Global Cyber Security News
Keep up to date with some of the latest news articles in the cyber security landscape, worldwide.
- Two High-Severity n8n Flaws Allow Authenticated Remote Code Executionby [email protected] (The Hacker News) on January 28, 2026 at 12:43 pm
Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution. The weaknesses, discovered by the JFrog Security Research team, are listed below - CVE-2026-1470 (CVSS score: 9.9) - An eval injection vulnerability that could allow an authenticated user to bypass the Expression
- From Triage to Threat Hunts: How AI Accelerates SecOpsby [email protected] (The Hacker News) on January 28, 2026 at 11:55 am
If you work in security operations, the concept of the AI SOC agent is likely familiar. Early narratives promised total autonomy. Vendors seized on the idea of the "Autonomous SOC" and suggested a future where algorithms replaced analysts. That future has not arrived. We have not seen mass layoffs or empty security operations centers. We have instead seen the emergence of a practical reality.
- Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacksby [email protected] (The Hacker News) on January 28, 2026 at 11:40 am
Threat actors with ties to China have been observed using an updated version of a backdoor called COOLCLIENT in cyber espionage attacks in 2025 to facilitate comprehensive data theft from infected endpoints. The activity has been attributed to Mustang Panda (aka Earth Preta, Fireant, HoneyMyte, Polaris, and Twill Typhoon) with the intrusions primarily directed against government entities located
- Password Reuse in Disguise: An Often-Missed Risky Workaroundby [email protected] (The Hacker News) on January 28, 2026 at 10:30 am
When security teams discuss credential-related risk, the focus typically falls on threats such as phishing, malware, or ransomware. These attack methods continue to evolve and rightly command attention. However, one of the most persistent and underestimated risks to organizational security remains far more ordinary. Near-identical password reuse continues to slip past security controls, often
- Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088by [email protected] (The Hacker News) on January 28, 2026 at 9:46 am
Google on Tuesday revealed that multiple threat actors, including nation-state adversaries and financially motivated groups, are exploiting a now-patched critical security flaw in RARLAB WinRAR to establish initial access and deploy a diverse array of payloads. "Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated
- Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojanby [email protected] (The Hacker News) on January 28, 2026 at 9:30 am
Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that masquerade as spellcheckers but contain functionality to deliver a remote access trojan (RAT). The packages, named spellcheckerpy and spellcheckpy, are no longer available on PyPI, but not before they were collectively downloaded a little over 1,000 times. "Hidden inside the Basque
- Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detectedby [email protected] (The Hacker News) on January 28, 2026 at 4:49 am
Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-24858 (CVSS score: 9.4), has been described as an authentication bypass related to FortiOS single sign-on (SSO). The flaw also affects FortiManager and FortiAnalyzer. The company said it's
- WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spywareby [email protected] (The Hacker News) on January 27, 2026 at 4:54 pm
Meta on Tuesday announced it's adding Strict Account Settings on WhatsApp to secure certain users against advanced cyber attacks because of who they are and what they do. The feature, similar to Lockdown Mode in Apple iOS and Advanced Protection in Android, aims to protect individuals, such as journalists or public-facing figures, from sophisticated spyware by trading some functionality for
- Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entitiesby [email protected] (The Hacker News) on January 27, 2026 at 4:45 pm
Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft. The campaigns have been codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, which identified them in September 2025. "While these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT)
- ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Servicesby [email protected] (The Hacker News) on January 27, 2026 at 2:38 pm
Cybersecurity researchers have disclosed details of a new campaign that combines ClickFix-style fake CAPTCHAs with a signed Microsoft Application Virtualization (App-V) script to distribute an information stealer called Amatera. "Instead of launching PowerShell directly, the attacker uses this script to control how execution begins and to avoid more common, easily recognized execution paths,"
- CTEM in Practice: Prioritization, Validation, and Outcomes That Matterby [email protected] (The Hacker News) on January 27, 2026 at 11:50 am
Cybersecurity teams increasingly want to move beyond looking at threats and vulnerabilities in isolation. It’s not only about what could go wrong (vulnerabilities) or who might attack (threats), but where they intersect in your actual environment to create real, exploitable exposure. Which exposures truly matter? Can attackers exploit them? Are our defenses effective? Continuous Threat Exposure
- Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active Exploitationby [email protected] (The Hacker News) on January 27, 2026 at 10:37 am
Microsoft on Monday issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability exploited in attacks. The vulnerability, tracked as CVE-2026-21509, carries a CVSS score of 7.8 out of 10.0. It has been described as a security feature bypass in Microsoft Office. "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized
- Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulasby [email protected] (The Hacker News) on January 27, 2026 at 10:36 am
A critical security flaw has been disclosed in Grist‑Core, an open-source, self-hosted version of the Grist relational spreadsheet-database, that could result in remote code execution. The vulnerability, tracked as CVE-2026-24002 (CVSS score: 9.1), has been codenamed Cellbreak by Cyera Research Labs. "One malicious formula can turn a spreadsheet into a Remote Code Execution (RCE) beachhead,"
- China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023by [email protected] (The Hacker News) on January 27, 2026 at 9:01 am
Cybersecurity researchers have discovered a JScript-based command-and-control (C2) framework called PeckBirdy that has been put to use by China-aligned APT actors since 2023 to target multiple environments. The flexible framework has been put to use against Chinese gambling industries and malicious activities targeting Asian government entities and private organizations, according to Trend Micro
- Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malwareby [email protected] (The Hacker News) on January 26, 2026 at 5:01 pm
Cybersecurity researchers have discovered an ongoing campaign that's targeting Indian users with a multi-stage backdoor as part of a suspected cyber espionage campaign. The activity, per the eSentire Threat Response Unit (TRU), involves using phishing emails impersonating the Income Tax Department of India to trick victims into downloading a malicious archive, ultimately granting the threat
- Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Codeby [email protected] (The Hacker News) on January 26, 2026 at 3:43 pm
Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also harbor covert functionality to siphon developer data to China-based servers. The extensions, which have 1.5 million combined installs and are still available for download from the official Visual Studio
- ⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & Moreby [email protected] (The Hacker News) on January 26, 2026 at 11:55 am
Security failures rarely arrive loudly. They slip in through trusted tools, half-fixed problems, and habits people stop questioning. This week’s recap shows that pattern clearly. Attackers are moving faster than defenses, mixing old tricks with new paths. “Patched” no longer means safe, and every day, software keeps becoming the entry point. What follows is a set of small but telling signals.
- Winning Against AI-Based Attacks Requires a Combined Defensive Approachby [email protected] (The Hacker News) on January 26, 2026 at 11:30 am
If there’s a constant in cybersecurity, it’s that adversaries are always innovating. The rise of offensive AI is transforming attack strategies and making them harder to detect. Google’s Threat Intelligence Group, recently reported on adversaries using Large Language Models (LLMs) to both conceal code and generate malicious scripts on the fly, letting malware shape-shift in real-time to evade
- Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developersby [email protected] (The Hacker News) on January 26, 2026 at 8:54 am
The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target developers and engineering teams in the blockchain sector. The phishing campaign has targeted Japan, Australia, and India, highlighting the adversary's expansion of the targeting scope beyond South Korea, Russia, Ukraine, and European nations, Check
- Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomwareby [email protected] (The Hacker News) on January 24, 2026 at 11:09 am
A new multi-stage phishing campaign has been observed targeting users in Russia with ransomware and a remote access trojan called Amnesia RAT. "The attack begins with social engineering lures delivered via business-themed documents crafted to appear routine and benign," Fortinet FortiGuard Labs researcher Cara Lin said in a technical breakdown published this week. "These documents and



















