Latest Internet & Cybersecurity News

đź“…January 25, 2026 at 1:00 AM
Massive 149M credential leak dominates cybersecurity news, alongside ransomware attacks on Under Armour and Nike probe, plus critical vulnerabilities and phishing campaigns.
1

149 Million Passwords Exposed in Massive Credential Leak

Cybersecurity researchers uncovered an unsecured database in late January 2026 containing 149 million usernames and passwords from services like Gmail (48M), Facebook (17M), and Netflix (3.4M).Source 1Source 2 The unencrypted data, accessible without authentication, poses risks of credential stuffing, phishing, and identity theft across email, social media, banking, and government domains.Source 1Source 2 Experts urge users to change passwords and enable multi-factor authentication immediately.Source 2

2

Under Armour Confirms Second Major Data Breach by Everest Ransomware

Under Armour disclosed a significant data breach investigation starting November 2025, claimed by the Everest ransomware group, confirmed in January 2026.Source 6 The incident highlights ongoing ransomware threats to major corporations, with details on exposed data still emerging.Source 6 Legal actions are anticipated as affected parties respond.Source 6

3

Nike Investigates Potential Security Incident After Hacker Claims

Nike launched a probe into a claimed data theft by the WorldLeaks cybercrime group, which threatened to leak stolen data from its systems.Source 9 The incident underscores rising threats to retail giants from data extortion groups.Source 9 Nike has not confirmed the breach scope yet.Source 9

4

CIRO Data Breach Exposes 750,000 Canadian Investors' Information

The Canadian Investment Regulatory Organization (CIRO) confirmed a phishing-led cyber incident from August 2025 exposed personal data of 750,000 investors, disclosed publicly in January 2026.Source 8 No passwords were compromised, but risks include fraud and targeted phishing; data has not surfaced on dark web per reports.Source 8 The breach illustrates how initial phishing can lead to mass data extraction.Source 8

5

Multi-Stage Phishing Campaign Targets Russia with Ransomware and Amnesia RAT

A sophisticated phishing operation targets Russian users using cloud services like GitHub and Dropbox to deliver Amnesia RAT for data theft and Hakuna Matata ransomware for encryption.Source 4 It disables Microsoft Defender via defendnot tool and includes WinLocker for control.Source 4 The chain abuses Windows features without vulnerabilities for full compromise.Source 4

6

Ukraine and Germany Identify Members of Russian-Affiliated Ransomware Group

Law enforcement in Ukraine and Germany conducted searches identifying two members of a Russian-linked ransomware group.Source 5 This action highlights international efforts against ransomware networks amid rising attacks.Source 5 Details on the group's operations remain under investigation.Source 5

7

CISA Adds VMware vCenter Flaw to Known Exploited Vulnerabilities Catalog

The U.S. CISA added a Broadcom VMware vCenter vulnerability to its KEV catalog, urging federal agencies to patch immediately.Source 10 The flaw is actively exploited, posing risks to virtualization infrastructure.Source 10 Organizations worldwide should prioritize remediation.Source 10

8

Critical Telnetd Flaw CVE-2026-24061 Affects GNU InetUtils for 11 Years

A critical vulnerability (CVSS 9.8) in GNU InetUtils telnetd (versions 1.9.3–2.7) went undetected for nearly 11 years, enabling remote attacks.Source 10 All affected versions are vulnerable to exploitation.Source 10 Users must update to mitigate risks.Source 10

9

Fortinet FortiCloud SSO Bypassed in Attacks on Patched Devices

Fortinet confirmed attackers bypassing FortiCloud SSO authentication even on fully patched devices, echoing recent SSO flaws.Source 10 This affects enterprise security perimeters significantly.Source 10 Fortinet recommends enhanced monitoring and configurations.Source 10

10

New Osiris Ransomware Abuses POORTRY Driver to Disable Security Tools

Researchers identified Osiris ransomware from a November 2025 attack using BYOVD with POORTRY driver to evade defenses.Source 10 It targets endpoints for encryption after disabling protections.Source 10 Detection and mitigation strategies are critical for organizations.Source 10

11

US Homeland Committee Examines CISA, TSA Roles in Cybersecurity Threats

House Homeland Security Republicans held a hearing on January 23, 2026, reviewing CISA, TSA, and S&T responsibilities against evolving cyber threats to infrastructure.Source 3 Emphasis on foreign adversaries like China and Russia targeting digital systems.Source 3 Calls for modern tactics including private sector tech integration.Source 3

12

TP-Link Patches Critical Flaw in VIGI Cameras Exposing 2,500+ Devices

TP-Link fixed a high-severity vulnerability affecting over 32 VIGI camera models, with 2,500 internet-exposed devices at risk of remote hacking.Source 10 Prompt patching is essential to prevent IoT compromises.Source 10 The flaw allowed unauthorized access to surveillance systems.Source 10