Latest Internet & Cybersecurity News

📅January 28, 2026 at 1:00 AM
January 2026 sees nation-state cyber ops escalate, ransomware hits energy firms, critical Oracle/SAP/VMware vulns exploited, AI-enhanced attacks surge globally.
1

US Cyber Operations Disrupt Venezuela Power and Radar in Maduro Capture

U.S. authorities deployed offensive cyber operations to disable power and radar systems in Caracas during a January operation to capture Venezuela’s president Nicolás Maduro. Effects were reversible with minimal civilian impact, marking overt use of cyber tools for law enforcement.Source 1 This signals normalization of cyber as tactical statecraft against weak infrastructure.

2

APT28 Targets Global Energy and Nuclear Organizations

Russia-linked APT28 ran campaigns against energy, nuclear research, and policy groups for credential harvesting and long-term access.Source 1 High-value targets provide intel on infrastructure and strategies, often preceding geopolitical actions.

3

Mustang Panda Spearphishes US Government on Venezuela Policy

China-linked Mustang Panda used Venezuela policy lures in spearphishing against U.S. government entities, focusing on credentials rather than disruption.Source 1 Telecom and policy bodies remain prime espionage targets.

4

Ransomware Strikes Romanian CET Oltenia Energy Producer

Romanian energy firm CET Oltenia suffered a ransomware attack amid rising incidents in energy sector.Source 1 Attacks exploit update windows, reflecting criminal and state pressure on energy stability.

5

Chilean Copec Confirms Ransomware on Internal Systems

Chile's Copec energy firm reported ransomware affecting internal operations, varying in impact but part of global energy targeting pattern.Source 1 Geopolitical risks amplify ransomware threats to national infrastructure.

6

Taiwan Energy Sector Faces Tenfold Cyberattack Surge

Taiwan reported a 10x increase in energy sector attacks, with foes exploiting software updates.Source 1 Sustained pressure from state-aligned actors threatens economic continuity.

7

Threat Actors Scan LLM Servers for Vulnerabilities

Large-scale scanning targets exposed LLM servers for API flaws, weak auth, enabling data theft or model compromise.Source 1 AI infrastructure now high-value as governance lags.

8

Grubhub Data Theft Linked to Salesloft Supply Chain Attack

Grubhub confirmed data download from systems in Jan 2026, tied to Salesloft Drift/Salesforce token incident; financials spared.Source 2 Confirmed publicly Jan 16, scale unquantified.

9

Oracle CVE-2026-20805 Actively Exploited for RCE

Critical Oracle vuln in Jan 2026 Patch Update allows remote code execution and unauthorized access, already exploited in wild.Source 3 Prioritizes enterprise databases in patching urgency.

10

SAP S/4HANA SQL Injection Exposes ERP Data

High-severity SQL injection in SAP S/4HANA private cloud/on-prem enables data exposure and manipulation of business processes.Source 3 Additional high-risk flaw allows unauthorized access.

11

CISA Adds VMware vCenter Vuln to Known Exploited List

Critical VMware vCenter Server flaw actively exploited, added to CISA KEV catalog requiring BOD 22-01 remediation.Source 5 Part of broader exploit chains.

12

ShinyHunters Phishing Campaign Hits Over 100 Organizations

ShinyHunters group targeted 100+ major orgs in recent cybercrime phishing campaign, per Silent Push analysis.Source 6 Focuses on widespread credential and access theft.

Latest Internet & Cybersecurity News | DeckBook AI