China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure

16/01/2026 0 Comments 0 tags

A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year. Cisco Talos, which is tracking the activity under

LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing

16/01/2026 0 Comments 0 tags

Security experts have disclosed details of a new campaign that has targeted U.S. government and policy entities using politically themed lures to deliver a backdoor known as LOTUSLITE. The targeted

Your Digital Footprint Can Lead Right to Your Front Door

16/01/2026 0 Comments 0 tags

You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media. But what about the information about you that’s already out

Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways

16/01/2026 0 Comments 0 tags

Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, nearly a month

AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks

15/01/2026 0 Comments 0 tags

A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service provider’s own GitHub repositories, including its AWS JavaScript SDK, putting every AWS

Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot

15/01/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a new attack method dubbed Reprompt that could allow bad actors to exfiltrate sensitive data from artificial intelligence (AI) chatbots like Microsoft Copilot in

Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access

15/01/2026 0 Comments 0 tags

A maximum-severity security flaw in a WordPress plugin called Modular DS has come under active exploitation in the wild, according to Patchstack. The vulnerability, tracked as CVE-2026-23550 (CVSS score: 10.0),

ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories

15/01/2026 0 Comments 0 tags

The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn

Model Security Is the Wrong Frame – The Real Risk Is Workflow Security

15/01/2026 0 Comments 0 tags

As AI copilots and assistants become embedded in daily work, security teams are still focused on protecting the models themselves. But recent incidents suggest the bigger risk lies elsewhere: in

4 Outdated Habits Destroying Your SOC’s MTTR in 2026

15/01/2026 0 Comments 0 tags

It’s 2026, yet many SOCs are still operating the way they did years ago, using tools and processes designed for a very different threat landscape. Given the growth in volumes