Cybersecurity News and Headlines

US Cargo Tech Company Publicly Exposed Its Shipping Systems and Customer Data to the Web
NewsJan 14, 2026

US Cargo Tech Company Publicly Exposed Its Shipping Systems and Customer Data to the Web

Bluspark Global, a U.S. shipping‑tech firm behind the Bluvoyix platform, left its API and customer data exposed to the public internet. Researchers discovered unauthenticated endpoints, plaintext passwords, and the ability to create admin accounts, granting access to decades‑old shipment records....

By TechCrunch (Cybersecurity)
From Bot Noise to Real Insights: How Jobrapido Achieved True Marketing ROI
NewsJan 14, 2026

From Bot Noise to Real Insights: How Jobrapido Achieved True Marketing ROI

Jobrapido, a global recruitment‑marketing platform, partnered with DataDome to combat bot‑driven traffic that was inflating costs and skewing performance metrics. The AI‑powered solution filtered out roughly 15% of invalid visits, giving the company a clean, real‑time view of genuine user...

By Security Boulevard
RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement
NewsJan 14, 2026

RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

Microsoft announced a joint operation with international law enforcement to dismantle RedVDS, a cybercrime‑as‑a‑service platform that provides disposable Windows VMs for phishing, BEC and financial fraud. Launched in 2019, RedVDS charged as little as $24 per month and is tied...

By SecurityWeek
Hacker Claims Full Breach of Russia’s Max Messenger, Threatens Public Leak
NewsJan 14, 2026

Hacker Claims Full Breach of Russia’s Max Messenger, Threatens Public Leak

A hacker using the alias CamelliaBtw posted on DarkForums claiming a full breach of Russia’s Max Messenger, exfiltrating roughly 142 GB of data that includes 15.4 million user records, authentication tokens, passwords, communication metadata, source code, and internal infrastructure assets. The alleged...

By HackRead
AppOmni Surfaces BodySnatcher AI Agent Security Flaw Affecting ServiceNow Apps
NewsJan 14, 2026

AppOmni Surfaces BodySnatcher AI Agent Security Flaw Affecting ServiceNow Apps

AppOmni, a SaaS security platform vendor, has disclosed a critical vulnerability in ServiceNow identified as CVE‑2025‑12420, nicknamed BodySnatcher. The flaw enables an unauthenticated attacker to impersonate any ServiceNow user and spawn a malicious AI agent within the platform. Because ServiceNow...

By Security Boulevard
Webinar: Beyond the Quadrant: An Analyst’s Guide to Evaluating Email Security in 2026
NewsJan 14, 2026

Webinar: Beyond the Quadrant: An Analyst’s Guide to Evaluating Email Security in 2026

Former Gartner analyst Ravisha Chugh and Abnormal’s Director of Product Marketing Lane Billings will host a webinar on January 20 2026, revealing how email‑security vendors will be evaluated in 2026. The session outlines Gartner’s evaluation criteria, essential vendor questions, red‑flags, and a proven shortlisting...

By Help Net Security
Survey: Rapid AI Adoption Causes Major Cyber Risk Visibility Gaps
NewsJan 14, 2026

Survey: Rapid AI Adoption Causes Major Cyber Risk Visibility Gaps

Panorays’ survey of 200 U.S. CISOs reveals that 60% consider AI vendors uniquely risky, yet only 22% have formal vetting processes. The rapid rollout of chat‑bots and AI agents is outpacing traditional third‑party risk controls, leaving most organizations with limited...

By HackRead
Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits
NewsJan 14, 2026

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits

New research by Jamf uncovers that the Predator spyware, sold by Intellexa, includes a self‑diagnostic system that reports detailed error codes when attacks fail. These codes convey why deployments were aborted—such as detection of developer mode, proxies, or analysis tools—allowing...

By SecurityWeek
Reprompt Attack Let Hackers Hijack Microsoft Copilot Sessions
NewsJan 14, 2026

Reprompt Attack Let Hackers Hijack Microsoft Copilot Sessions

Researchers at Varonis uncovered a “Reprompt” attack that lets hackers hijack Microsoft Copilot Personal sessions by embedding malicious prompts in the URL’s `q` parameter. After a victim clicks a crafted link, the attacker can issue follow‑up commands that bypass Copilot’s...

By BleepingComputer
EasyDMARC Expands Executive Team with Armen Najarian as Chief Commercial Officer
NewsJan 14, 2026

EasyDMARC Expands Executive Team with Armen Najarian as Chief Commercial Officer

EasyDMARC announced the appointment of Armen Najarian as its new Chief Commercial Officer. Najarian brings over 25 years of experience in email security, fraud prevention, and AI‑driven analytics, previously leading go‑to‑market roles at ThreatMetrix, Agari, Outseer and Sift. He will...

By Security Boulevard
Data Protection Agency Tells Coupang to Stop Publishing Unconfirmed Information About Data Breach
NewsJan 14, 2026

Data Protection Agency Tells Coupang to Stop Publishing Unconfirmed Information About Data Breach

South Korea’s Personal Information Protection Commission (PIPC) has ordered e‑commerce giant Coupang to stop publishing its own findings about a recent data breach that exposed personal information of millions of users. The regulator warned that unverified disclosures could mislead consumers...

By DataBreaches.net
Eurail Passengers Taken for a Ride as Data Breach Spills Passports, Bank Details
NewsJan 14, 2026

Eurail Passengers Taken for a Ride as Data Breach Spills Passports, Bank Details

Eurail confirmed a data breach that exposed personal information of customers, particularly those who received passes through the EU‑funded DiscoverEU programme. The breach potentially includes passport numbers, issuance details, and bank information, though direct‑purchase customers’ passports were not stored visually....

By DataBreaches.net
Airia Adds AI Governance for Compliance, Accountability, and Control
NewsJan 14, 2026

Airia Adds AI Governance for Compliance, Accountability, and Control

Airia has launched an AI Governance product, completing its three‑pillar enterprise AI management ecosystem alongside AI Security and Agent Orchestration. The new suite offers a governance dashboard, model and agent registries, compliance automation, and risk assessment tools to provide end‑to‑end...

By Help Net Security
SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats
NewsJan 14, 2026

SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats

SpyCloud unveiled its Supply Chain Threat Protection solution, extending identity‑threat visibility to vendors and other third‑party partners. The platform draws on billions of recaptured breach, malware, phishing and dark‑web data points to deliver real‑time evidence of compromised credentials. It introduces...

By CSO Online
One Identity Manager 10.0 Introduces Risk-Based Governance and ITDR Capabilities
NewsJan 14, 2026

One Identity Manager 10.0 Introduces Risk-Based Governance and ITDR Capabilities

One Identity launched Manager 10.0, adding risk‑based governance, identity threat detection and response (ITDR) playbooks, and AI‑assisted natural‑language reporting. The upgrade integrates third‑party UEBA risk scores, automates remediation actions, and introduces a browser‑based admin console. Enhanced Syslog CEF formatting improves SIEM...

By Help Net Security
Cloud Marketplace Pax8 Accidentally Exposes Data on 1,800 MSP Partners
NewsJan 14, 2026

Cloud Marketplace Pax8 Accidentally Exposes Data on 1,800 MSP Partners

Cloud commerce platform Pax8 inadvertently emailed an internal spreadsheet to fewer than 40 UK partners, exposing business data for roughly 1,800 managed service providers. The CSV listed more than 56,000 entries, including partner IDs, customer names, Microsoft SKU counts and...

By BleepingComputer
Victorian Department of Education Says Hackers Stole Students’ Data
NewsJan 14, 2026

Victorian Department of Education Says Hackers Stole Students’ Data

The Victorian Department of Education disclosed that an unauthorized party accessed a database containing personal details and school‑issued email addresses of current and former students, along with encrypted passwords. More sensitive information such as birth dates, home addresses, and phone...

By BleepingComputer
G7 Sets 2034 Deadline for Finance to Adopt Quantum-Safe Systems
NewsJan 14, 2026

G7 Sets 2034 Deadline for Finance to Adopt Quantum-Safe Systems

The G7 Cyber Expert Group has issued a recommended roadmap urging financial institutions and public entities to fully adopt post‑quantum cryptography by 2034. The plan outlines six phases—from awareness and inventory to migration, testing and validation—spanning 2025‑2035. While advisory, it...

By Infosecurity Magazine
New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification
NewsJan 14, 2026

New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification

New research shows 64% of third‑party applications on websites access sensitive data without a clear business justification, up from 51% in 2024. Only 39% of security leaders have deployed dedicated web‑exposure solutions, despite 81% ranking web attacks as a top...

By The Hacker News
Microsoft Fixes Three Zero-Days on Busy Patch Tuesday
NewsJan 14, 2026

Microsoft Fixes Three Zero-Days on Busy Patch Tuesday

Microsoft released its latest Patch Tuesday update, fixing 114 CVEs including three critical zero‑day bugs. The zero‑days are CVE‑2026‑20805 (information disclosure in Desktop Window Manager), CVE‑2026‑21265 (secure‑boot certificate bypass), and CVE‑2023‑31096 (elevation of privilege in legacy Agere modem drivers). The...

By Infosecurity Magazine
Cybersecurity at the State and Local Level: Washington Has the Framework, It’s Time to Act
NewsJan 14, 2026

Cybersecurity at the State and Local Level: Washington Has the Framework, It’s Time to Act

The March 2025 White House Executive Order calls on states, localities and tribal entities to own their cybersecurity preparedness, while the State and Local Cybersecurity Grant Program (SLCGP) allocates $1 billion over four years to fund those efforts. The bipartisan PILLAR...

By CSO Online
Spring CLI Vulnerability Allows Attackers to Execute Commands on User Systems
NewsJan 14, 2026

Spring CLI Vulnerability Allows Attackers to Execute Commands on User Systems

A command‑injection flaw (CVE‑2026‑22718) has been discovered in the Spring CLI VS Code extension, affecting all versions up to 0.9.0. The vulnerability allows an attacker with local access to execute arbitrary commands, earning a medium severity rating and a CVSS score...

By GBHackers On Security
Is It Time for Internet Services to Adopt Identity Verification?
NewsJan 14, 2026

Is It Time for Internet Services to Adopt Identity Verification?

Australia has enacted a law prohibiting anyone under 16 from holding a social‑media account, forcing platforms to purge non‑compliant profiles. The move positions the country as a global test case for age‑based bans and sparks a broader debate on mandatory...

By WeLiveSecurity
Microsoft: Windows 365 Update Blocks Access to Cloud PC Sessions
NewsJan 14, 2026

Microsoft: Windows 365 Update Blocks Access to Cloud PC Sessions

Microsoft confirmed that a recent Windows 365 update is preventing users from signing into their Cloud PC sessions, causing widespread access failures that began on Tuesday at 19:00 UTC. The issue, tracked under incident WP1217671, stems from a security‑focused update that unintentionally broke...

By BleepingComputer
Multiple Elastic Vulnerabilities Could Lead to File Theft and DoS
NewsJan 14, 2026

Multiple Elastic Vulnerabilities Could Lead to File Theft and DoS

Elastic has issued urgent patches for four critical Kibana vulnerabilities spanning versions 7.x through 9.2.3. The most severe, CVE‑2026‑0532, combines SSRF and file disclosure, allowing authenticated attackers to exfiltrate credentials. Three medium‑severity flaws can cause denial‑of‑service through resource exhaustion in...

By GBHackers On Security
Monroe University Says 2024 Data Breach Affects 320,000 People
NewsJan 14, 2026

Monroe University Says 2024 Data Breach Affects 320,000 People

Monroe University disclosed that a December 2024 cyberattack compromised personal, financial, and health data of more than 320,000 individuals. Attackers accessed the network for two weeks, from Dec 9 to Dec 23, before the breach was detected. The university began notifying affected...

By BleepingComputer
AI in Manufacturing: The Growing Risk and Reward Dilemma Escalating Data Security
NewsJan 14, 2026

AI in Manufacturing: The Growing Risk and Reward Dilemma Escalating Data Security

AI adoption in U.S. manufacturing is accelerating, with 55% of firms already using generative AI and many planning further expansion. Meanwhile, ransomware attacks on the sector surged 87% in 2024, making manufacturing the most targeted industry. Without enterprise‑grade security—especially through...

By Security Boulevard
Scamnetic Delivers Fraud Protection Across All Payment Types
NewsJan 14, 2026

Scamnetic Delivers Fraud Protection Across All Payment Types

Scamnetic launched its patent‑pending IDeveryone Payment Protection solution, extending identity‑proofing to every payment channel—from push and digital payments to cryptocurrency, checks, wire transfers and ACH. The offering adds real‑time recipient verification and optional insurance, aiming to curb the $442 billion global...

By Help Net Security
Critical Node.js Vulnerability Can Cause Server Crashes via Async_hooks Stack Overflow
NewsJan 14, 2026

Critical Node.js Vulnerability Can Cause Server Crashes via Async_hooks Stack Overflow

Node.js released security updates fixing a critical vulnerability (CVE‑2025‑59466) that causes the runtime to terminate with exit code 7 when a stack overflow occurs while async_hooks is enabled. The bug affects all versions from 8.x through 18.x and impacts major frameworks...

By The Hacker News
CISO Assistant: Open-Source Cybersecurity Management and GRC
NewsJan 14, 2026

CISO Assistant: Open-Source Cybersecurity Management and GRC

CISO Assistant’s community edition is an open‑source governance, risk, and compliance (GRC) platform that lets security teams document assets, risks, controls, and framework alignment in a single, self‑hosted system. The tool ships with built‑in mappings to ISO 27001, NIST CSF, and...

By Help Net Security
US Cybersecurity Weakened by Congressional Delays Despite Plankey Renomination
NewsJan 14, 2026

US Cybersecurity Weakened by Congressional Delays Despite Plankey Renomination

The White House renominated seasoned cyber veteran Sean Plankey as CISA director after his initial nomination lapsed, but Senate holds tied to a Coast Guard issue and a pending telecom security report are delaying confirmation. Simultaneously, deep budget cuts have...

By CSO Online
Firmware Scanning Time, Cost, and Where Teams Run EMBA
NewsJan 14, 2026

Firmware Scanning Time, Cost, and Where Teams Run EMBA

A new research paper compares the EMBA firmware analysis tool on a local workstation and an Azure virtual machine, measuring execution time, repeatability, and cost. Identical configurations and a common firmware set were used, revealing that scan duration depends more...

By Help Net Security
Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives
NewsJan 14, 2026

Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

California Privacy Protection Agency appointed Nicole Ozer to its board, reinforcing the state’s privacy agenda. Ozer, former ACLU tech director and executive at UC Law San Francisco, brings extensive experience in privacy law, AI, and digital civil liberties. Her appointment...

By The Cyber Express
How AI Image Tools Can Be Tricked Into Making Political Propaganda
NewsJan 14, 2026

How AI Image Tools Can Be Tricked Into Making Political Propaganda

A new study shows that commercial text‑to‑image models can be coaxed into generating political propaganda by replacing explicit names with descriptive profiles and fragmenting prompts across multiple low‑risk languages. Researchers tested GPT‑4o, GPT‑5 and GPT‑5.1, achieving bypass rates up to...

By Help Net Security
Taiwan Endures Greater Cyber Pressure From China
NewsJan 14, 2026

Taiwan Endures Greater Cyber Pressure From China

Taiwan’s National Security Bureau reported an average of 2.63 million cyber attacks per day in 2025, a 6 percent rise from the prior year. Energy utilities faced a ten‑fold surge in malicious traffic while hospitals and emergency services saw attacks climb 54 percent....

By Dark Reading
Personal Details of Thousands of Border Patrol and ICE Agents Allegedly Leaked in Huge Data Breach
NewsJan 14, 2026

Personal Details of Thousands of Border Patrol and ICE Agents Allegedly Leaked in Huge Data Breach

A whistleblower allegedly released personal data on roughly 4,500 ICE and Border Patrol employees, including about 2,000 frontline agents, after the Jan. 7 shooting of Renee Nicole Good. The leak, posted on the volunteer‑run ICE List site, contains names, work emails,...

By DataBreaches.net
AI Scraping in Mobile Apps: How It Works and How to Stop It
NewsJan 14, 2026

AI Scraping in Mobile Apps: How It Works and How to Stop It

Scraping has migrated from web sites to mobile apps as AI‑driven bots target richer, structured API data. Attackers decompile Android APKs, extract endpoints and credentials, then replay authenticated requests without using the UI. Traditional defenses—rate limits, CAPTCHAs, and token‑based authentication—fail...

By Security Boulevard
CISO Succession Crisis Highlights How Turnover Amplifies Security Risks
NewsJan 13, 2026

CISO Succession Crisis Highlights How Turnover Amplifies Security Risks

Chief Information Security Officers are facing unprecedented turnover, with average tenure now 18‑26 months. Rapid M&A activity forces CISOs to juggle integration, risk, board advising, and crisis management, leading to burnout and a 66% report of excessive expectations. Surveys show...

By Dark Reading
Ukraine's Army Targeted in New Charity-Themed Malware Campaign
NewsJan 13, 2026

Ukraine's Army Targeted in New Charity-Themed Malware Campaign

Ukraine’s Defense Forces were hit by a charity‑themed malware campaign from October to December 2025 that delivered the PluggyApe backdoor. The attacks arrived via Signal or WhatsApp messages promising charitable documents, but instead provided password‑protected PIF archives containing malicious payloads. Ukrainian...

By BleepingComputer
NY: Southold Laserfiche Access Remains Suspended After Cyberattack
NewsJan 13, 2026

NY: Southold Laserfiche Access Remains Suspended After Cyberattack

Southold, New York, has kept its Laserfiche online record‑keeping system offline for more than six weeks after a cyberattack on Nov. 24 compromised its servers. The town announced that public access will remain suspended with no clear restoration timeline. To remediate,...

By DataBreaches.net
Central Maine Healthcare Breach Exposed Data of over 145,000 People
NewsJan 13, 2026

Central Maine Healthcare Breach Exposed Data of over 145,000 People

Central Maine Healthcare suffered a cyber intrusion that lasted from March 19 to June 1, 2024, exposing the personal and health information of 145,381 individuals. The breach affected patients, current and former employees, revealing names, dates of birth, treatment details,...

By BleepingComputer
NDSS 2025 – A Comprehensive Memory Safety Analysis Of Bootloaders
NewsJan 13, 2026

NDSS 2025 – A Comprehensive Memory Safety Analysis Of Bootloaders

Researchers at NDSS 2025 presented the first systematic memory‑safety study of bootloaders, revealing a growing attack surface as these low‑level programs add features. By surveying prior vulnerabilities and building a dedicated fuzzing framework, the team examined nine popular bootloaders and...

By Security Boulevard
New Windows Updates Replace Expiring Secure Boot Certificates
NewsJan 13, 2026

New Windows Updates Replace Expiring Secure Boot Certificates

Microsoft has begun automatically replacing expiring Secure Boot certificates on eligible Windows 11 24H2 and 25H2 devices. The certificates, which protect the pre‑boot environment, are set to expire in June 2026, prompting a phased rollout through Windows quality updates. High‑confidence devices receive the...

By BleepingComputer
FortiOS Vulnerability Allows Remote Code Execution Without Login
NewsJan 13, 2026

FortiOS Vulnerability Allows Remote Code Execution Without Login

Fortinet disclosed a heap‑based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager that allows unauthenticated remote code execution. The flaw can be triggered via crafted network requests, especially on exposed fabric interfaces, and affects versions from 6.4.17 up...

By eSecurity Planet
Man to Plead Guilty to Hacking US Supreme Court Filing System
NewsJan 13, 2026

Man to Plead Guilty to Hacking US Supreme Court Filing System

Nicholas Moore, a 24‑year‑old from Springfield, Tennessee, is set to plead guilty to unauthorized access of the U.S. Supreme Court’s electronic filing system on 25 separate days between August and October 2023. Prosecutors allege he obtained information from a protected...

By TechCrunch (Cybersecurity)
Windows 11 KB5074109 & KB5073455 Cumulative Updates Released
NewsJan 13, 2026

Windows 11 KB5074109 & KB5073455 Cumulative Updates Released

Microsoft released the Windows 11 KB5074109 and KB5073455 cumulative updates for 25H2/24H2 and 23H2, delivering the January 2026 Patch Tuesday security patches. The updates raise build numbers to 26200.7623 (or 26100.7462) and 226x1.6050, and they address a range of vulnerabilities, driver compatibility,...

By BleepingComputer
Microsoft January 2026 Patch Tuesday Fixes 3 Zero-Days, 114 Flaws
NewsJan 13, 2026

Microsoft January 2026 Patch Tuesday Fixes 3 Zero-Days, 114 Flaws

Microsoft released its January 2026 Patch Tuesday update, addressing 114 security flaws across Windows and related services. The bundle includes eight critical vulnerabilities—six remote code execution and two elevation‑of‑privilege bugs—plus one actively exploited information‑disclosure flaw in Desktop Window Manager. Two publicly...

By BleepingComputer
What Is a DNS Attack? Understanding the Risks and Threats
NewsJan 13, 2026

What Is a DNS Attack? Understanding the Risks and Threats

The Domain Name System (DNS) remains a critical yet vulnerable internet backbone, with 88% of organizations reporting at least one DNS attack in 2023. Attacks such as hijacking, cache poisoning, and DDoS floods can redirect users, cause service outages, and...

By The Cyber Express
After Goldman, JPMorgan Discloses Law Firm Data Breach
NewsJan 13, 2026

After Goldman, JPMorgan Discloses Law Firm Data Breach

JPMorgan Chase disclosed to the Maine Attorney General that a data breach at law firm Fried Frank exposed personal information of 659 investors in a private‑equity fund. The breach involved unauthorized copying of files containing names, contact details, account numbers,...

By SecurityWeek