UINAT
NewsRankingsCompaniesGuidesBreachesCompliance
TagsAbout
Home/News

Security News

Breaking cybersecurity news, vulnerability disclosures, and industry updates.

Microsoft Releases Enhanced Security Controls for Copilot for Microsoft 365 Amid Enterprise Data Oversharing Concerns

Microsoft introduces new Purview DLP integration, sensitivity label enforcement, and oversharing assessment tools for Copilot for Microsoft 365, responding to widespread CISO concerns about AI assistants accessing sensitive data through existing permissions.

February 1, 2026 MicrosoftCopilotAI security

CrossCurve DeFi Bridge Exploited for $3M Through Message Validation Bypass

Attackers drained approximately $3 million from CrossCurve's cross-chain bridge by spoofing messages to the ReceiverAxelar contract, which lacked proper validation of cross-chain calls.

February 1, 2026 DeFicryptocurrencybridge exploit

Varonis Finds 'Reprompt' Prompt Injection That Exfiltrates Data From Microsoft Copilot

Varonis discovered a prompt injection attack chain that could steal sensitive data from Microsoft Copilot with a single click, bypassing safety filters through double-request and chain-request techniques. Patched January 13, 2026.

February 1, 2026 MicrosoftCopilotprompt injection

Qilin Ransomware Gang Claims Tulsa International Airport Breach

The Russian-speaking Qilin ransomware group listed Tulsa International Airport as a victim, leaking financial documents, employee IDs, and executive communications in the aviation sector's first reported attack of 2026.

February 1, 2026 ransomwareQilinaviation

GlassWorm: Self-Spreading Malware Hits VS Code Extensions on Open VSX

GlassWorm, a self-propagating worm using Solana blockchain for C2 and invisible Unicode obfuscation, has infected 35,800+ developers through compromised VS Code extensions on Open VSX.

January 31, 2026 supply chain attackVS Codemalware

RedKitten: Iran-Linked Group Targets Human Rights NGOs With AI-Written Macros

HarfangLab uncovered an Iran-linked campaign using AI-generated Office macros and the SloppyMIO backdoor to target activists documenting human rights violations during Iran's 2025-2026 protests.

January 31, 2026 APTIranespionage

CISA 2015 Cybersecurity Information Sharing Authorities Set to Expire

The Cybersecurity Information Sharing Act of 2015 faces expiration on January 30, 2026, despite bipartisan support for 10-year reauthorization. Sen. Rand Paul's objections over unrelated CISA agency concerns block permanent extension.

January 30, 2026 CISAlegislationinformation sharing

CrowdStrike Q4 FY2026 Preview: Charlotte AI and Platform Consolidation Drive Growth

CrowdStrike's fiscal Q4 2026 earnings call scheduled for March 3, 2026, with analysts expecting continued momentum from Falcon platform consolidation, Charlotte AI efficiency gains, and FedRAMP High authorization.

January 30, 2026 CrowdStrikeearningsAI

Ivanti EPMM Zero-Days Chained for Unauthenticated RCE, Already Exploited in the Wild

Two chained Ivanti EPMM vulnerabilities (CVE-2026-1281 and CVE-2026-1340, both CVSS 9.8) allow unauthenticated RCE via Bash command injection. CISA gave federal agencies only 3 days to patch.

January 30, 2026 Ivantizero-dayvulnerability

GootLoader Uses 500-1,000 Concatenated ZIP Archives to Evade Detection

The GootLoader malware loader now creates malformed ZIP files containing hundreds of concatenated archives, causing security tools to extract harmless files while Windows extracts malicious JavaScript.

January 30, 2026 GootLoadermalwareevasion

eScan Antivirus Update Server Breached, Trojanized Updates Distributed to Customers

Attackers compromised an eScan regional update server on January 20, 2026, distributing signed malicious updates that deployed a multi-stage backdoor. IOCs and detection guidance included.

January 29, 2026 supply chainantiviruseScan

Fake AI Coding Assistant on VS Code Marketplace Drops ScreenConnect RAT

A malicious VS Code extension posing as an AI coding assistant deploys ConnectWise ScreenConnect for persistent remote access using quadruple impersonation tactics and Rust-based backup delivery.

January 29, 2026 VS Codemalwaresupply chain
‹ Prev
1234…9
Next ›
SYS ONLINE
PAGES 963
UPDATED 2026-02-06
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

// Sections

  • › News
  • › Rankings
  • › Companies
  • › Breaches

// Resources

  • › Guides
  • › Compliance
  • › Tags
  • › About

// Feeds

  • › All Content
  • › News Only
  • › Breaches Only

> © 2026 UINAT. All rights reserved.

[ DEFEND THE PERIMETER ]

Search