Category: CyberSecurityNews

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems
23
Jan
2026

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems

A new malware campaign targeting Windows users has emerged, using deceptive LNK shortcut files to distribute MoonPeak, a dangerous remote…

20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation
23
Jan
2026

20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation

A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by…

Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware
23
Jan
2026

Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware

A new wave of web-based malware campaigns is using fake verification pages to trick users into installing dangerous software. These…

New Windows Notepad and Paint Update Brings More Useful AI Features
23
Jan
2026

New Windows Notepad and Paint Update Brings More Useful AI Features

Artificial intelligence (AI) features have been added to Windows 11 Notepad and Paint for Canary and Dev Channel users, turning…

New Watering Hole Attacking EmEditor Users with Stealer Malware
23
Jan
2026

New Watering Hole Attacking EmEditor Users with Stealer Malware

A major security threat has emerged targeting developers who use EmEditor, a popular text editor favored by Japanese programming communities….

Microsoft to Add Brand Impersonation Protection Warning to Teams Calls
23
Jan
2026

Microsoft to Add Brand Impersonation Protection Warning to Teams Calls

A new security feature for Teams Calling now alerts users to suspicious external calls that try to impersonate trusted organizations….

MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command
23
Jan
2026

MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command

A sophisticated macOS malware called MacSync has emerged as a dangerous new threat targeting cryptocurrency users through deceptive social engineering…

Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports
23
Jan
2026

Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports

Node.js has updated its HackerOne vulnerability disclosure program to require a minimum Signal score of 1.0, aiming to reduce low-quality…

Hackers Can Use GenAI to Change Loaded Clean Page Into Malicious within Seconds
23
Jan
2026

Hackers Can Use GenAI to Change Loaded Clean Page Into Malicious within Seconds

A new and alarming threat has emerged in the cybersecurity landscape where attackers combine artificial intelligence with web-based attacks to…

New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users
23
Jan
2026

New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users

A dangerous new generation of phishing kits designed specifically for voice-based attacks has emerged as a growing threat to enterprise…

76 Zero-day Vulnerabilities Uncovered by Hackers on Pwn2Own Automotive 2026
23
Jan
2026

76 Zero-day Vulnerabilities Uncovered by Hackers on Pwn2Own Automotive 2026

Security researchers at Pwn2Own Automotive 2026 demonstrated 76 unique zero-day vulnerabilities across electric vehicle chargers and in-vehicle infotainment systems. The…

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability
23
Jan
2026

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability

Fortinet confirms active exploitation of a FortiCloud SSO authentication bypass vulnerability, with a new automated campaign targeting even fully patched…