113Articles
9Categories
2026-01-07Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.  CVE-2009-0556 Microsoft Office PowerPoint Code Injection Vulnerability CVE-2025-37164 HPE OneView Code Injection Vulnerability  These…
KEV
πŸ›
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers
πŸ›
CVE-2025-4432 Ring: some aes functions may panic when overflow checking is enabled in ring
πŸ›
Google Warns of High-Risk WebView Vulnerability That Breaks Security Controls
πŸ›
CVE-2025-1744 Out-of-bounds Write in radare2
πŸ›
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions
πŸ›
Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
πŸ›
Bug in Open WebUI macht Kostenlos-Tool zur Backdoor
πŸ›
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control
πŸ›
Critical RCE flaw allows full takeover of n8n AI workflow platform
πŸ›
Critical n8n Vulnerability Allows Authenticated Remote Code Execution
πŸ›
CVE-2025-68285 libceph: fix potential use-after-free in have_mon_and_osd_map()
πŸ›
CVE-2025-68290 most: usb: fix double free on late probe failure
πŸ›
CVE-2025-68331 usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
πŸ›
CVE-2025-68327 usb: renesas_usbhs: Fix synchronous external abort on unbind
πŸ›
CVE-2025-68330 iio: accel: bmc150: Fix irq assumption regression
πŸ›
CVE-2025-68282 usb: gadget: udc: fix use-after-free in usb_gadget_state_work
πŸ›
CVE-2025-68283 libceph: replace BUG_ON with bounds check for map->max_osd
πŸ›
CVE-2025-68307 can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs
πŸ›
CVE-2025-68286 drm/amd/display: Check NULL before accessing
πŸ›
CVE-2025-68295 smb: client: fix memory leak in cifs_construct_tcon()
πŸ›
CVE-2025-68288 usb: storage: Fix memory leak in USB bulk transport
πŸ›
CVE-2025-68284 libceph: prevent potential out-of-bounds writes in handle_auth_session_key()
πŸ›
CVE-2025-68308 can: kvaser_usb: leaf: Fix potential infinite loop in command parsers
πŸ›
CVE-2025-68287 usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths
πŸ›
CVE-2025-68289 usb: gadget: f_eem: Fix memory leak in eem_unwrap
πŸ›
CVE-2025-68302 net: sxgbe: fix potential NULL dereference in sxgbe_rx()
πŸ›
CVE-2025-68328 firmware: stratix10-svc: fix bug in saving controller data
πŸ›
CVE-2025-68339 atm/fore200e: Fix possible data race in fore200e_open()
πŸ›
CVE-2025-68342 can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data
πŸ›
CVE-2025-68343 can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header
πŸ›
CVE-2025-62224 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
⚠️
Cybersecurity hat kein Budget-Problem
⚠️
8 things CISOs can’t afford to get wrong in 2026
⚠️
Veeam Backup Vulnerability Exposes Systems to Root-Level Remote Code Execution
⚠️
Black Cat Hacker Group Uses Fake Notepad++ Websites to Distribute Malware and Steal Data
⚠️
Hackers Exploit Routing Misconfigurations to Successfully Spoof Organizations
⚠️
CISO Lessons from a Children’s Novel as Cybersecurity Outgrows IT and Building Talent - BSW #429
⚠️
Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing
⚠️
Complex Routing, Misconfigurations Exploited for Domain Spoofing in Phishing Attacks
⚠️
Microsoft warns of a surge in phishing attacks exploiting email routing gaps
⚠️
Critical Dolby Vulnerability Patched in Android - SecurityWeek
⚠️
New D-Link flaw in legacy DSL routers actively exploited in attacks
KEV
⚠️
Hackers Exploit Zero-Day in Discontinued D-Link Devices
⚠️
New Veeam vulnerabilities expose backup servers to RCE attacks
⚠️
Veeam Backup Vulnerabilities Enable Remote Code Execution as Root
⚠️
Vulnerability in Totolink Range Extender Allows Device Takeover
⚠️
How to eliminate IT blind spots in the modern, AI-driven enterprise
⚠️
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions
⚠️
Max severity Ni8mare flaw lets hackers hijack n8n servers
⚠️
Chinese Hackers Use NFC-Enabled Android Malware to Steal Payment Information
⚠️
TOTOLINK EX200 Extender Flaw Allows AttackersΒ Full System Access
⚠️
Threat Actors Exploit Google Cloud Services to Steal Microsoft 365 Credentials
⚠️
ToddyCat Malware Exploits ProxyLogon to Compromise Microsoft Exchange Servers
⚠️
Critical jsPDF flaw lets hackers steal secrets via generated PDFs
⚠️
New GoBruteforcer attack wave targets crypto, blockchain projects
πŸ“’
Automated data poisoning proposed as a solution for AI theft threat
πŸ“’
Sedgwick Acknowledges Data Breach After TridentLocker Ransomware Claim
πŸ“’
Google Chrome security advisory (AV26-002)
πŸ“’
GitHub security advisory (AV26-003)
πŸ“’
n8n security advisory (AV26-004)
πŸ“’
Android security advisory – January 2026 monthly rollup (AV26-005)
πŸ“’
Samsung mobile security advisory (AV26-007)
πŸ“’
Qualcomm security advisory – January 2026 monthly rollup (AV26-006)
πŸ“’
Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches
πŸ“’
Veeam security advisory (AV26-008)
πŸ”₯
FΓΌr Cyberattacken gewappnet – Krisenkommunikation nach Plan
πŸ”₯
Kimwolf Bot Strikes - "Routers Will Not Protect You"
πŸ”₯
Weekly Update 485
πŸ”₯
Malicious Chrome Extension Leaks ChatGPT and DeepSeek Chats of 900,000 Users
πŸ”₯
ownCloud urges users to enable MFA after credential theft reports
πŸ”₯
Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats
πŸ”₯
Neue Ransomware-Bedrohung zielt auf deutsche Unternehmen
πŸ”₯
Explore the latest Microsoft Incident Response proactive services for enhanced resilience
πŸ”₯
Hackers Claim to Disconnect Brightspeed Customers After Breach - Infosecurity Magazine
πŸ”₯
CrazyHunter Ransomware Targets Healthcare Sector Using Sophisticated Evasion Tactics
πŸ”₯
LockBit 5.0 Unveils Advanced Encryption and Enhanced Anti-Analysis Techniques
πŸ•΅οΈ
ISC Stormcast For Wednesday, January 7th, 2026 https://isc.sans.edu/podcastdetail/9756, (Wed, Jan 7th)
πŸ•΅οΈ
Court Demands OpenAI Hand Over 20M Anonymized ChatGPT Chats in AI Copyright Dispute
πŸ•΅οΈ
Hackers Create Fake DocuSign Login Page to Steal User Credentials
πŸ•΅οΈ
High-Severity Flaw in Open WebUI Affects AI Connections
πŸ•΅οΈ
Hospitality Sector Hit By PHALT#BLYX ClickFix Malware Campaign
πŸ•΅οΈ
Coinbase insider who sold customer data to criminals arrested in India
πŸ•΅οΈ
The Wegman’s Supermarket Chain Is Probably Using Facial Recognition
πŸ•΅οΈ
Microsoft most spoofed brand in phishing attacks | Cybernews
πŸ•΅οΈ
Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers
πŸ•΅οΈ
Cybersecurity Firms Secured $14 Billion in Funding in 2025
πŸ•΅οΈ
UK Launches New Cyber Unit to Bolster Defences Against Cyber Threats - Infosecurity Magazine
πŸ•΅οΈ
Several Code Execution Flaws Patched in Veeam Backup & Replication
πŸ•΅οΈ
Your Phone Remembers Everything
πŸ•΅οΈ
The Loudest Voices in Security Often Have the Least to Lose
πŸ•΅οΈ
In 2026, Hackers Want AI: Threat Intel on Vibe Hacking & HackGPT
πŸ•΅οΈ
Embrace Your Unique Edge
πŸ•΅οΈ
Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud - Infosecurity Magazine
πŸ•΅οΈ
Hackers Using Malicious QR Codes for Phishing via HTML Table
πŸ•΅οΈ
Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns with Multiple Malware
πŸ•΅οΈ
Chinese Hackers Launch Ongoing Attacks on Taiwan’s Critical Infrastructure
πŸ•΅οΈ
North Korean Threat Actor Spreads Malware via QR Codes
πŸ•΅οΈ
AI: The New Threat to Privacy
🌐
Webinar: Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators
πŸŽ™οΈ
How the World Got Owned Episode 1: The 1980s
πŸ“‘
Im Fokus: Die IT-Agenda 2026 gestalten
πŸ“‘
A phishing campaign with QR codes rendered using an HTML table, (Wed, Jan 7th)
πŸ“‘
UK announces plan to strengthen public sector cyber defenses
πŸ“‘
The Future of Cybersecurity Includes Non-Human Employees
πŸ“‘
Google Search AI hallucinations push Google to hire "AI Answers Quality" engineers
πŸ“‘
Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem
πŸ“‘
Microsoft: Classic Outlook bug prevents opening encrypted emails
πŸ“‘
Logitech Options+, G HUB macOS apps break after certificate expires
πŸ“‘
ChatGPT is losing market share as Google Gemini gains ground
πŸ“‘
OpenAI says ChatGPT won't use your health information to train its models
πŸ“‘
Weekly Threat Bulletin – January 7th, 2026
πŸ“‘
GRU-Linked BlueDelta Evolves Credential Harvesting