Researchers find Jordan government used Cellebrite phone-cracking tech against activists
22
Jan
2026

Researchers find Jordan government used Cellebrite phone-cracking tech against activists

Jordanian authorities used Cellebrite phone-cracking technology to access the devices of domestic activists and human rights defenders and then extract…

Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild
22
Jan
2026

Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild

A critical authentication bypass vulnerability in SmarterTools SmarterMail is actively being exploited in the wild by attackers, according to security…

ICE Agents Are ‘Doxing’ Themselves
22
Jan
2026

ICE Agents Are ‘Doxing’ Themselves

Last week, a website called ICE List went viral after its creators said that they had received what they described…

Multi-Stage Scheme Steals Data, Triggers UPI Payments
22
Jan
2026

Multi-Stage Scheme Steals Data, Triggers UPI Payments

A sophisticated multi-stage phishing campaign is actively targeting PNB MetLife Insurance customers through fake payment gateway pages. The attack chain…

Hackers Are Using LinkedIn DMs and PDF Tools to Deploy Trojans
22
Jan
2026

Hackers Are Using LinkedIn DMs and PDF Tools to Deploy Trojans – Hackread – Cybersecurity News, Data Breaches, AI, and More

ReliaQuest Threat Research has identified a new phishing campaign on LinkedIn that tricks professionals into downloading malicious files. Using DLL…

Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
22
Jan
2026

INC ransomware opsec fail allowed data recovery for 12 US orgs

An operational security failure allowed researchers to recover data that the INC ransomware gang stole from a dozen U.S. organizations….

Hackers Earned $516,500 for 37 Unique 0-day Vulnerabilities
22
Jan
2026

Hackers Earned $516,500 for 37 Unique 0-day Vulnerabilities

Day One of Pwn2Own Automotive 2026, which delivered $516,500 USD for 37 zero-days, the event has now accumulated $955,750 USD…

BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records
22
Jan
2026

BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records

A critical vulnerability in BIND 9 exposes DNS servers to remote denial-of-service (DoS) attacks. Security firm ISC disclosed CVE-2025-13878 on…

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
22
Jan
2026

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

Ravie LakshmananJan 22, 2026Vulnerability / Linux A critical security flaw has been disclosed in the GNU InetUtils telnet daemon (telnetd)…

Microsoft Teams
22
Jan
2026

Microsoft Teams to add brand impersonation warnings to calls

Microsoft will soon add new fraud protection features to Teams calls, warning users about external callers who attempt to impersonate…

Attackers Infrastructure Exposed Using JA3 Fingerprinting Tool
22
Jan
2026

Attackers Infrastructure Exposed Using JA3 Fingerprinting Tool

A new powerful method to detect and trace attacker infrastructure using JA3 fingerprinting, a technique that identifies malicious tools through…

NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution
22
Jan
2026

NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution

NVIDIA has patched critical vulnerabilities in its CUDA Toolkit that expose developers and GPU-accelerated systems to command injection and arbitrary…