Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088

28/01/2026 0 Comments 0 tags

Google on Tuesday revealed that multiple threat actors, including nation-state adversaries and financially motivated groups, are exploiting a now-patched critical security flaw in RARLAB WinRAR to establish initial access and

Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan

28/01/2026 0 Comments 0 tags

Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that masquerade as spellcheckers but contain functionality to deliver a remote access trojan (RAT). The packages,

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

28/01/2026 0 Comments 0 tags

Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-24858 (CVSS

ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services

27/01/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a new campaign that combines ClickFix-style fake CAPTCHAs with a signed Microsoft Application Virtualization (App-V) script to distribute an information stealer called Amatera. “Instead

CTEM in Practice: Prioritization, Validation, and Outcomes That Matter

27/01/2026 0 Comments 0 tags

Cybersecurity teams increasingly want to move beyond looking at threats and vulnerabilities in isolation. It’s not only about what could go wrong (vulnerabilities) or who might attack (threats), but where

Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

27/01/2026 0 Comments 0 tags

A critical security flaw has been disclosed in Grist‑Core, an open-source, self-hosted version of the Grist relational spreadsheet-database, that could result in remote code execution. The vulnerability, tracked as CVE-2026-24002

China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023

27/01/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a JScript-based command-and-control (C2) framework called PeckBirdy that has been put to use by China-aligned APT actors since 2023 to target multiple environments. The flexible framework

WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware

27/01/2026 0 Comments 0 tags

Meta on Tuesday announced it’s adding Strict Account Settings on WhatsApp to secure certain users against advanced cyber attacks because of who they are and what they do. The feature,

Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

27/01/2026 0 Comments 0 tags

Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft. The campaigns have been codenamed Gopher Strike and

Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation

27/01/2026 0 Comments 0 tags

Microsoft on Monday issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability exploited in attacks. The vulnerability, tracked as CVE-2026-21509, carries a CVSS score of 7.8 out of