loader image
Microsoft SQL Server Flaw Lets Attackers Elevate

A newly disclosed Microsoft SQL Server flaw may allow attackers with existing access to escalate their privileges across a network. Microsoft addressed the vulnerability, tracked as CVE-2026-20803, in a security update released on January 13, 2026. The flaw affects SQL Server installations and lets authorized users bypass authentication controls. If exploited, the issue could enable […]

Palo Alto Networks Patches Firewall DoS Flaw

Palo Alto Networks patches a firewall bug that attackers could exploit to disrupt GlobalProtect gateways, according to a recent advisory. The flaw, identified as CVE-2026-0227, affects PAN-OS, the company’s operating system used in its firewall appliances. It allows unauthenticated users to launch denial-of-service (DoS) attacks, potentially rendering network infrastructure inaccessible. The vulnerability stems from how […]

BreachForums User Database Leaked

The breachforums user database leaked online this week, exposing the identities and activities of users once shielded by the platform’s dark web anonymity. On January 9, 2026, cybersecurity researchers uncovered that the entire user database from one of the most infamous underground marketplaces was compromised and made publicly downloadable. This leak has turned the tables […]

WEF Warns AI, Geopolitics Reshape Cyber Threats

The World Economic Forum’s Global Cybersecurity Outlook 2026 warns that rapid artificial intelligence development and intensifying geopolitical tensions are reshaping the global cybersecurity landscape. As AI systems proliferate across industries, WEF warns AI could amplify both the scale and sophistication of cyber threats, increasing risks for governments, businesses, and individuals alike. The report highlights growing […]

Endesa Says Full Customer Data Exposed in Breach

Endesa says a cyberattack exposed sensitive customer data after an unauthorized party accessed its commercial platform. The Spanish electricity giant reported that attackers may have obtained identification details, contract data, national ID numbers, and possibly bank account numbers, but no passwords. Endesa, which serves over 10 million customers and reported €21.3 billion in revenue in […]

Uganda Cuts Internet, Proton Signups Jump 8,000%

Uganda cuts internet access nationwide just days before its January 15 election, despite earlier assurances from officials that no blackout would occur. Authorities suspended public connectivity to curb what they described as “misinformation” and “electoral fraud.” The move came after Uganda’s communications regulator ordered restrictions on roaming calls and new SIM cards, fueling concerns among […]

Ukraine Army Hit by Charity-Themed Malware

A recent cyber campaign targeting Ukraine’s Defense Forces has exposed new vulnerabilities in military digital infrastructure. Between October and December 2023, unidentified threat actors disguised malware delivery under the pretense of charitable aid, deploying a backdoor dubbed PluggyApe. This incident marks the latest in a series of sophisticated cyberattacks exploiting social engineering tactics to infiltrate […]

AZ Monica Hospital Shuts Servers After Cyberattack

A cyberattack forced Belgium’s AZ Monica hospital to shut down its servers early Wednesday morning, disrupting medical services and prompting the transfer of several critical patients. The hospital, which operates two campuses in Antwerp and Deurne, specializes in acute and outpatient care and disconnected its systems precisely at 6:32 a.m. in response to the breach. […]

Angular Flaw Lets Attackers Execute Code

A newly disclosed Angular flaw enables code execution attacks by allowing the injection of malicious scripts through a critical vulnerability in Angular’s Template Compiler. Identified as CVE-2026-22610, the flaw affects multiple versions of the @angular/compiler and @angular/core packages, compromising the framework’s security measures. The vulnerability originates in Angular’s internal sanitization process, which fails to adequately […]

n8n Nodes Compromised by Malicious npm Package

Hackers have compromised n8n nodes by exploiting a weaponized npm package posing as a legitimate Google Ads integration. The malicious package mimicked authentic functionality, tricking developers into entering their OAuth credentials. Once input, the data was exfiltrated to an attacker-controlled server during routine workflow execution. Researchers at EndorLabs uncovered eight malicious packages targeting the automation […]

Endesa Says Hackers Accessed Customer Contracts

Spanish utility provider Endesa says hackers accessed data from its systems in a recent security breach impacting both the main company and its regulated retailer, Energía XXI. The attack exposed contract-related information that includes customers’ personal details, according to notices the company is now sending to affected individuals. Endesa has not disclosed how many customers […]

Europol, Spain Police Arrest 34 in Black Axe Raid

Europol announced the arrest of 34 individuals in Spain tied to the Black Axe criminal group after a joint crackdown with Spanish police and Bavarian authorities. The operation focused heavily on Seville, with additional arrests in Madrid, Málaga and Barcelona. Black Axe, a highly organized syndicate rooted in Nigeria, engages in cyber fraud, trafficking and […]