** Ravie Lakshmanan ** Jan 19, 2026 Hardware Security / Vulnerability A team of academics from the CISPA Helmholtz Center for Information Security in Germany has disclosed the details of a new …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
Just a few years ago, the cloud was touted as the “magic pill” for any cyber threat or performance issue. Many were lured by the “always-on” dream, trading granular control for …
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More
** Ravie Lakshmanan ** Jan 19, 2026 Hacking News / Cybersecurity In cybersecurity, the line between a normal update and a serious incident keeps getting thinner. Systems that once felt reliable are …
Cybersecurity researchers have disclosed details of an ongoing campaign dubbed KongTuke that used a malicious Google Chrome extension masquerading as an ad blocker to deliberately crash the web …
AI-Powered Surveillance in Schools It all sounds pretty dystopian : Inside a white stucco building in Southern California, video cameras compare faces of passersby against a facial recognition …
** Ravie Lakshmanan ** Jan 19, 2026 Malware / Threat Intelligence Cybersecurity researchers have disclosed a cross-site scripting (XSS) vulnerability in the web-based control panel used by operators …
“How many states are there in the United States?” Published 2026-01-18. Last Updated 2026-01-18 07:46:26 UTC by Didier Stevens (Version: 1) 0 comment(s) I’ve seen many API requests …
** Ravie Lakshmanan ** Jan 17, 2026 Law Enforcement / Cybercrime Ukrainian and German law enforcement authorities have identified two Ukrainians suspected of working for the Russia-linked …
Wireshark 4.6.3 Released Published 2026-01-17. Last Updated 2026-01-17 09:25:51 UTC by Didier Stevens (Version: 1) 0 comment(s) Wireshark release 4.6.3 fixes 4 vulnerabilities and 9 bugs. Didier …
** Jan 17, 2026 ** Ravie Lakshmanan Artificial Intelligence / Data Privacy OpenAI on Friday said it would start showing ads in ChatGPT to logged-in adult U.S. users in both the free and ChatGPT Go …
** Jan 16, 2026 ** Ravie Lakshmanan Malvertising / Threat Intelligence The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that’s …
Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that masquerade as human resources (HR) and enterprise resource planning (ERP) platforms like Workday, …
AI and the Corporate Capture of Knowledge More than a decade after Aaron Swartz’s death , the United States is still living inside the contradiction that destroyed him. Swartz believed that knowledge, …
** Jan 16, 2026 ** The Hacker News Privacy / Data Protection You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media. But what about the …
** Jan 16, 2026 ** Ravie Lakshmanan Malware / Cyber Espionage Security experts have disclosed details of a new campaign that has targeted U.S. government and policy entities using politically themed …
China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure
** Jan 16, 2026 ** Ravie Lakshmanan Zero-Day / Cyber Espionage A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last …
** Jan 16, 2026 ** Ravie Lakshmanan Vulnerability / Web Security Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure …
ISC Stormcast For Friday, January 16th, 2026 https://isc.sans.edu/podcastdetail/9770, (Fri, Jan 16th)
ISC Stormcast For Friday, January 16th, 2026 https://isc.sans.edu/podcastdetail/9770
A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service provider’s own GitHub repositories, including its AWS JavaScript SDK, …
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories
** Jan 15, 2026 ** Ravie Lakshmanan Cybersecurity / Hacking News The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show …
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot
** Jan 15, 2026 ** Ravie Lakshmanan Prompt Injection / Enterprise Security Cybersecurity researchers have disclosed details of a new attack method dubbed Reprompt that could allow bad actors to …
** Jan 15, 2026 ** Ravie Lakshmanan Web Security /Vulnerability A maximum-severity security flaw in a WordPress plugin called Modular DS has come under active exploitation in the wild, according to …
** Jan 15, 2026 ** The Hacker News Data Security / Artificial Intelligence As AI copilots and assistants become embedded in daily work, security teams are still focused on protecting the models …
New Vulnerability in n8n This isn’t good: We discovered a critical vulnerability ( CVE-2026-21858, CVSS 10.0 ) in n8n that enables attackers to take over locally deployed instances, impacting an …
[This is a Guest Diary by Matthew Presnal, an ISC intern as part of the SANS.edu BACS program] Cryptojacking and botnets can pose a greater threat than a simple drain of resources. These organizations …