UINAT
NewsRankingsCompaniesGuidesCompliance
Home/News

Security News

Breaking cybersecurity news, vulnerability disclosures, and industry updates.

Critical D-Link Router Vulnerability Actively Exploited for Remote Code Execution

CVE-2026-0625 enables unauthenticated remote code execution on legacy D-Link DSL routers via DNS configuration endpoint. No patch available for EOL devices.

January 28, 2026 D-LinkvulnerabilityRCE

Critical Fortinet FortiOS SSO Vulnerability Under Active Exploitation

CVE-2026-24858 is a critical authentication bypass flaw in FortiOS single sign-on with a CVSS score of 9.4. Patches are now available.

January 28, 2026 Fortinetzero-dayvulnerability

Malicious PyPI Packages Masquerading as Spellcheckers Deliver RAT Malware

Packages 'spellcheckerpy' and 'spellcheckpy' downloaded over 1,000 times before removal from Python Package Index.

January 28, 2026 supply chainPyPImalware

Iranian MuddyWater APT Deploys New Rust-Based 'RustyWater' Implant

Spear-phishing campaign targets diplomatic, maritime, financial, and telecom entities across the Middle East with upgraded malware toolkit.

January 28, 2026 APTIranMuddyWater

Ransomware Attacks Surge 45% in 2025 with Over 9,200 Cases Recorded

NordStellar research reveals US companies remain primary targets with 3,255 incidents. Small and medium businesses face the highest risk.

January 28, 2026 ransomwareresearchstatistics

Two US Cybersecurity Professionals Plead Guilty to BlackCat Ransomware Charges

Former security workers admitted to operating as BlackCat/ALPHV affiliates, paying 20% of ransoms to administrators for malware access.

January 28, 2026 ransomwareBlackCatALPHV

China-Linked Mustang Panda Deploys Updated COOLCLIENT Backdoor Against Governments

APT group targets government entities with enhanced malware enabling comprehensive data theft from infected endpoints.

January 28, 2026 APTChinaMustang Panda

Critical n8n Workflow Automation Flaw Allows Remote Code Execution

CVE-2026-1470 scores CVSS 9.9 with eval injection vulnerability enabling attackers to execute arbitrary code on n8n servers.

January 28, 2026 vulnerabilityn8nRCE

Oracle January 2026 Critical Patch Update Addresses 337 Vulnerabilities

Massive security update includes 38 patches for Financial Services Applications, with 33 remotely exploitable without authentication.

January 28, 2026 Oraclepatchvulnerability

Researchers Expose Industrial-Scale 'Pig Butchering' Fraud Infrastructure

Investigation reveals service providers fueling Southeast Asian scam compounds where trafficking victims are forced to conduct investment fraud.

January 28, 2026 fraudscampig butchering

SAP Patches Critical SQL Injection in S/4HANA with CVSS 9.9 Score

January 2026 Security Patch Day releases 17 notes including four critical vulnerabilities affecting enterprise ERP systems.

January 28, 2026 SAPSQL injectionpatch

Critical WordPress Plugin Vulnerability Actively Exploited in the Wild

CVE-2026-23550 in Modular DS plugin scores maximum CVSS 10.0, enabling unauthenticated privilege escalation on WordPress sites.

January 28, 2026 WordPressvulnerabilityexploitation

Microsoft Releases Emergency Patch for Actively Exploited Office Zero-Day

CVE-2026-21509 bypasses OLE mitigations in Microsoft Office and Microsoft 365. CISA has added the flaw to its KEV catalog with a February 16 deadline.

January 27, 2026 Microsoftzero-dayvulnerability

Blue Shield of California Notifies Members of Healthcare Data Breach

Protected health information potentially exposed including names, dates of birth, claims data, diagnoses, and medication information.

January 27, 2026 healthcaredata breachHIPAA

European Space Agency Confirms Data Breach, Over 200GB of Data Stolen

Attackers exfiltrated API tokens, Bitbucket repositories, and source code from ESA servers. Investigation ongoing.

January 27, 2026 data breachESAsource code

Russia's Fancy Bear APT Runs Low-Cost Credential Harvesting Campaign Against Global Targets

APT28 targets organizations in the Balkans, Middle East, and Central Asia with simple but effective phishing attacks using legitimate documents.

January 27, 2026 APTRussiaFancy Bear

Claims Management Giant Sedgwick Hit by TridentLocker Ransomware

Attackers claim to have exfiltrated sensitive data from systems supporting government services operations at one of the world's largest claims administrators.

January 27, 2026 ransomwaredata breachinsurance

Belgian Hospital Shuts Down Systems After Cyberattack, Transfers Critical Patients

AZ Monica hospital in Antwerp forced to cancel procedures and move patients to other facilities following security incident.

January 27, 2026 healthcareransomwareBelgium

ClickFix Attacks Combine Fake CAPTCHAs with Signed Microsoft Scripts to Deploy Stealer

New campaign uses social engineering and legitimate Microsoft Application Virtualization scripts to distribute Amatera information stealer.

January 27, 2026 malwaresocial engineeringinfostealer

Critical 'Cellbreak' Vulnerability in Grist Spreadsheet Platform Enables RCE

CVE-2026-24002 allows remote code execution through malicious spreadsheet formulas in popular open-source data tool.

January 27, 2026 vulnerabilityRCEGrist

Microsoft Disrupts RedVDS Cybercrime Service Behind Millions in Fraud

Coordinated action with UK, German authorities, and Europol takes down subscription service offering disposable VMs for $24/month to criminals.

January 27, 2026 Microsoftcybercrimefraud

CISA Adds Five Vulnerabilities to KEV Catalog Including Microsoft Office Zero-Day

New additions include CVE-2026-21509, a Linux kernel flaw from 2018, and SmarterMail vulnerabilities. Federal agencies face February deadlines.

January 26, 2026 CISAKEVvulnerabilities

Data Privacy Week 2026 Launches with 'Take Control of Your Data' Theme

The National Cybersecurity Alliance kicks off Data Privacy Week from January 26-30, focusing on empowering individuals and organizations to manage personal information.

January 26, 2026 privacyawarenesscompliance

Microsoft January 2026 Patch Tuesday: 114 Vulnerabilities Fixed, One Actively Exploited

Monthly security update addresses 114 CVEs including CVE-2026-20805, a Windows Desktop Window Manager flaw under active exploitation.

January 13, 2026 MicrosoftPatch Tuesdayvulnerabilities
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

Sections

  • News
  • Rankings
  • Companies

Resources

  • Guides
  • Compliance
  • RSS Feed

© 2026 UINAT. All rights reserved.

RSS