Latest Internet & Cybersecurity News

📅January 23, 2026 at 1:00 PM
Critical vulnerabilities in AI frameworks, Cisco, Fortinet exploited; ransomware hits firms like Under Armour; state-sponsored hacks from China, Russia; spam via Zendesk and cybercrime takedowns dominate cybersecurity news.
1

NCSC Warns UK Organisations of DoS Threats from Russian Hacktivists

The UK's NCSC issued an alert about Russian state-aligned hacktivist groups targeting organisations with denial-of-service attacks focused on disruption.Source 1 Jonathon Ellison urged reviewing defences and preparing response plans.Source 1 Activity aims at overwhelming networks rather than financial gain.Source 1

2

Critical Vulnerabilities Exposed in Chainlit AI Framework

Security researchers found two critical flaws in Chainlit, an open-source AI app framework, risking organisations adopting AI.Source 1 This coincides with Project DarkSide initiative uncovering AI development weaknesses.Source 1 Organisations accelerating AI use face serious exposure.Source 1

3

Zendesk Systems Abused for Global Spam Wave

Attackers exploited unsecured Zendesk support systems for mass spam since January 18, affecting Discord, Dropbox, NordVPN, and others.Source 1 Fake tickets trigger automated replies turning platforms into spam engines with alarming subjects.Source 1 No malicious links but causes confusion via Unicode text.Source 1

4

Fortinet Patch Bypass Actively Exploited on Firewalls

Attackers bypass patches for FortiGate CVE-2025-59718, hacking updated firewalls as reported by admins.Source 1Source 6 Fortinet customers see ongoing exploitation of this critical authentication flaw.Source 6 Immediate remediation urged.Source 6

5

Fortune 500 Firms Exposed by Misconfigured Test Apps

Pentera found 1,926 vulnerable test apps on AWS, Azure, GCP with permissive IAM roles, linked to Cloudflare, F5, Palo Alto.Source 1 Issues remediated post-exposure.Source 1 Highlights cloud config risks for large enterprises.Source 1

6

Everest Ransomware Breaches Under Armour, Exposes 72.7M Accounts

Ransomware group Everest leaked data from Under Armour after unpaid ransom, affecting 72.7 million customers from November 2025 attack.Source 6 Breach posted on cybercrime forum January 18.Source 6 Company has not publicly responded.Source 6

7

Cisco Patches Actively Exploited Zero-Day in Unified Communications

Cisco fixed CVE-2026-20045 (CVSS 8.2), a zero-day RCE in Unified CM, IM & Presence, Unity Connection, Webex Calling.Source 6Source 15 Unauthenticated remote attacks enable arbitrary OS commands.Source 6 Actively exploited as of January 21.Source 15

8

Qilin Ransomware Hits Singapore's Neo Group

Qilin compromised Neo Group, a top caterer with global trading, leaking confidential data observed on underground forums.Source 4 Operates in catering, manufacturing, retail across 30+ countries.Source 4 Sensitive organisational info exposed.Source 4

9

China-Linked Groups Ramp Up Hacking with ShadowPad, Mustang Panda

PRC hackers continue aggressive campaigns using ShadowPad, FINALDRAFT, Windows Group Policy for espionage.Source 3 Groups like Ink Dragon target governments; Mustang Panda deploys TONESHELL rootkit.Source 3 Evasive Panda uses DNS poisoning for MgBot.Source 3

10

Microsoft Disrupts RedVDS Cybercrime Marketplace

Microsoft took down RedVDS, linked to $40M US fraud since March 2025, hosting phishing tools, BEC services, VPNs.Source 2 Platform offered SuperMailer, credential theft, account takeover.Source 2 Major blow to cybercrime-as-a-service.Source 2

11

BreachForums Cybercrime Forum Data Leaked

Hacker 'James' leaked 323,988 BreachForums member records including emails, IPs, real names of admins and Shiny Hunters.Source 2 Database exposed usernames, passwords, registration dates.Source 2 Highlights risks in dark web forums.Source 2

12

Dire Wolf Ransomware Attacks Perdana Petroleum Berhad

Dire Wolf published data from Malaysian oil firm Perdana Petroleum after compromise.Source 4 Part of ongoing ransomware incidents reported January 23.Source 4 Underscores energy sector targeting.Source 4