Learn how AI-powered Zero Trust detects attacks without files or indicators

January 7, 2026hacker newsThreat detection/endpoint security Security teams are still catching malware. The question is, what are they not catching? Currently, there are an increasing number of attacks that do not arrive as files. It does not drop binaries. Traditional alerts are not triggered. Instead, it runs silently through tools already present in your environment, […]
n8n warns of CVSS 10.0 RCE vulnerability affecting self-hosted and cloud versions

January 7, 2026Rabi LakshmananVulnerability / Cloud Security Open source workflow automation platform n8n has warned of a maximum severity security flaw that, if successfully exploited, could lead to authenticated remote code execution (RCE). This vulnerability has been assigned CVE identifier CVE-2026-21877 and is rated 10.0 by the CVSS scoring system. “Under certain conditions, it may […]
The future of cybersecurity includes non-human employees

January 7, 2026hacker newsEnterprise security/artificial intelligence Non-human employees are becoming the future of cybersecurity, and businesses need to prepare accordingly. As organizations expand artificial intelligence (AI) and cloud automation, non-human identities (NHI) such as bots, AI agents, service accounts, and automation scripts are rapidly increasing. In fact, in ConductorOne’s 2025 Future of Identity Security report, […]
Veeam fixes critical RCE vulnerability in CVSS 9.0 for backup and replication

January 7, 2026Ravi LakshmananVulnerabilities / Enterprise Security Veeam has released a security update that addresses multiple flaws in its backup and replication software, including a “critical” issue that could lead to remote code execution (RCE). This vulnerability is tracked as CVE-2025-59470 and has a CVSS score of 9.0. “This vulnerability allows a backup or tape […]
Microsoft warns that incorrect email routing settings can allow internal domain phishing

January 7, 2026Ravi LakshmananEmail Security/Financial Fraud Phishing attackers exploit routing scenarios and misconfigured spoofing protections to impersonate an organization’s domain and distribute emails that appear to be sent internally. “Threat actors are leveraging this vector to deliver a variety of phishing messages related to various phishing-as-a-service (PhaaS) platforms, such as Tycoon 2FA,” the Microsoft Threat […]
Ongoing attack exploits critical RCE vulnerability in legacy D-Link DSL routers

January 7, 2026Ravi LakshmananNetwork security/vulnerabilities A newly discovered critical security flaw in legacy D-Link DSL gateway routers is being exploited in the wild. The vulnerability, tracked as CVE-2026-0625 (CVSS score: 9.3), involves a case of command injection into the ‘dnscfg.cgi’ endpoint due to improper sanitization of user-specified DNS configuration parameters. “An unauthenticated, remote attacker may […]
Two Chrome extensions found to be stealing ChatGPT and DeepSeek chats from 900,000 users

Cybersecurity researchers have discovered two new malicious extensions in the Chrome Web Store designed to leak OpenAI ChatGPT and DeepSeek conversations along with browsing data to servers under attacker control. Extensions with over 900,000 total users are named below. Chat GPT with GPT-5, Claude Sonnet, DeepSeek AI for Chrome (ID: fnmihdojmnkclgjpcoonokmkhjpjechg, 600,000 users) AI sidebar […]
Unpatched firmware flaw leaves TOTOLINK EX200 open to full remote device takeover

January 6, 2026Ravi LakshmananIoT security/vulnerabilities The CERT Coordination Center (CERT/CC) has detailed an unpatched security flaw affecting the TOTOLINK EX200 Wireless Range Extender. This flaw could allow a remote authenticated attacker to gain complete control of the device. This flaw, CVE-2025-65606 (CVSS score: N/A), is characterized as a flaw in the firmware upload error handling […]
Fake reservation email redirects hotel staff to fake BSoD page delivering DCRat

January 6, 2026Ravi LakshmananMalware/Endpoint Security Source: Securonics Cybersecurity researchers have revealed details of a new campaign called PHALT#BLYX that leverages ClickFix-style lures to display fake Blue Screen of Death (BSoD) error fixes in attacks targeting European hospitality businesses. According to cybersecurity firm Securonix, the end goal of the multi-stage campaign is to deliver a remote […]
What is identity dark matter?

January 6, 2026hacker newsSaaS Security / Enterprise Security The invisible half of the identity universe Identity existed in one place, such as an LDAP directory, HR system, or a single IAM portal. No more. Today, identities are fragmented across SaaS, on-premises, IaaS, PaaS, homegrown, and shadow applications. Each of these environments has its own accounts, […]