28
Jan
2026

Why prevention-first secrets security will define enterprise scale: Learnings from a leading telecom

Once a secret enters Git, it’s expensive to remediate. But the real problem runs deeper than cost. Grégory Maitrallain, Solution…

28
Jan
2026

React2Shell Vulnerability CVE-2025-55182 Actively Exploited

Threat actors have been actively exploiting a critical vulnerability in React Server Components, tracked as CVE-2025-55182 and commonly referred to…

Malware toolkit guarantees store approval for Chrome extensions
28
Jan
2026

Malware toolkit guarantees store approval for Chrome extensions

A suspected Russian malware-as-a-service operation has been selling a turnkey website-spoofing toolkit that promised to bypass Google’s Chrome Web Store…

16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins
28
Jan
2026

16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins

Researchers have uncovered a significant security threat targeting ChatGPT users through deceptive browser extensions. A coordinated campaign involving 16 malicious…

28
Jan
2026

CERT UEFI Parser: Open-source tool exposes UEFI architecture to uncover vulnerabilities

CERT UEFI Parser, a new open-source security analysis tool from the CERT Coordination Center has been released to help researchers…

28
Jan
2026

Cyberattack On Delta Disrupts Security Services In Russia

A cyberattack on Delta, a Russian provider of alarm and security systems for homes, businesses, and vehicles, has disrupted operations…

Gov faces Senate wrath over social media ban secrecy
28
Jan
2026

Gov faces Senate wrath over social media ban secrecy

Federal Communications Minister Anika Wells is facing a Senate challenge to her decision to block access to documents that could…

OpenSSL Vulnerabilities Allow Remote Attackers to Execute Malicious Code
28
Jan
2026

OpenSSL Vulnerabilities Allow Remote Attackers to Execute Malicious Code

OpenSSL patched 12 vulnerabilities on January 27, 2026, including one high-severity flaw that could lead to remote code execution. Most…

28
Jan
2026

Grammarly and QuillBot are among widely used Chrome extensions facing serious privacy questions

A new study shows that some of the most widely used AI-powered browser extensions are a privacy risk. They collect…

28
Jan
2026

Audits for AI systems that keep changing

Security and risk teams often rely on documentation and audit artifacts that reflect how an AI system worked months ago….

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected
28
Jan
2026

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Ravie LakshmananJan 28, 2026Network Security / Zero-Day Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS…

Critical Vulnerability in VM2 Sandbox Library for Node.js Let Attackers run Untrusted Code
28
Jan
2026

Critical Vulnerability in VM2 Sandbox Library for Node.js Let Attackers run Untrusted Code

A critical sandbox escape vulnerability has been identified in vm2. This widely used Node.js library provides sandbox isolation for executing…