week in security
26
Jan
2026

A week in security (January 19 – January 25)

Last week on Malwarebytes Labs: On the ThreatDown blog: Stay safe! We don’t just report on threats—we remove them Cybersecurity…

Russia-linked Sandworm APT implicated in major cyber attack on Poland’s power grid
26
Jan
2026

Russia-linked Sandworm APT implicated in major cyber attack on Poland’s power grid

Russia-linked Sandworm APT implicated in major cyber attack on Poland’s power grid Pierluigi Paganini January 26, 2026 Russia-linked APT Sandworm…

Attackers Targeting Construction Firms Exploiting Mjobtime App Vulnerability Using MSSQL and IIS POST Request
26
Jan
2026

Attackers Targeting Construction Firms Exploiting Mjobtime App Vulnerability Using MSSQL and IIS POST Request

Attackers are increasingly turning their attention to construction firms by abusing weaknesses in business software that runs on their job…

26
Jan
2026

Inside Microsoft’s veteran-to-tech workforce pipeline

The technology workforce is changing, and military veterans are increasingly being recognized as one of the industry’s most valuable and…

48M Gmail, 6.5M Instagram Exposed Online From Unprotected Database
26
Jan
2026

48M Gmail, 6.5M Instagram Exposed Online From Unprotected Database

A massive database containing 149 million stolen login credentials was discovered exposed online without password protection or encryption. Posing serious…

Threat Actors Fake BSODs and Trusted Build Tools to Bypass Defenses and Deploy DCRat
26
Jan
2026

Threat Actors Fake BSODs and Trusted Build Tools to Bypass Defenses and Deploy DCRat

A new malware campaign is exploiting fake Blue Screen of Death warnings and trusted Microsoft build tools to deliver a…

26
Jan
2026

Brakeman: Open-source vulnerability scanner for Ruby on Rails applications

Brakeman is an open-source security scanner used by teams that build applications with Ruby on Rails. The tool focuses on…

26
Jan
2026

AWS releases updated PCI PIN compliance report for payment cryptography

Amazon Web Services has published an updated Payment Card Industry Personal Identification Number (PCI PIN) compliance package for its AWS…

Microsoft Investigating Boot Failure Issues With Windows 11, version 25H2 Following January Update
26
Jan
2026

Microsoft Investigating Boot Failure Issues With Windows 11, version 25H2 Following January Update

Microsoft has launched an urgent investigation into severe stability issues plaguing the January 2026 security update for Windows 11, following…

ChatGPT
26
Jan
2026

ChatGPT Temporary chat feature is getting a much-needed upgrade

OpenAI is testing a big upgrade for ChatGPT’s temporary chat feature. The update will allow you to retain personalization in temporary…

1Password adds pop-pp warnings for suspected phishing sites
25
Jan
2026

1Password adds pop-up warnings for suspected phishing sites

The 1Password digital vault and password manager has added built-in protection against phishing URLs to help users identify malicious pages…

7 Top Endpoint Security Platforms for 2026
25
Jan
2026

7 Top Endpoint Security Platforms for 2026 – Hackread – Cybersecurity News, Data Breaches, AI, and More

Endpoints remain the most common pivot point attackers use to establish presence inside networks, escalate privileges, and move laterally toward…