⤷ Title: “Update” to Nightmare: eScan Antivirus Hacked to Distribute Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 02:15:55 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Compromise #cyber attack #eScan #infosec #malware #Manual Patch #MicroWorld Technologies #Morphisec #Reload.exe #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 02:15:55 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Compromise #cyber attack #eScan #infosec #malware #Manual Patch #MicroWorld Technologies #Morphisec #Reload.exe #supply chain attack
Daily CyberSecurity
"Update" to Nightmare: eScan Antivirus Hacked to Distribute Malware
Critical supply chain attack hits eScan antivirus. Hackers hijacked updates to install malware and disable the AV. Manual patch required.
⤷ Title: Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:59:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #building automation #CISA #Critical Vulnerability #CVE_2025_26385 #ICS security #Johnson Controls #Metasys #Smart Building #sql injection #TCP 1433
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:59:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #building automation #CISA #Critical Vulnerability #CVE_2025_26385 #ICS security #Johnson Controls #Metasys #Smart Building #sql injection #TCP 1433
Daily CyberSecurity
Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
CISA warns of CVSS 10 flaw CVE-2025-26385 in Johnson Controls Metasys. Remote SQL execution possible. Patch now or close TCP port 1433.
⤷ Title: Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:52:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #exploited in the wild #Ivanti EPMM #MDM #mobile security #MobileIron Core #rce #Remote Code Execution #unauthenticated RCE #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:52:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #exploited in the wild #Ivanti EPMM #MDM #mobile security #MobileIron Core #rce #Remote Code Execution #unauthenticated RCE #zero_day
Daily CyberSecurity
Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack
Ivanti confirms critical EPMM RCE flaws (CVE-2026-1281) are exploited in the wild. Unauthenticated attackers can compromise MDM. Patch immediately.
⤷ Title: Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:27:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admission Controller #cloud_native #CVE_2026_22039 #CVE_2026_23881 #DevSecOps #dos #K8s #Kubernetes Security #Kyverno #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:27:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admission Controller #cloud_native #CVE_2026_22039 #CVE_2026_23881 #DevSecOps #dos #K8s #Kubernetes Security #Kyverno #privilege escalation
Daily CyberSecurity
Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
Critical Kyverno flaw CVE-2026-22039 (CVSS 10) allows policy creators to gain cluster admin rights. Update to v1.16.3 to fix privilege escalation & DoS.
⤷ Title: “SessionReaper” Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:21:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #API vulnerability #CVE_2025_54236 #e_commerce security #Magento #Oasis Security #root access #Session Hijacking #SessionReaper #Web Shells
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:21:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #API vulnerability #CVE_2025_54236 #e_commerce security #Magento #Oasis Security #root access #Session Hijacking #SessionReaper #Web Shells
Daily CyberSecurity
"SessionReaper" Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites
"SessionReaper" (CVE-2025-54236) targets Magento stores. Attackers use zombie tokens to gain root access. 200+ sites compromised. Patch now.
⤷ Title: Scam Alert: “Amazon Ads Blocker” Extension Hijacks Creator Commissions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:16:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #10xprofit_20 #adware #Affiliate Hijacking #Affiliate Marketing #Amazon Ads Blocker #Chrome extension #Creator Revenue #google chrome #Malicious Extension #Socket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:16:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #10xprofit_20 #adware #Affiliate Hijacking #Affiliate Marketing #Amazon Ads Blocker #Chrome extension #Creator Revenue #google chrome #Malicious Extension #Socket Security
Daily CyberSecurity
Scam Alert: "Amazon Ads Blocker" Extension Hijacks Creator Commissions
"Amazon Ads Blocker" extension exposed for stealing creator revenue. It hijacks affiliate links to divert commissions to the developer. Uninstall it now.
⤷ Title: Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:13:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2025_33217 #CVE_2025_33220 #GPU Driver #Linux Security #nvidia #privilege escalation #use after free #vGPU #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:13:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2025_33217 #CVE_2025_33220 #GPU Driver #Linux Security #nvidia #privilege escalation #use after free #vGPU #Windows Security
Daily CyberSecurity
Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws
NVIDIA patches high-severity flaws (CVE-2025-33217) in GPU drivers & vGPU software. Flaws allow code execution. Update Windows/Linux drivers now.
⤷ Title: The “WorkMail Pivot”: Hackers Abuse AWS WorkMail to Bypass SES Sandbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
Daily CyberSecurity
The "WorkMail Pivot": Hackers Abuse AWS WorkMail to Bypass SES Sandbox
Attackers are bypassing AWS SES sandbox limits by pivoting to WorkMail. Rapid7 reveals how this abuse creates a blind spot for defenders.
⤷ Title: The Great Recalibration: Amazon Cuts 16,000 More Roles in Massive Shift to AI-First Future
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:06:37 +0000
════════════════════════
⌗ Tags: #Technology #Amazon #Amazon Jobs #artificial intelligence #Beth Galetti #Corporate Restructuring #Future of Work #Generative AI #Layoffs 2026 #Tech News #Workforce Reduction
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:06:37 +0000
════════════════════════
⌗ Tags: #Technology #Amazon #Amazon Jobs #artificial intelligence #Beth Galetti #Corporate Restructuring #Future of Work #Generative AI #Layoffs 2026 #Tech News #Workforce Reduction
Daily CyberSecurity
The Great Recalibration: Amazon Cuts 16,000 More Roles in Massive Shift to AI-First Future
Amazon confirms 16,000 new layoffs in Jan 2026, completing a 30,000-person cut. Discover how the titan is swapping managers for Generative AI tech.
⤷ Title: The AI Squeeze: NVIDIA Overtakes Apple as TSMC’s Top Revenue Source
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:03:27 +0000
════════════════════════
⌗ Tags: #Technology #A19 chip #AI Infrastructure #Apple #Blackwell GPU #CoWoS #data centers #Jensen Huang #nvidia #Semiconductor News 2026 #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:03:27 +0000
════════════════════════
⌗ Tags: #Technology #A19 chip #AI Infrastructure #Apple #Blackwell GPU #CoWoS #data centers #Jensen Huang #nvidia #Semiconductor News 2026 #TSMC
Daily CyberSecurity
The AI Squeeze: NVIDIA Overtakes Apple as TSMC’s Top Revenue Source
NVIDIA replaces Apple as TSMC's largest customer in Jan 2026. Discover how the $33B AI chip boom is rewriting the rules of the silicon industry.
⤷ Title: The Fake Region Block: YouTube’s Cryptic New War on Ad-Blockers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:00:05 +0000
════════════════════════
⌗ Tags: #Technology #Ad Blocker #AdGuard #Anti_Adblock 2026 #google #Reddit Workaround #Tech Frustration #uBlock Origin #Video Unavailable #XHR Filtering #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:00:05 +0000
════════════════════════
⌗ Tags: #Technology #Ad Blocker #AdGuard #Anti_Adblock 2026 #google #Reddit Workaround #Tech Frustration #uBlock Origin #Video Unavailable #XHR Filtering #youtube
Daily CyberSecurity
The Fake Region Block: YouTube’s Cryptic New War on Ad-Blockers
YouTube is faking regional blocks to break ad-blockers in Jan 2026! Discover the "technical frustration" strategy behind the new "unavailable" errors.
⤷ Title: Locked Out of the Crate: Microsoft’s “Smart” Security Cripples ASUS ROG Ally
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:30:22 +0000
════════════════════════
⌗ Tags: #Windows #Armoury Crate #ASUS #Driver Signing #false positive #Gaming News 2026 #infosec #Microsoft Defender #ROG Ally #Smart App Control #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:30:22 +0000
════════════════════════
⌗ Tags: #Windows #Armoury Crate #ASUS #Driver Signing #false positive #Gaming News 2026 #infosec #Microsoft Defender #ROG Ally #Smart App Control #Windows 11
Daily CyberSecurity
Locked Out of the Crate: Microsoft’s "Smart" Security Cripples ASUS ROG Ally
Microsoft Defender's Smart App Control is blocking ASUS Armoury Crate in Jan 2026. Learn why your ROG Ally controls are broken and how to fix it.
⤷ Title: The Final Hang-Up: Microsoft Disables Legacy Modem Drivers for Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:24:32 +0000
════════════════════════
⌗ Tags: #Windows #Agere Systems #CVE_2023_31096 #CVE_2025_24052 #Dial_up Modem #Driver Security #InfoSec 2026 #KB5074109 #Motorola SM56 #Patch Tuesday #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:24:32 +0000
════════════════════════
⌗ Tags: #Windows #Agere Systems #CVE_2023_31096 #CVE_2025_24052 #Dial_up Modem #Driver Security #InfoSec 2026 #KB5074109 #Motorola SM56 #Patch Tuesday #Windows 11
Daily CyberSecurity
The Final Hang-Up: Microsoft Disables Legacy Modem Drivers for Security
Windows 11 intentionally kills dial-up modems in Jan 2026! Discover why Microsoft removed Agere and Motorola drivers to fix critical security flaws.
⤷ Title: The $799 Gamble: Apple Absorbs Memory Costs to Freeze iPhone 18 Prices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:19:37 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Apple Services #DRAM Crisis #InfoSec 2026 #iPhone 18 #LPDDR5X #Ming_Chi Kuo #NAND Flash #Smartphone Prices 2026 #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:19:37 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Apple Services #DRAM Crisis #InfoSec 2026 #iPhone 18 #LPDDR5X #Ming_Chi Kuo #NAND Flash #Smartphone Prices 2026 #Supply Chain
Daily CyberSecurity
The $799 Gamble: Apple Absorbs Memory Costs to Freeze iPhone 18 Prices
Ming-Chi Kuo predicts iPhone 18 prices will stay flat in 2026. Discover how Apple plans to absorb rising memory costs to crush its competition.
⤷ Title: The Instant Browser: Google Tests New Auto-Launch Toggle for Chrome
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:13:50 +0000
════════════════════════
⌗ Tags: #Technology #Boot Speed #Chrome Canary #Gemini AI #google chrome #macOS #PC Maintenance #RAM Management #Startup Settings #Tech News 2026 #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:13:50 +0000
════════════════════════
⌗ Tags: #Technology #Boot Speed #Chrome Canary #Gemini AI #google chrome #macOS #PC Maintenance #RAM Management #Startup Settings #Tech News 2026 #Windows 11
Daily CyberSecurity
The Instant Browser: Google Tests New Auto-Launch Toggle for Chrome
Google Chrome is testing a new auto-launch toggle in Jan 2026. Learn how to enable the foreground startup feature for near-instant boot response.
⤷ Title: The Insider Exit Ramp: Why You Should Switch Windows 11 Channels Now
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:04:30 +0000
════════════════════════
⌗ Tags: #Windows #Beta Channel #Build 26300.7674 #Canary Channel #Dev Channel #Microsoft #OS Updates #PC Maintenance #Windows 11 #Windows 11 Tips #Windows Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 08:04:30 +0000
════════════════════════
⌗ Tags: #Windows #Beta Channel #Build 26300.7674 #Canary Channel #Dev Channel #Microsoft #OS Updates #PC Maintenance #Windows 11 #Windows 11 Tips #Windows Insider
Daily CyberSecurity
The Insider Exit Ramp: Why You Should Switch Windows 11 Channels Now
Windows 11 Build 26300.7674 is here! Learn how to use this rare 2026 "migration window" to switch from the Dev Channel to the Beta Channel safely.
⤷ Title: The Digital Sanctuary: Apple’s 10 Essential Privacy Rules for 2026
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 07:53:54 +0000
════════════════════════
⌗ Tags: #Data Leak #Apple #Data Privacy Day #Data Protection #Face ID #InfoSec 2026 #iOS 26 #iphone #Passkeys #Private Cloud Compute #Safari
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 07:53:54 +0000
════════════════════════
⌗ Tags: #Data Leak #Apple #Data Privacy Day #Data Protection #Face ID #InfoSec 2026 #iOS 26 #iphone #Passkeys #Private Cloud Compute #Safari
Daily CyberSecurity
The Digital Sanctuary: Apple’s 10 Essential Privacy Rules for 2026
Celebrate Data Privacy Day 2026 with Apple’s 10 best security tools. From Private Cloud Compute to Locked Apps, take control of your digital footprint.
⤷ Title: Locking Down the Chat: WhatsApp Debuts “Strict Mode” to Combat Pegasus Spyware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 07:49:26 +0000
════════════════════════
⌗ Tags: #Technology #Advanced Protection #InfoSec 2026 #Lockdown Mode #memory safety #Meta #NSO Group #Pegasus spyware #Rust #Strict Account Settings #WhatsApp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 07:49:26 +0000
════════════════════════
⌗ Tags: #Technology #Advanced Protection #InfoSec 2026 #Lockdown Mode #memory safety #Meta #NSO Group #Pegasus spyware #Rust #Strict Account Settings #WhatsApp
Daily CyberSecurity
Locking Down the Chat: WhatsApp Debuts “Strict Mode” to Combat Pegasus Spyware
In response to the escalating proliferation of cyber offensives and the pervasive shadow of espionage, WhatsApp, the communication vanguard under the Meta umbrella, has announced the inauguration …
⤷ Title: Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)
════════════════════════
𐀪 Author: Piotr Bazydlo (@chudyPB)
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 16:15:16 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Piotr Bazydlo (@chudyPB)
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 16:15:16 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)
When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief.
Clearly, the universe had decided to…
Clearly, the universe had decided to…
⤷ Title: Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)
════════════════════════
𐀪 Author: Piotr Bazydlo (@chudyPB)
════════════════════════
ⴵ Time: Thu, 22 Jan 2026 00:27:19 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Piotr Bazydlo (@chudyPB)
════════════════════════
ⴵ Time: Thu, 22 Jan 2026 00:27:19 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)
Well, well, well - look what we’re back with.
You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV hall-of-famers.…
You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV hall-of-famers.…
⤷ Title: Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:00:00 +0000
════════════════════════
⌗ Tags: #How_To #InfoSec 101 #John Malone #Red Team #Social Engineering
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:00:00 +0000
════════════════════════
⌗ Tags: #How_To #InfoSec 101 #John Malone #Red Team #Social Engineering
Black Hills Information Security, Inc.
Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions - Black Hills Information Security, Inc.
This scenario simultaneously tests identity confirmation tooling (SSPR, MFA, Conditional Access), how users act under pressure, and the organization's ability to detect and follow-up on social engineering attacks.