π°π΅ North Koreaβlinked actors are luring developers with fake job repos.
Simply opening a malicious VS Code project can auto-run hidden tasks that fetch JavaScript from Vercel and deploy a backdoor enabling remote code execution.
π Learn how it works β https://thehackernews.com/2026/01/north-korea-linked-hackers-target.html
Simply opening a malicious VS Code project can auto-run hidden tasks that fetch JavaScript from Vercel and deploy a backdoor enabling remote code execution.
π Learn how it works β https://thehackernews.com/2026/01/north-korea-linked-hackers-target.html
π₯12π8π7
π¨ npm binary-parser flaw enables arbitrary JavaScript execution in some Node.js apps.
Affects versions < 2.3.0 and only hits apps that build parsers from untrusted input via dynamic code generation.
π Exploit path explained β https://thehackernews.com/2026/01/certcc-warns-binary-parser-bug-allows.html
Affects versions < 2.3.0 and only hits apps that build parsers from untrusted input via dynamic code generation.
π Exploit path explained β https://thehackernews.com/2026/01/certcc-warns-binary-parser-bug-allows.html
π8π3
π¨ LastPass is warning users about an active phishing campaign.
Fake βmaintenanceβ emails create 24-hour urgency and redirect victims to spoofed LastPass sites designed to steal master passwords.
π How the scam works and how to spot it β https://thehackernews.com/2026/01/lastpass-warns-of-fake-maintenance.html
Fake βmaintenanceβ emails create 24-hour urgency and redirect victims to spoofed LastPass sites designed to steal master passwords.
π How the scam works and how to spot it β https://thehackernews.com/2026/01/lastpass-warns-of-fake-maintenance.html
π10
π Containers now power core production systems, but security is lagging behind.
ActiveState data shows 82% of orgs suffered a container breach last yearβand many leaders now treat incidents as expected, not preventable.
π Why container security is becoming βinevitableβ β https://thehackernews.com/expert-insights/2026/01/the-great-container-disconnect-security.html
ActiveState data shows 82% of orgs suffered a container breach last yearβand many leaders now treat incidents as expected, not preventable.
π Why container security is becoming βinevitableβ β https://thehackernews.com/expert-insights/2026/01/the-great-container-disconnect-security.html
π5
π€β οΈ One developer. 88,000+ lines of code.
Researchers say an advanced Linux malware framework was built in weeks with AI help, guided by a single skilled developer using an AI agentβresetting expectations for what one actor can build.
π Read β https://thehackernews.com/2026/01/voidlink-linux-malware-framework-built.html
Researchers say an advanced Linux malware framework was built in weeks with AI help, guided by a single skilled developer using an AI agentβresetting expectations for what one actor can build.
π Read β https://thehackernews.com/2026/01/voidlink-linux-malware-framework-built.html
π₯12π±4π2
π¨ Security researchers found two high-severity flaws in Chainlit, an open-source AI chatbot framework.
The bugs enable file reads and SSRF, exposing API keys and internal data and enabling lateral movement. Fixed in v2.9.4.
π Read β https://thehackernews.com/2026/01/chainlit-ai-framework-flaws-enable-data.html
The bugs enable file reads and SSRF, exposing API keys and internal data and enabling lateral movement. Fixed in v2.9.4.
π Read β https://thehackernews.com/2026/01/chainlit-ai-framework-flaws-enable-data.html
π8π4π₯4
π‘οΈ Security teams donβt fail by missing bugs. They fail by fixing the wrong ones.
Gartnerβs EAP category shifts focus from CVE volume to real attack paths across cloud and identity. Most alerts never reach critical assets. EAPs show what actually matters.
π Read β https://thehackernews.com/2026/01/exposure-assessment-platforms-signal.html
Gartnerβs EAP category shifts focus from CVE volume to real attack paths across cloud and identity. Most alerts never reach critical assets. EAPs show what actually matters.
π Read β https://thehackernews.com/2026/01/exposure-assessment-platforms-signal.html
π7
π RCE flaws found in widely used AI Python libraries.
Researchers report bugs in Apple FlexTok, NVIDIA NeMo, and Salesforce Uni2TS that trigger when malicious model metadata is loaded.
These tools power popular AI models. Patches are out, no active exploitation seen yet.
π Read β https://thehackernews.com/2026/01/threatsday-bulletin-ai-voice-cloning.html#rce-via-ai-libraries
Researchers report bugs in Apple FlexTok, NVIDIA NeMo, and Salesforce Uni2TS that trigger when malicious model metadata is loaded.
These tools power popular AI models. Patches are out, no active exploitation seen yet.
π Read β https://thehackernews.com/2026/01/threatsday-bulletin-ai-voice-cloning.html#rce-via-ai-libraries
π±7π₯5
Static pentest reports create unnecessary delays.
Todayβs security teams need real-time visibility, automated handoffs, and continuous workflows. Not PDFs that stall remediation.
This step-by-step guide explains how automation modernizes pentest delivery so findings move from discovery to remediation immediately.
Download the guide π https://thn.news/pentest-delivery-guide
Todayβs security teams need real-time visibility, automated handoffs, and continuous workflows. Not PDFs that stall remediation.
This step-by-step guide explains how automation modernizes pentest delivery so findings move from discovery to remediation immediately.
Download the guide π https://thn.news/pentest-delivery-guide
π6π5
π Webinar Alert! MSSPs arenβt losing in 2026 because theyβre small. Theyβre losing because delivery doesnβt scale.
This live webinar breaks down how AI removes manual assessments and reporting β so you can deliver CISO-level security without hiring more analysts.
See the exact operating model top MSSPs are using to protect margins.
π Save your seat before it fills β https://thehackernews.com/2026/01/webinar-how-smart-mssps-using-ai-to.html
This live webinar breaks down how AI removes manual assessments and reporting β so you can deliver CISO-level security without hiring more analysts.
See the exact operating model top MSSPs are using to protect margins.
π Save your seat before it fills β https://thehackernews.com/2026/01/webinar-how-smart-mssps-using-ai-to.html
π7π1
π¨ Zoom and GitLab shipped urgent security fixes.
β€ Zoom patched a critical RCE (CVSS 9.9) in Node MMRs that could let a meeting participant run code.
β€ GitLab fixed high-severity bugs enabling unauthenticated DoS and a 2FA bypass.
π Details on affected versions and patches β https://thehackernews.com/2026/01/zoom-and-gitlab-release-security.html
β€ Zoom patched a critical RCE (CVSS 9.9) in Node MMRs that could let a meeting participant run code.
β€ GitLab fixed high-severity bugs enabling unauthenticated DoS and a 2FA bypass.
π Details on affected versions and patches β https://thehackernews.com/2026/01/zoom-and-gitlab-release-security.html
π₯13π3
π§βπ» North Korean actors behind the Contagious Interview campaign targeted 3,136 IPs, researchers say.
The activity hit AI, crypto, finance, and software firms across Europe, Asia, and the Middle East.
πΌ Hiring processes were the entry point.
π Learn more β https://thehackernews.com/2026/01/north-korean-purplebravo-campaign.html
The activity hit AI, crypto, finance, and software firms across Europe, Asia, and the Middle East.
πΌ Hiring processes were the entry point.
π Learn more β https://thehackernews.com/2026/01/north-korean-purplebravo-campaign.html
π9π7
π¨ Cisco fixed an actively exploited zero-day in its voice and collaboration stack.
CVE-2026-20045 allows unauthenticated attackers to run commands and escalate to root on exposed Unified CM and Webex Calling systems.
πDetails β https://thehackernews.com/2026/01/cisco-fixes-actively-exploited-zero-day.html
CVE-2026-20045 allows unauthenticated attackers to run commands and escalate to root on exposed Unified CM and Webex Calling systems.
πDetails β https://thehackernews.com/2026/01/cisco-fixes-actively-exploited-zero-day.html
π₯9π€7π4π2β‘1
π¨ Fortinet FortiGate under automated SSO abuse.
Attackers exploit CVE-2025-59718/59719 to add admin users, enable VPN access, and export firewall configs within seconds, per Arctic Wolf.
π Learn whatβs happening and what to disable β https://thehackernews.com/2026/01/automated-fortigate-attacks-exploit.html
Attackers exploit CVE-2025-59718/59719 to add admin users, enable VPN access, and export firewall configs within seconds, per Arctic Wolf.
π Learn whatβs happening and what to disable β https://thehackernews.com/2026/01/automated-fortigate-attacks-exploit.html
π€8β‘5π4
Model Context Protocol (MCP) connects AI models directly to live enterprise systems.
One compromised MCP server can expose data, tokens, and APIs at scale.
Most existing security tools have little to no visibility into this layer.
π MCP risks and why they matter β https://thehackernews.com/expert-insights/2026/01/do-you-really-know-your-ai-landscape.html
One compromised MCP server can expose data, tokens, and APIs at scale.
Most existing security tools have little to no visibility into this layer.
π MCP risks and why they matter β https://thehackernews.com/expert-insights/2026/01/do-you-really-know-your-ai-landscape.html
π₯9β‘5π2
π¨ SmarterMail flaw is under active attack within 48 hours of patching.
The bug lets attackers bypass auth, reset the admin password, then abuse built-in admin features to run OS commands as SYSTEM.
Activity points to patch reverse-engineering.
π Details β https://thehackernews.com/2026/01/smartermail-auth-bypass-exploited-in.html
The bug lets attackers bypass auth, reset the admin password, then abuse built-in admin features to run OS commands as SYSTEM.
Activity points to patch reverse-engineering.
π Details β https://thehackernews.com/2026/01/smartermail-auth-bypass-exploited-in.html
π8π4π±3β‘1
π¨ Fake SymPy on PyPI is targeting Linux devs. The package sympy-dev clones the real project text, poses as a dev build, and has 1,100+ downloads since Jan 17.
It activates only when certain math functions run, then loads an XMRig miner fully in memory to avoid traces.
π Learn how the loader works β https://thehackernews.com/2026/01/malicious-pypi-package-impersonates.html
It activates only when certain math functions run, then loads an XMRig miner fully in memory to avoid traces.
π Learn how the loader works β https://thehackernews.com/2026/01/malicious-pypi-package-impersonates.html
π€―7β‘1
Learn cybersecurity risk management from the experts at Georgetown. Attend our webinar on TBD.
Sign up - https://thn.news/risk-mgmt-insight
Sign up - https://thn.news/risk-mgmt-insight
π6
β οΈπ§ Email is still the easiest way in.
In Google Workspace, BEC attacks often carry no links or malware, so native defenses miss them. One compromised inbox can expose years of sensitive email and files.
Hardening helps, but blind spots remain.
π Gmail limits, real attack paths β https://thehackernews.com/2026/01/filling-most-common-gaps-in-google.html
In Google Workspace, BEC attacks often carry no links or malware, so native defenses miss them. One compromised inbox can expose years of sensitive email and files.
Hardening helps, but blind spots remain.
π Gmail limits, real attack paths β https://thehackernews.com/2026/01/filling-most-common-gaps-in-google.html
π8
Behind every bar in this report is time won, money saved, or risk stopped.
@anyrun_app helps businesses boost DR by 36% & reduce MTTR by 21 minutes with better attack visibility for SOC & MSSP teams.
See how it can support your org in 2026 π https://thn.news/threat-intel-hub
@anyrun_app helps businesses boost DR by 36% & reduce MTTR by 21 minutes with better attack visibility for SOC & MSSP teams.
See how it can support your org in 2026 π https://thn.news/threat-intel-hub
π₯8