What is happening to the Internet in Venezuela? Did the U.S. use cyber capabilities?
https://securityaffairs.com/186509/intelligence/what-is-happening-to-the-internet-in-venezuela.html
https://securityaffairs.com/186509/intelligence/what-is-happening-to-the-internet-in-venezuela.html
Security Affairs
What is happening to the Internet in Venezuela? Did the U.S. use cyber capabilities?
In light of the tragic events that occurred in Venezuela, what is happening to the Internet in the country, and how are users accessing it?
QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
https://securityonline.info/qnap-patches-high-severity-sql-injection-and-path-traversal-flaws/
https://securityonline.info/qnap-patches-high-severity-sql-injection-and-path-traversal-flaws/
Daily CyberSecurity
QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
QNAP patches high-severity flaws (CVSS 8.1) in Qfiling and MARS that allow data theft and code injection. Secure your NAS by updating to the latest versions!
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
https://securityonline.info/zero-click-hijack-the-prestashop-checkout-flaw-that-turns-emails-into-full-account-access-poc-publishes/
https://securityonline.info/zero-click-hijack-the-prestashop-checkout-flaw-that-turns-emails-into-full-account-access-poc-publishes/
Daily CyberSecurity
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
PrestaShop patches a 9.1 critical flaw (CVE-2025-61922) in the Checkout module. Attackers can hijack accounts via email. PoC available.
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
https://securityonline.info/the-sleeper-in-your-browser-how-darkspectre-turned-8-8-million-extensions-into-state-aligned-spies/
https://securityonline.info/the-sleeper-in-your-browser-how-darkspectre-turned-8-8-million-extensions-into-state-aligned-spies/
Daily CyberSecurity
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
Koi Security unmasks DarkSpectre, a Chinese threat group that used 300+ browser extensions to spy on 8.8M users and steal corporate meeting data.
Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
https://securityonline.info/eaton-ups-software-flaws-expose-systems-to-high-risk-code-execution/
https://securityonline.info/eaton-ups-software-flaws-expose-systems-to-high-risk-code-execution/
Daily CyberSecurity
Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
Eaton warns of critical 8.6 severity flaws in UPS Companion software (CVE-2025-59887 & 59888). Upgrade to v3.0 now to prevent hijacking!
New WordPress Phishing Scam Steals Credit Cards via Telegram
https://securityonline.info/new-wordpress-phishing-scam-steals-credit-cards-via-telegram/
https://securityonline.info/new-wordpress-phishing-scam-steals-credit-cards-via-telegram/
Daily CyberSecurity
New WordPress Phishing Scam Steals Credit Cards via Telegram
Researcher Anurag uncovers a WordPress phishing campaign that steals credit cards and 3-D Secure OTPs, exfiltrating data directly via Telegram bots.
Transparent Tribe Weaponizes “JLPT” Tests in New Cyber-Espionage Campaign Against India
https://securityonline.info/transparent-tribe-weaponizes-jlpt-tests-in-new-cyber-espionage-campaign-against-india/
https://securityonline.info/transparent-tribe-weaponizes-jlpt-tests-in-new-cyber-espionage-campaign-against-india/
Daily CyberSecurity
Transparent Tribe Weaponizes "JLPT" Tests in New Cyber-Espionage Campaign Against India
CYFIRMA unmasks APT36's latest campaign: a fake JLPT exam lure using fileless LNK malware to evade antivirus and spy on Indian government targets.
CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
https://securityonline.info/cve-2025-66848-critical-flaw-in-jd-cloud-routers-grants-hackers-root-access/
https://securityonline.info/cve-2025-66848-critical-flaw-in-jd-cloud-routers-grants-hackers-root-access/
Daily CyberSecurity
CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
JD Cloud alerts users to CVE-2025-66848, a 9.8 critical flaw allowing remote attackers to bypass auth and gain root access on NAS routers.
The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
https://securityonline.info/the-invisible-predator-how-vvs-stealer-abuses-pyarmor-to-ghost-discord-accounts/
https://securityonline.info/the-invisible-predator-how-vvs-stealer-abuses-pyarmor-to-ghost-discord-accounts/
Daily CyberSecurity
The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
Unit 42 unmasks VVS Stealer, a Python-based threat using Pyarmor obfuscation to bypass AV, hijack Discord sessions, and steal browser credentials.
“Sliver” in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
https://securityonline.info/sliver-in-the-stack-exposed-logs-reveal-targeted-fortiweb-exploitation-campaign/
https://securityonline.info/sliver-in-the-stack-exposed-logs-reveal-targeted-fortiweb-exploitation-campaign/
Daily CyberSecurity
"Sliver" in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
Threat actor uses React2Shell to deploy Sliver C2 on FortiWeb devices, using a Bangladesh Airforce decoy to target govt and financial sectors.
CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
https://securityonline.info/cve-2026-21440-new-adonisjs-9-2-critical-flaw-allows-arbitrary-file-writes-and-rce/
https://securityonline.info/cve-2026-21440-new-adonisjs-9-2-critical-flaw-allows-arbitrary-file-writes-and-rce/
Daily CyberSecurity
CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
CVE-2026-21440: A critical 9.2 flaw in AdonisJS file uploads allows attackers to overwrite system files and gain RCE. Update to v10.1.2 immediately!
❤1
Private Intelligence: Telegram’s 2026 Update Brings AI Summaries via the Cocoon Network
https://securityonline.info/private-intelligence-telegrams-2026-update-brings-ai-summaries-via-the-cocoon-network/
https://securityonline.info/private-intelligence-telegrams-2026-update-brings-ai-summaries-via-the-cocoon-network/
Daily CyberSecurity
Private Intelligence: Telegram’s 2026 Update Brings AI Summaries via the Cocoon Network
Telegram's first 2026 update adds AI channel summaries powered by the private Cocoon network and a gorgeous Liquid Glass redesign for iOS.
The Hacker Returns: Bitfinex Mastermind Ilya Lichtenstein Freed Early via Trump Law
https://securityonline.info/the-hacker-returns-bitfinex-mastermind-ilya-lichtenstein-freed-early-via-trump-law/
https://securityonline.info/the-hacker-returns-bitfinex-mastermind-ilya-lichtenstein-freed-early-via-trump-law/
Daily CyberSecurity
The Hacker Returns: Bitfinex Mastermind Ilya Lichtenstein Freed Early via Trump Law
Bitfinex hacker Ilya Lichtenstein released early in Jan 2026! He credits Trump’s First Step Act and vows a new career in cybersecurity research.
The Unpatchable Leak: Sony’s PS5 Security Crumples as BootROM Keys Hit the Web
https://securityonline.info/the-unpatchable-leak-sonys-ps5-security-crumples-as-bootrom-keys-hit-the-web/
https://securityonline.info/the-unpatchable-leak-sonys-ps5-security-crumples-as-bootrom-keys-hit-the-web/
Daily CyberSecurity
The Unpatchable Leak: Sony’s PS5 Security Crumples as BootROM Keys Hit the Web
A massive leak of PS5 BootROM keys has exposed Sony’s hardware trust root. This unpatchable flaw clears the path for permanent jailbreaks and custom firmware.
Systems over Slop: Nadella’s 2026 AI Vision Sparks “Microslop” Revolt
https://securityonline.info/systems-over-slop-nadellas-2026-ai-vision-sparks-microslop-revolt/
https://securityonline.info/systems-over-slop-nadellas-2026-ai-vision-sparks-microslop-revolt/
Daily CyberSecurity
Systems over Slop: Nadella’s 2026 AI Vision Sparks "Microslop" Revolt
Satya Nadella’s 2026 AI manifesto calls for a shift from "models to systems," but the #Microslop backlash proves users are tired of AI-generated junk.
The Scrapbook Strategy: Why OpenAI is Betting $17 Billion on Pinterest
https://securityonline.info/the-scrapbook-strategy-why-openai-is-betting-17-billion-on-pinterest/
https://securityonline.info/the-scrapbook-strategy-why-openai-is-betting-17-billion-on-pinterest/
Daily CyberSecurity
The Scrapbook Strategy: Why OpenAI is Betting $17 Billion on Pinterest
OpenAI is reportedly planning to acquire Pinterest for $17.5B in 2026. The goal? High-quality visual data and a proven ad engine to take on Google.
Resecurity Caught ShinyHunters in Honeypot
https://securityaffairs.com/186528/security/resecurity-caught-shinyhunters-in-honeypot.html
https://securityaffairs.com/186528/security/resecurity-caught-shinyhunters-in-honeypot.html
Security Affairs
Resecurity Caught ShinyHunters in Honeypot
Resecurity caught ShinyHunters (SLH) using decoy accounts; the group attacked airlines, telecoms, and law enforcement in Sept 2025.
European Space Agency Confirms Cybersecurity Breach on External Servers
https://thecyberexpress.com/european-space-agency-confirms-cyber-incident/
https://thecyberexpress.com/european-space-agency-confirms-cyber-incident/
The Cyber Express
European Space Agency Confirms Cybersecurity Incident
European Space Agency (ESA) has said further updates will be shared once more information becomes available.
SlowMist Flags Potential Security Risk at HitBTC Exchange
https://thecyberexpress.com/hitbtc-exchange-critical-security-warning/
https://thecyberexpress.com/hitbtc-exchange-critical-security-warning/
The Cyber Express
HitBTC Exchange Faces Critical Security Warning
A security alert from SlowMist warns of a critical vulnerability at HitBTC Exchange after failed disclosure attempts.
Sedgwick discloses data breach after TridentLocker ransomware attack
https://securityaffairs.com/186525/data-breach/sedgwick-discloses-data-breach-after-tridentlocker-ransomware-attack.html
https://securityaffairs.com/186525/data-breach/sedgwick-discloses-data-breach-after-tridentlocker-ransomware-attack.html
Security Affairs
Sedgwick discloses data breach after TridentLocker ransomware attack
Sedgwick confirmed a cyber incident at its federal contractor unit after TridentLocker claimed to steal 3.4GB of data.
Critical IBM API Connect Vulnerability Enables Authentication Bypass
https://thecyberexpress.com/ibm-api-connect-security-vulnerability/
https://thecyberexpress.com/ibm-api-connect-security-vulnerability/
The Cyber Express
IBM API Connect Faces Critical Security Vulnerability
Organizations running affected versions of IBM API Connect are urged to assess their deployments immediately.