Latest Internet & Cybersecurity News

๐Ÿ“…January 19, 2026 at 1:00 PM
Major cybersecurity developments include China's ban on US/Israeli software, Microsoft's Patch Tuesday zero-days, massive data breaches at Endesa and CIRO, and ransomware attacks amid rising geopolitical tensions.
1

China Bans U.S. and Israeli Cybersecurity Software

Beijing ordered Chinese firms to stop using cybersecurity tools from vendors like VMware, Palo Alto Networks, Fortinet, and CrowdStrike due to national security concerns over data leaks. This escalates tech decoupling and geopolitical tensions.Source 1Source 4 Organizations in China must reassess supply chains urgently.Source 4

2

Microsoft Patch Tuesday Fixes Actively Exploited Zero-Days

Microsoft addressed 114 vulnerabilities, including CVE-2026-20805 in Desktop Window Manager under active exploitation, and others added to CISA's Known Exploited Vulnerabilities catalog. Updates cover Windows, affecting all supported versions.Source 2Source 5Source 9 Urgent patching is recommended for enterprises.Source 9

3

Spanish Energy Giant Endesa Discloses Massive Data Breach

Endesa reported a breach exposing data of 22 million customers, with threat actors claiming theft of full customer data. This impacts personal information of millions.Source 1Source 2 Investigations continue amid ongoing threats.Source 2

4

Ransomware Attack Disrupts South Korean Kyowon Group

A ransomware incident at Kyowon exposed over 9 million user accounts and halted operations at the conglomerate. It highlights vulnerabilities in complex supply chains.Source 1Source 4 Recovery efforts are underway.Source 1

5

CIRO Confirms Data Breach Affecting 750,000 Canadian Investors

Canada's CIRO disclosed a phishing attack from August 2025 impacting 750,000 investors, exposing sensitive data like SINs, incomes, and account details after nine months of investigation. Notifications began January 14, 2026.Source 6 Protection services offered to affected individuals.Source 6

6

CISA Adds Gogs Git Service Flaw to Known Exploited Vulnerabilities

U.S. CISA directed federal agencies to patch a remote code execution vulnerability in Gogs due to active exploitation. Software development organizations urged to prioritize updates.Source 1Source 4 This affects enterprise networks.Source 4

7

BreachForums Hacking Forum Database Leaked

The BreachForums user database, exposing 324,000 accounts, was leaked, giving the community a taste of its own medicine. This incident reveals internal vulnerabilities in hacking forums.Source 2 Further leaks possible.Source 2

8

Europol and Spanish Police Arrest 34 Black Axe Members

Authorities dismantled parts of the Black Axe criminal network involved in cyber fraud and money laundering across Europe and Africa. Arrests highlight international cooperation against cybercrime.Source 1Source 4 Operations disrupted.Source 4

9

Instagram Data Scraping Affects 17.5 Million Users

A massive scraping incident compromised data of 17.5 million Instagram users, alongside a password reset flaw fixed by Meta, which denied a breach. Users advised to check suspicious emails.Source 2Source 3 Phishing risks elevated.Source 3

10

Cisco Patches Critical AsyncOS Zero-Day Exploited by Chinese APT

Cisco addressed a critical zero-day in AsyncOS (UAT-8837) exploited by Chinese actors, part of ongoing infrastructure vulnerabilities. Immediate patching essential.Source 2 Supply chain risks persist.Source 2

11

Palo Alto Networks Fixes GlobalProtect Flaw with PoC

Palo Alto addressed a critical GlobalProtect vulnerability where a PoC exploit exists, enabling potential admin takeover. Despite China's ban, patches issued promptly.Source 1 Users urged to update.Source 1

12

Iran Slows Cyber Attacks on UK Amid Domestic Protests

Cyber attacks on the UK from Iran decreased noticeably during recent Iranian protests, as reported by British defense executives. Geopolitical distractions shift threat priorities.Source 14 Monitoring continues.Source 14