Latest Internet & Cybersecurity News

đź“…January 20, 2026 at 1:00 PM
January 2026 sees rising AI-powered phishing, ransomware attacks, malware dominance, OT cyber-physical risks, and state-linked DDoS on critical infrastructure.
1

January 2026 Cyber Attacks Timeline Reports 61 Events

The timeline records 61 cyber incidents, with malware at 36%, account takeover 15%, and ransomware 11%.Source 2 Phishing is the top initial access at 15%, followed by public-facing app vulnerabilities at 14% and social engineering at 12%; public administrations most targeted at 14%.Source 2 Analysts urge better phishing detection, vulnerability monitoring, and security training.Source 2

2

Incransom Ransomware Hits TruStar Holdings LLC

On January 15, 2026, Incransom claimed a major attack on US firm TruStar Holdings, compromising 1.4 TB of data including drawings, files, and transactions.Source 4 The breach highlights ongoing ransomware threats to businesses.Source 4 Robust cybersecurity is essential to protect sensitive data.Source 4

3

Malicious Chrome Extensions Target Workday and NetSuite Users

Five fake Chrome extensions impersonate HR/ERP tools like Workday and NetSuite to steal tokens and hijack accounts via session hijacking.Source 6 They exfiltrate cookies and block admin access.Source 6 Over 840,000 installs in ad fraud scheme GhostPoster hide malware in images.Source 6

4

UK NCSC Warns of Russia-Linked Hacktivists' DDoS Attacks

On January 19, 2026, NCSC alerted on pro-Russian groups like NoName057(16) targeting UK critical infrastructure and local government with DDoS.Source 12 Attacks aim to disrupt networks; review defenses urged.Source 12 Group hit NATO supporters including Sweden, Germany, Switzerland.Source 12

5

European Space Agency Suffers Massive Data Breaches

In late 2025-early 2026, hackers stole over 700 GB from ESA, including code, credentials, and mission docs from groups '888' and Scattered Lapsus$ Hunters.Source 8 Data leaked on BreachForums via unpatched flaws.Source 8 Infostealer malware likely aided via employee credentials.Source 8

6

AI-Powered Phishing Kits Surge in Effectiveness

AI phishing kits enable scalable, personalized attacks that evade detection with better emails and timing.Source 1 QR code phishing bypasses filters to steal credentials; 10 defenses recommended.Source 1 Awareness key to counter point-and-click attack tools.Source 1

7

WEF: AI Supercharges Cyber Arms Race in 2026

94% expect AI as top cybersecurity change driver; cloud/IoT expand OT attack surfaces.Source 3 OT cyber now cyber-physical with global cascade risks from disruptions.Source 3 Emerging climate-digital crises by 2030 heighten vulnerabilities.Source 3

8

XSS Vulnerability in StealC Malware Exposes Hackers

Researchers exploited XSS in StealC control panel to spy on operators like YouTubeTA, stealing 390k passwords.Source 6 Malware-as-a-service uses YouTube, Telegram; opsec error revealed IP.Source 6 Infostealers fuel credential theft at record rates.Source 6

9

Token Theft and Session Hijacking Rise in 2026

Attackers target session/OAuth tokens for persistent access bypassing MFA; Microsoft saw 147k replays in 2023.Source 10 1.8B credentials stolen in H1 2025 via infostealers.Source 10 Ransomware often starts with bought access.Source 10

10

ETSI Releases AI Cybersecurity Standard

New ETSI standard sets baseline cybersecurity requirements for AI systems.Source 7 Aims to establish foundational protections amid rising threats.Source 7 Part of broader news roundup on January 19, 2026.Source 7

11

Financial Services Lag in AI Cybersecurity Adoption

WEF research shows financial firms trail in using AI for cyber operations ahead of Davos.Source 11 Highlights sector gaps in tech leverage.Source 11 Urges catch-up on AI defenses.Source 11