Categories Breaking News

Breaking News – Cyber Threats – 2026-01-28 07:00 PST

Breaking News – Cyber Threats (last 6h)

Generated: 2026-01-28 07:00 PST

  • SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws
    BleepingComputer • 2026-01-28 06:39 • www.bleepingcomputer.com
    SolarWinds has released security updates to patch critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk IT help desk software. […]
    https://www.bleepingcomputer.com/news/security/solarwinds-warns-of-critical-web-help-desk-rce-auth-bypass-flaws/
  • Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution
    The Hacker News • 2026-01-28 06:01 • thehackernews.com
    A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system.
    The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0 on the CVSS scoring system.
    “In vm2 for version 3.10.0, Promise.prototype.then Promise.prototype.catch
    https://thehackernews.com/2026/01/critical-vm2-nodejs-flaw-allows-sandbox.html
  • Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation
    BleepingComputer • 2026-01-28 05:15 • www.bleepingcomputer.com
    A malicious campaign is actively targeting exposed LLM (Large Language Model) service endpoints to commercialize unauthorized access to AI infrastructure. […]
    https://www.bleepingcomputer.com/news/security/hackers-hijack-exposed-llm-endpoints-in-bizarre-bazaar-operation/
  • Slovakian man pleads guilty to operating darknet marketplace
    BleepingComputer • 2026-01-28 04:49 • www.bleepingcomputer.com
    A Slovakian national admitted on Tuesday to helping operate a darknet marketplace that sold narcotics, cybercrime tools and services, fake government IDs, and stolen personal information for more than two years. […]
    https://www.bleepingcomputer.com/news/security/slovakian-man-pleads-guilty-to-operating-kingdown-market-cybercrime-marketplace/
  • Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution
    The Hacker News • 2026-01-28 04:43 • thehackernews.com
    Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution.
    The weaknesses, discovered by the JFrog Security Research team, are listed below –

    CVE-2026-1470 (CVSS score: 9.9) – An eval injection vulnerability that could allow an authenticated user to bypass the Expression
    https://thehackernews.com/2026/01/two-high-severity-n8n-flaws-allow.html

  • From Triage to Threat Hunts: How AI Accelerates SecOps
    The Hacker News • 2026-01-28 03:55 • thehackernews.com
    If you work in security operations, the concept of the AI SOC agent is likely familiar. Early narratives promised total autonomy. Vendors seized on the idea of the “Autonomous SOC” and suggested a future where algorithms replaced analysts.
    That future has not arrived. We have not seen mass layoffs or empty security operations centers. We have instead seen the emergence of a practical reality.
    https://thehackernews.com/2026/01/from-triage-to-threat-hunts-how-ai.html
  • New WhatsApp lockdown feature protects high-risk users from hackers
    BleepingComputer • 2026-01-28 03:48 • www.bleepingcomputer.com
    Meta has started rolling out a new WhatsApp lockdown-style security feature designed to protect journalists, public figures, and other high-risk individuals from sophisticated threats, including spyware attacks. […]
    https://www.bleepingcomputer.com/news/security/whatsapp-gets-new-lockdown-feature-that-blocks-cyberattacks/
  • Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks
    The Hacker News • 2026-01-28 03:40 • thehackernews.com
    Threat actors with ties to China have been observed using an updated version of a backdoor called COOLCLIENT in cyber espionage attacks in 2025 to facilitate comprehensive data theft from infected endpoints.
    The activity has been attributed to Mustang Panda (aka Earth Preta, Fireant, HoneyMyte, Polaris, and Twill Typhoon) with the intrusions primarily directed against government entities located
    https://thehackernews.com/2026/01/mustang-panda-deploys-updated.html
  • Password Reuse in Disguise: An Often-Missed Risky Workaround
    The Hacker News • 2026-01-28 02:30 • thehackernews.com
    When security teams discuss credential-related risk, the focus typically falls on threats such as phishing, malware, or ransomware. These attack methods continue to evolve and rightly command attention. However, one of the most persistent and underestimated risks to organizational security remains far more ordinary.
    Near-identical password reuse continues to slip past security controls, often
    https://thehackernews.com/2026/01/password-reuse-in-disguise-often-missed.html
  • Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088
    The Hacker News • 2026-01-28 01:46 • thehackernews.com
    Google on Tuesday revealed that multiple threat actors, including nation-state adversaries and financially motivated groups, are exploiting a now-patched critical security flaw in RARLAB WinRAR to establish initial access and deploy a diverse array of payloads.
    “Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated
    https://thehackernews.com/2026/01/google-warns-of-active-exploitation-of.html
  • Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan
    The Hacker News • 2026-01-28 01:30 • thehackernews.com
    Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that masquerade as spellcheckers but contain functionality to deliver a remote access trojan (RAT).
    The packages, named spellcheckerpy and spellcheckpy, are no longer available on PyPI, but not before they were collectively downloaded a little over 1,000 times.
    “Hidden inside the Basque
    https://thehackernews.com/2026/01/fake-python-spellchecker-packages-on.html
  • Beware! Fake ChatGPT browser extensions are stealing your login credentials
    Graham Cluley • 2026-01-28 01:20 • www.bitdefender.com
    If you’ve installed a browser extension to enhance your ChatGPT experience, you might want to think again.

    Read more in my article on the Hot for Security blog.
    https://www.bitdefender.com/en-us/blog/hotforsecurity/beware-fake-chatgpt-browser-extensions-are-stealing-your-login-credentials

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like