Critical sandbox escape flaw discovered in popular vm2 NodeJS library
27
Jan
2026

Critical sandbox escape flaw found in popular vm2 NodeJS library

A critical-severity vulnerability in the vm2 Node.js sandbox library, tracked as CVE-2026-22709, allows escaping the sandbox and executing arbitrary code on the…

Attackers Hijacking Official GitHub Desktop Repository to Distribute Malware as Official Installer
27
Jan
2026

Attackers Hijacking Official GitHub Desktop Repository to Distribute Malware as Official Installer

Cybercriminals have discovered a dangerous way to trick developers into downloading malware by exploiting how GitHub works. The attack involves…

Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js
27
Jan
2026

Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js

A critical vulnerability in the vm2 JavaScript sandbox library (versions ≤ 3.10.0) enables attackers to bypass sandbox protections and execute…

March ransomware slowdown probably a red herring
27
Jan
2026

Broken decryptor leaves Sicarii ransomware victims adrift

A coding error, possibly introduced thanks to over-reliance on artificial intelligence (AI) vibe coding tools, has rendered an emergent strain…

Interconnectedness, extortion risk make cybersecurity a healthcare C-suite priority
27
Jan
2026

Interconnectedness, extortion risk make cybersecurity a healthcare C-suite priority

Listen to the article 3 min This audio is auto-generated. Please let us know if you have feedback. Dive Brief:…

Nike
27
Jan
2026

Nike investigates data breach after extortion gang leaks files

Nike is investigating what it described as a “potential cyber security incident” after the World Leaks ransomware gang leaked 1.4…

G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload
27
Jan
2026

G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload

On January 23rd, 2026, security researchers discovered a dangerous npm package named ansi-universal-ui that disguised itself as a legitimate user…

ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games
27
Jan
2026

ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games

A surge in infrastructure deployment that mirrors the tactics of SLSH, a predatory alliance uniting three major threat actors: Scattered…

What Every Company Needs To Know About Cybersecurity In 2026
27
Jan
2026

RSAC 2026—Where The World Talks Security

For 35 years, RSAC has been a driving force behind the world’s cybersecurity community. The power of community is a…

UK government’s National Data Library works up steam
27
Jan
2026

UK government’s National Data Library works up steam

The UK government’s Department for Science, Innovation and Technology (DSIT) has completed what it calls the “discovery phase” of its…

Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online
27
Jan
2026

Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online

Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online Pierluigi Paganini January 27, 2026 Shadowserver researchers found 6,000+ SmarterMail servers…

Hackers Using Teams to Deliver Malicious Content Posing as Microsoft Services
27
Jan
2026

Hackers Using Teams to Deliver Malicious Content Posing as Microsoft Services

A sophisticated phishing campaign has been identified in which threat actors are abusing legitimate Microsoft Teams functionality to distribute malicious…