

January 13, 2026Ravi LakshmananThreat Intelligence/Cyber Espionage Cybersecurity researchers have revealed details of a previously undocumented, feature-rich malware framework codenamed VoidLink that is specifically designed for long-term, stealthy access to Linux-based cloud environments. According to a new report from Check Point Research, cloud-native Linux malware frameworks consist of a set of custom loaders, implants, rootkits, and […]
What should we learn from how attackers leverage AI in 2025?

January 13, 2026hacker newsThreat Intelligence/Identity Security Old strategy, new scale: While defenders chase trends, attackers optimize fundamentals. The security industry loves to talk about “new” threats. Attacks using AI. Quantum-resistant encryption. Zero Trust Architecture. But if you look around, it seems like the most effective attacks in 2025 will be pretty much the same as […]
ServiceNow fixes critical AI platform flaw that allows unauthenticated user impersonation

January 13, 2026Ravi LakshmananVulnerabilities / SaaS Security ServiceNow has revealed details of a critical security flaw affecting the ServiceNow AI platform that is currently being patched. This flaw could allow an unauthenticated user to impersonate another user and perform arbitrary actions as that user. This vulnerability was tracked as CVE-2025-12420 and had a CVSS score […]
New malware campaign delivers Remcos RAT via multi-stage Windows attack

January 13, 2026Ravi LakshmananMalware/Endpoint Security Cybersecurity researchers have revealed details of a new campaign called “SHADOW#REACTOR.” The campaign utilizes an evasive multi-stage attack chain to distribute a commercially available remote administration tool called Remcos RAT to establish persistent and covert remote access. “The infection chain follows a tightly tailored execution path: an obfuscated VBS launcher […]
CISA warns that Gogs vulnerability that allows code execution is being actively exploited

January 13, 2026Ravi LakshmananVulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw affecting Gogs to its Known Exploited Vulnerabilities (KEV) catalog, warning that it can be actively exploited. This vulnerability is tracked as CVE-2025-8110 (CVSS score: 8.7) and is related to a path traversal case in the repository […]
n8n supply chain attack exploits community nodes to steal OAuth tokens

January 12, 2026Ravi LakshmananVulnerability/Workflow Automation Threat actors have been observed uploading a set of eight packages to the npm registry masquerading as integrations targeting the n8n workflow automation platform to steal developers’ OAuth credentials. One such package, named ‘n8n-nodes-hfgjf-irtuinvcm-lasdqewriit’, mimics the Google Ads integration, prompting users to link their ad accounts in a seemingly legitimate […]
AI Automation Exploits, Telecom Espionage, Prompt Poaching & More

Jan 12, 2026Ravie LakshmananHacking News / Cybersecurity This week made one thing clear: small oversights can spiral fast. Tools meant to save time and reduce friction turned into easy entry points once basic safeguards were ignored. Attackers didn’t need novel tricks. They used what was already exposed and moved in without resistance. Scale amplified the […]
GoBruteforcer botnet exploits weak credentials to target crypto project databases

A new wave of GoBruteforcer attacks targets the databases of cryptocurrencies and blockchain projects, putting them into botnets that can brute force user passwords for services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux servers. “The current wave of campaigns is being driven by two factors: the mass reuse of AI-generated server deployments that […]
Anthropic launches Claude AI for healthcare with secure medical record access

January 12, 2026Ravi LakshmananArtificial intelligence/healthcare Anthropic has become the latest artificial intelligence (AI) company to announce a new suite of features that will give users of its Claude platform a deeper understanding of their health information. Under an initiative called Claude for Healthcare, Claude Pro and Max plan subscribers in the U.S. can choose to […]