Latest Internet & Cybersecurity News

đź“…January 28, 2026 at 1:00 PM
Major data breaches hit IDHS, US Supreme Court, and Endesa; Microsoft Office vulnerability exploited; ShinyHunters phishing targets 100+ orgs; Electrum attacks Polish energy.
1

Illinois Department of Human Services Data Breach Exposes 700,000 Records

The Illinois Department of Human Services (IDHS) confirmed a data breach exposing sensitive records of roughly 700,000 individuals, one of the largest public-sector breaches in 2026. This incident underscores ongoing risks in government systems.Source 1

2

Hacker Faces Trial for Breaching US Supreme Court Systems

A hacker repeatedly accessed the US Supreme Court’s electronic document filing system using stolen credentials, stealing and posting personal data on Instagram. The case highlights vulnerabilities from credential reuse in high-profile systems.Source 1

3

Spanish Energy Giant Endesa Notifies Customers of Data Breach

Endesa and EnergĂ­a XXI confirmed unauthorized access to their commercial platform, exposing customer IDs, contacts, contracts, and payment details for millions. The breach was contained quickly with no passwords compromised.Source 1

4

Microsoft Releases Emergency Patch for Actively Exploited Office Vulnerability

Microsoft issued out-of-band updates for CVE-2026-21509, a high-severity security feature bypass in Office products like 2016-2024 versions and M365 Apps. The flaw is exploited in the wild to install malware via malicious files.Source 4

5

ShinyHunters Phishing Campaign Targets Over 100 Organizations

Cybercrime group ShinyHunters launched a phishing campaign hitting numerous major organizations, as identified by Silent Push. This underscores persistent phishing threats to large entities.Source 12

6

Electrum Group Launches First Major DER Cyberattack on Polish Electric System

Dragos reported Electrum targeting Poland's distributed energy resources in a significant cyberattack on electric systems. This marks a new escalation in industrial control system threats.Source 13

7

Tokio Marine HCC Releases Top 10 Cyber Incidents of 2025

The report lists major 2025 breaches like Marks & Spencer ransomware (ÂŁ300M impact), Jaguar Land Rover (ÂŁ1.9B loss), and AWS outages, highlighting ransomware and supply-chain risks.Source 2

8

US Cybersecurity Pros Plead Guilty in BlackCat Ransomware Attacks

Three US-based experts admitted roles as BlackCat (ALPHV) affiliates, using insider knowledge for breaches and extortion. The case warns of risks from trusted vendors.Source 8

9

Nearly 9 in 10 Firms Remain Vulnerable to Cyber Risks

A report reveals almost 90% of firms are still exposed to cyber threats, emphasizing widespread organizational weaknesses.Source 11

10

Dragos: Chinese APTs Target Taiwan Semiconductor Industry

Four Chinese nation-state actors are attacking Taiwan's semiconductors via SharePoint bugs, per recent reports. This reflects ongoing geopolitical cyber tensions.Source 10

11

UK Cyber Security and Resilience Bill Reshapes Landscape

New UK legislation addresses cyber resilience, alongside data protection reforms like the Data (Use and Access) Act 2025 commencements.Source 3

12

2026 Predictions: Surge in Legitimate Tool Abuse and Deepfake Vishing

Experts forecast increased RMM tool abuse, vishing with deepfakes, SaaS targeting, and APTs on semiconductors amid geopolitical tensions.Source 5