Latest Internet & Cybersecurity News

πŸ“…January 23, 2026 at 1:00 AM
January 23, 2026 cybersecurity headlines feature NCSC DoS warnings, AI framework flaws, ransomware surges, major takedowns, and rising global spending amid evolving threats.
1

NCSC Warns UK Organisations of DoS Threats from Russian Hacktivists

The UK's NCSC issued an alert about ongoing denial-of-service attacks by Russian state-aligned hacktivist groups targeting organisations for disruption, not financial gain.Source 1 Director Jonathon Ellison urged reviewing defences and preparing response plans.Source 1 Focus is on overwhelming networks and online services.Source 1

2

Critical Vulnerabilities Exposed in Chainlit AI Framework

Security researchers uncovered two critical flaws in Chainlit, an open-source AI app framework, posing risks to AI-adopting organisations.Source 1 This coincides with Project DarkSide initiative targeting AI development weaknesses.Source 1 Organisations accelerating AI use face serious exposure.Source 1

3

Zendesk Support Systems Abused for Global Spam Wave

Attackers exploited unsecured Zendesk systems to generate mass spam via fake support tickets and automated replies, affecting Discord, Dropbox, NordVPN, and others.Source 1 Campaign started January 18 with chaotic, alarming subjects using Unicode text.Source 1 No malicious links found, but highlights verification gaps.Source 1

4

Fortinet Patch Bypass Actively Exploited

Attackers are targeting a Fortinet patch bypass vulnerability under active exploitation.Source 1 Organisations urged to apply updates immediately.Source 1 Details limited but part of weekly cyber roundup.Source 1

5

Fortune 500 Firms Exposed by Misconfigured Test Apps

Pentera found 1,926 vulnerable test apps on AWS, Azure, GCP linked to Fortune 500 like Cloudflare, F5, Palo Alto with permissive IAM roles.Source 1 Issues remediated post-discovery.Source 1 Highlights risks of default credentials in cloud environments.Source 1

6

RansomHouse Hits Luxshare, Exposes iPhone Data

Ransomware group RansomHouse attacked Luxshare Precision, Apple's iPhone/iPad assembler, on December 15, 2025, using double extortion.Source 2 Proprietary data exfiltrated; no customer credentials compromised.Source 2 Attack announced January 8, 2026.Source 2

7

BreachForums Cybercrime Forum Data Leaked

Hacker 'James' leaked 323,988 member records from BreachForums, including usernames, emails, IPs, and real names of admins and Shiny Hunters.Source 2 Breach occurred January 9, 2026.Source 2 Forum known for cybercriminal activities.Source 2

8

Microsoft Disrupts RedVDS Cybercrime Marketplace

Microsoft took down RedVDS, linked to $40M US fraud since March 2025, hosting phishing tools, mailers, VPNs, and attack services like BEC.Source 2 Announcement on January 14, 2026.Source 2 Platform offered cybercrime-as-a-service.Source 2

9

Cisco Patches Critical CVE-2026-20045 Zero-Day

Cisco fixed a critical code injection flaw from improper HTTP input validation on January 21, 2026.Source 8 Vulnerability allows unauthenticated remote attackers.Source 8 Immediate patching recommended.Source 8

10

Qilin Ransomware Compromises Neo Group in Singapore

Qilin ransomware hit Neo Group, a top events caterer with global trading, exposing confidential data observed on underground forums.Source 4 Operates in catering, manufacturing, retail across 30+ countries.Source 4 Sensitive organisational info leaked.Source 4

11

Global Cybersecurity Spending to Hit $240 Billion in 2026

Gartner forecasts $240B in info security spending, up 12.5% from 2025, driven by AI threats and regulations.Source 5 Shift to AI-resilience, securing unstructured data.Source 5 Includes $121.1B software, $92.8B services.Source 5

12

CISA and FBI Release OT Cyber Risk Guidance

CISA and FBI issued new guidance on January 15, 2026, addressing cyber risks in operational technology environments.Source 11 Targets critical infrastructure.Source 11 Emphasises enhanced protections.Source 11