UINAT
NewsRankingsCompaniesGuidesBreachesCompliance
TagsAbout
Home/News

Security News

Breaking cybersecurity news, vulnerability disclosures, and industry updates.

Cisco Patches Actively Exploited Zero-Day in Unified Communications and Webex

CVE-2026-20045, a CVSS 9.8 RCE flaw in Cisco Unified CM, is being actively exploited. No workaround exists—organizations must upgrade to 14SU5 or 15SU4 immediately.

January 22, 2026 Ciscozero-dayCVE-2026-20045

Automated Attacks Exploit FortiCloud SSO to Hijack FortiGate Firewalls

Arctic Wolf detected automated attacks on FortiGate devices starting January 15, exploiting CVE-2026-24858 (CVSS 9.8) to create backdoor admin accounts. Fortinet temporarily suspended FortiCloud SSO globally to contain the threat.

January 22, 2026 FortinetFortiGatezero-day

Apple Expands Advanced Data Protection with End-to-End Encryption for Additional iCloud Categories

Apple broadens its Advanced Data Protection feature to more countries and adds new encrypted data categories, while maintaining its refusal to comply with UK government demands for a backdoor—leaving British users without the feature.

January 22, 2026 AppleencryptioniCloud

Malicious PyPI Packages Masquerading as Spellcheckers Deliver RAT Malware

Packages 'spellcheckerpy' and 'spellcheckpy' downloaded over 1,000 times use multi-layer encryption and fileless execution to deliver cryptocurrency-stealing RAT. Same threat actor linked to November 2025 campaign.

January 21, 2026 supply chainPyPImalware

Under Armour Ransomware Breach Exposes 72 Million Customer Records

The Everest ransomware group leaked 72.7 million Under Armour customer records including emails, names, dates of birth, purchase history, and loyalty program details after the company didn't pay.

January 21, 2026 Under Armourransomwaredata breach

Oracle January 2026 Critical Patch Update Addresses 337 Vulnerabilities

Massive security update includes patches across 122 products with two CVSS 10.0 flaws. Java SE receives 11 remotely exploitable patches, and Financial Services Applications have 33 unauthenticated attack vectors.

January 20, 2026 Oraclepatchvulnerability

Healthcare Ransomware Crisis: Lessons from Ascension and the 2024-2025 Attack Wave

Healthcare ransomware attacks affected 93% of organizations in 2024-2025, with Ascension's $1.8B loss and 5.6M affected patients illustrating the sector's vulnerability. HIPAA Security Rule update pending.

January 20, 2026 ransomwarehealthcarebreach

Malicious Chrome Extensions Impersonate Workday, NetSuite to Hijack Enterprise Accounts

Five malicious Chrome extensions disguised as HR and ERP platforms like Workday, NetSuite, and SuccessFactors stole authentication tokens and enabled account takeover before being removed from the Chrome Web Store.

January 19, 2026 Chrome extensionsmalwareaccount takeover

CrowdStrike Falcon Outage: The Largest IT Failure in History One Year Later

On July 19, 2024, a faulty CrowdStrike Falcon content update crashed 8.5 million Windows systems worldwide, causing over $10 billion in damages and grounding thousands of flights. A retrospective on what happened and what changed.

January 19, 2026 CrowdStrikeoutageincident

SEC Charges Publicly Traded Company for Misleading Investors About Data Breach Severity

The Securities and Exchange Commission files charges against a publicly traded firm for materially understating the scope and impact of a 2025 data breach, signaling aggressive enforcement of cyber disclosure rules adopted in December 2023.

January 18, 2026 SECbreach disclosurecompliance

Redis RCE Vulnerability Exploitable Despite Authentication — Upgrade to 8.3.2

CVE-2025-62507 is a stack buffer overflow in Redis 8.2's XACKDEL command. JFrog researchers demonstrated full remote code execution is achievable, contradicting the initial 'authentication required' assessment.

January 17, 2026 RedisvulnerabilityRCE

Salt Typhoon: Inside the Worst Telecom Hack in US History

Chinese state-sponsored hackers compromised nine major US telecommunications carriers throughout 2024, accessing wiretap systems, call metadata for over a million users, and communications of presidential campaign staff.

January 17, 2026 Salt TyphoonChinatelecom
‹ Prev
1…567…9
Next ›
SYS ONLINE
PAGES 963
UPDATED 2026-02-06
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

// Sections

  • › News
  • › Rankings
  • › Companies
  • › Breaches

// Resources

  • › Guides
  • › Compliance
  • › Tags
  • › About

// Feeds

  • › All Content
  • › News Only
  • › Breaches Only

> © 2026 UINAT. All rights reserved.

[ DEFEND THE PERIMETER ]

Search