21
Jan
2026

GNU InetUtils Vulnerability Exploited via “-f root” to Achieve Full System Control

A critical authentication bypass vulnerability in GNU InetUtils’ telnetd server allows remote attackers to gain root access without credentials by…

Two rats
21
Jan
2026

Can you use too many LOLBins to drop some RATs?

Recently, our team came across an infection attempt that stood out—not for its sophistication, but for how determined the attacker…

LastPass theft
21
Jan
2026

Fake Lastpass emails pose as password vault backup alerts

LastPass is warning of a new phishing campaign disguised as a maintenance notification from the service, asking users to back…

Research Finds 64% of Third-Party Apps Access Sensitive Data
21
Jan
2026

Research Finds 64% of Third-Party Apps Access Sensitive Data

Boston, MA, USA, January 21st, 2026, CyberNewsWire Reflectiz today announced the release of its 2026 State of Web Exposure Research,…

Critical Zoom Vulnerability Enables Remote Code Execution via Command Injection
21
Jan
2026

Critical Zoom Vulnerability Enables Remote Code Execution via Command Injection

A critical command injection vulnerability in Zoom Node Multimedia Routers (MMRs) has been disclosed, potentially allowing meeting participants to execute…

Researchers warn VoidProxy phishing platform can bypass MFA
21
Jan
2026

Backup request is actually a phishing campaign, LastPass warns

LastPass on Tuesday warned of a phishing campaign with false claims that the company is conducting maintenance and asking customers…

Cybersecurity abstract
21
Jan
2026

Black Basta’s alleged ringleader identified as authorities raid homes of other members

Law enforcement agencies from multiple European countries are still pursuing leads on people involved in the Black Basta ransomware group,…

GitLab
21
Jan
2026

GitLab warns of high-severity 2FA bypass, denial-of-service flaws

GitLab has patched a high-severity two-factor authentication bypass impacting community and enterprise editions of its software development platform. Tracked as…

Researchers Uncovered LockBit’s 5.0 Latest Affiliate Panel and Encryption Variants
21
Jan
2026

Researchers Uncovered LockBit’s 5.0 Latest Affiliate Panel and Encryption Variants

LockBit, one of the most dangerous ransomware groups in the world, has released its newest version despite facing serious law…

ErrTraffic Exploits Visual Page Breaks to Fuel ClickFix Attacks, Rebranding Exploits as “GlitchFix”
21
Jan
2026

ErrTraffic Exploits Visual Page Breaks to Fuel ClickFix Attacks, Rebranding Exploits as “GlitchFix”

ErrTraffic is a Traffic Distribution System (TDS) designed to power ClickFix social engineering attacks. Unlike traditional fake update prompts, ErrTraffic deliberately breaks…

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
21
Jan
2026

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Ravie LakshmananJan 21, 2026Vulnerability / Network Security Zoom and GitLab have released security updates to resolve a number of security…

ACME Flaw in Cloudflare allowed attackers to reach origin servers
21
Jan
2026

ACME Flaw in Cloudflare allowed attackers to reach origin servers

ACME flaw in Cloudflare allowed attackers to reach origin servers Pierluigi Paganini January 21, 2026 Cloudflare fixed a flaw in…