Latest Internet & Cybersecurity News
📅January 19, 2026 at 1:00 AM
Critical vulnerabilities patched by Microsoft, Cisco, and others amid ransomware attacks, hospital disruptions, state-sponsored exploits, and global cybercrime crackdowns.
1
Microsoft Issues Emergency Patch for Actively Exploited Windows Zero-Day CVE-2026-20805
Microsoft released an urgent patch for CVE-2026-20805, a critical zero-day vulnerability affecting all supported Windows versions that is under active exploitation. The flaw allows attackers unauthorized access, prompting immediate updates. This follows January Patch Tuesday fixing 112-114 flaws, including one exploited zero-day.
2
Cisco Patches Zero-Day RCE in Secure Email Gateways Exploited by China-Linked APT
Cisco addressed CVE-2025-20393 (CVSS 10.0), a maximum-severity flaw in AsyncOS for Secure Email Gateway exploited as zero-day by China-nexus APT UAT-9686. Patches prevent root command execution if exposed ports are open. Disclosure came nearly a month after detection.