MacSync macOS Infostealer Exploits ClickFix-style Attack to Trick Users with Single Terminal Command
23
Jan
2026

MacSync macOS Infostealer Exploits ClickFix-style Attack to Trick Users with Single Terminal Command

A sophisticated macOS infostealer campaign that leverages deceptive ClickFix-style social engineering to distribute MacSync, a Malware-as-a-Service (MaaS) credential-stealing tool targeting cryptocurrency…

VS Code
23
Jan
2026

Malicious AI extensions on VSCode Marketplace steal developer data

Two malicious extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace that were collectively installed 1.5 million times exfiltrate developer data to China-based servers….

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems
23
Jan
2026

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems

A new malware campaign targeting Windows users has emerged, using deceptive LNK shortcut files to distribute MoonPeak, a dangerous remote…

76 Zero-Day Vulnerabilities Exposed at Pwn2Own Automotive 2026 by Hackers
23
Jan
2026

76 Zero-Day Vulnerabilities Exposed at Pwn2Own Automotive 2026 by Hackers

The final day of Pwn2Own Automotive 2026 brought the world’s elite security researchers to the finish line with a spectacular…

20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation
23
Jan
2026

20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation

A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by…

Threat Actors Exploit LNK Files to Deploy MoonPeak Malware on Windows Systems
23
Jan
2026

Threat Actors Exploit LNK Files to Deploy MoonPeak Malware on Windows Systems

A sophisticated three-stage malware attack campaign against Windows users in South Korea using specially crafted LNK (shortcut) files. The attack…

Fortinet fixed two critical flaws in FortiFone and FortiSIEM
23
Jan
2026

Fortinet warns of active FortiCloud SSO bypass affecting updated devices

Fortinet warns of active FortiCloud SSO bypass affecting updated devices Pierluigi Paganini January 23, 2026 Fortinet confirmed attacks are bypassing…

CISA confirms active exploitation of four enterprise software bugs
23
Jan
2026

CISA confirms active exploitation of four enterprise software bugs

The Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. warned of active exploitation of four vulnerabilities impacting enterprise software from…

Node.js Sets New Standard for HackerOne Reports, Demands Signal of 1.0 or Higher
23
Jan
2026

Node.js Sets New Standard for HackerOne Reports, Demands Signal of 1.0 or Higher

Node.js has implemented a new quality control measure on its HackerOne bug bounty program, requiring researchers to maintain a minimum…

Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware
23
Jan
2026

Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware

A new wave of web-based malware campaigns is using fake verification pages to trick users into installing dangerous software. These…

™
23
Jan
2026

Salt Security Expands “Universal Visibility” with Specialized API Security for Databricks and Rapid Edge Support for Netlify

Salt Security announced a major expansion of its platform’s connectivity fabric with two new strategic integrations: the Salt Databricks Connector and…

CISA Updates KEV Catalog with 4 Critical Vulnerabilities Following Ongoing Exploits
23
Jan
2026

CISA Updates KEV Catalog with 4 Critical Vulnerabilities Following Ongoing Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalogue with four critical security flaws…