Latest Internet & Cybersecurity News

📅January 26, 2026 at 1:00 AM
Major cybersecurity incidents include massive password breaches, ransomware attacks, critical vulnerabilities in FortiGate, VMware, Cisco, and exploits of patched systems globally.Source 1Source 2Source 3
1

Massive Data Breach Exposes 149 Million Passwords from Gmail, Netflix, Facebook

Cybersecurity researchers uncovered a publicly accessible database with 149 million login credentials, including plaintext passwords for Gmail, Facebook, and Netflix. This exposes users to credential stuffing and identity theft risks.Source 2 The breach was reported on January 25, 2026.Source 2

2

Osiris Ransomware Emerges Using BYOVD to Kill Security Tools

New Osiris ransomware leverages Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools. It targets enterprises with advanced evasion methods.Source 1 Security experts warn of its potential for widespread disruption.Source 1

3

CISA Adds VMware vCenter Server Flaw to Known Exploited Vulnerabilities

U.S. CISA cataloged a critical Broadcom VMware vCenter Server vulnerability actively exploited in the wild. Organizations must patch immediately to prevent compromise.Source 1Source 6 The flaw allows unauthorized access and control.Source 1

4

Fully Patched FortiGate Firewalls Compromised via SSO Bypass

Attackers are bypassing FortiCloud SSO on updated Fortinet FortiGate firewalls, adding users and stealing configs. Arctic Wolf detected a surge in automated attacks since January 15.Source 1Source 3Source 6 Even latest patches fail to block exploits.Source 3

5

CISA Adds Cisco Unified Communications Zero-Day to KEV Catalog

Cisco fixed an actively exploited zero-day in Unified Communications products, now added to CISA's Known Exploited Vulnerabilities list as CVE-2026-20045. Immediate patching is required.Source 1Source 6 Attacks confirmed in the wild.Source 1

6

Critical SmarterMail Vulnerability Under Active Attack

A SmarterMail flaw (WT-2026-0001) is exploited days after its January 15 patch, with no CVE assigned yet. Attackers target unpatched servers for remote code execution.Source 1Source 6 Urgent updates advised.Source 6

7

Jordanian Access Broker Pleads Guilty to Hacking 50 Companies

Feras Khalil Ahmad Albashiti admitted selling unauthorized access to 50 corporate networks via online forums. He faces charges for fraud using cryptocurrency payments.Source 1Source 3Source 4 Arrest followed undercover sting in 2023.Source 3

8

TP-Link Patches Critical VIGI Camera Flaw Allowing Remote Takeover

CVE-2026-0629 (CVSS 8.7) in over 32 TP-Link VIGI camera models enables local network attackers to hijack devices. Over 2,500 exposed cameras identified online.Source 1Source 6 Patch released immediately.Source 6

9

72M Under Armour Records Surface in Data Breach Investigation

Investigation launched after 72 million Under Armour user records appeared online, potentially exposing personal data. Breach impacts customer privacy significantly.Source 1 Details under active probe.Source 1

10

RansomHub Claims Breach of Apple Partner Luxshare

RansomHub ransomware affiliates allege stealing and encrypting data from Luxshare Precision, Apple's Chinese supplier. Sensitive files posted on leak site.Source 3 Incident escalates supply chain risks.Source 3

11

ESET Links Sandworm to Cyberattack on Poland’s Power Grid

Russia-linked Sandworm used wiper malware in late 2025 attack on Poland's energy grid, aiming for outages. ESET analyzed the destructive payload.Source 1Source 4 Highlights state-sponsored threats.Source 4

12

UK NCSC Warns of Russia-Linked Hacktivists DDoS Attacks

NCSC alerts on Russian hacktivists targeting UK organizations with DDoS disruptions. Increased activity noted recently.Source 1Source 4 Defensive measures recommended.Source 4