Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited

Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability that it said has been actively exploited in the wild.
Of the 114 flaws, eight are rated Critical, and 106 are rated Important… Continue reading Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited

Posted in Uncategorized

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Node.js has released updates to fix what it described as a critical security issue impacting “virtually every production Node.js app” that, if successfully exploited, could trigger a denial-of-service (DoS) condition.
“Node.js/V8 makes a best-effort at… Continue reading Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Posted in Uncategorized

PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of new cyber attacks targeting its defense forces with malware known as PLUGGYAPE between October and December 2025.
The activity has been attributed with medium confidence… Continue reading PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces

Posted in Uncategorized

Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages

Cybersecurity researchers have discovered a major web skimming campaign that has been active since January 2022, targeting several major payment networks like American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay.
“Enterprise… Continue reading Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages

Posted in Uncategorized

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Cybersecurity researchers have disclosed details of a malicious Google Chrome extension that’s capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX) available in over 170 countries, while masquerading as a tool … Continue reading Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Posted in Uncategorized

[Webinar] Securing Agentic AI: From MCPs and Tool Access to Shadow API Key Sprawl

AI agents are no longer just writing code. They are executing it.
Tools like Copilot, Claude Code, and Codex can now build, test, and deploy software end-to-end in minutes. That speed is reshaping engineering—but it’s also creating a security gap most … Continue reading [Webinar] Securing Agentic AI: From MCPs and Tool Access to Shadow API Key Sprawl

Posted in Uncategorized

New Advanced Linux VoidLink Malware Targets Cloud and container Environments

Cybersecurity researchers have disclosed details of a previously undocumented and feature-rich malware framework codenamed VoidLink that’s specifically designed for long-term, stealthy access to Linux-based cloud environments
According to a new report … Continue reading New Advanced Linux VoidLink Malware Targets Cloud and container Environments

Posted in Uncategorized

ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation

ServiceNow has disclosed details of a now-patched critical security flaw impacting its ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform arbitrary actions as that user.
The vulnerability, tracked a… Continue reading ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation

Posted in Uncategorized