UINAT
NewsRankingsCompaniesGuidesBreachesCompliance
TagsAbout
Home/News

Security News

Breaking cybersecurity news, vulnerability disclosures, and industry updates.

Allianz Life Breach Exposes 2.8 Million Records via Salesforce Attack

Scattered Spider and ShinyHunters breached Allianz Life's Salesforce CRM through OAuth app social engineering, exposing SSNs and personal data. The attack is part of a larger campaign targeting Google, Qantas, and LVMH.

January 16, 2026 AllianzShinyHuntersScattered Spider

Poland Repels Cyberattack on Power Grid, Attributes to Russia's Sandworm

Russia's Sandworm deployed DynoWiper malware against ~30 Polish energy facilities on December 29-30, 2025—the first major cyberattack targeting distributed energy resources. Some equipment was damaged beyond repair.

January 15, 2026 PolandSandwormRussia

Palo Alto Networks Completes $25 Billion Acquisition of CyberArk in Largest PAM Deal Ever

Palo Alto Networks finalizes its $25 billion acquisition of CyberArk Software with 99.8% shareholder approval, integrating privileged access management into Cortex and Strata platforms to address human, machine, and AI agent identities.

January 15, 2026 Palo Alto NetworksCyberArkacquisition

Microsoft Disrupts RedVDS Cybercrime Service Behind $40 Million in Fraud

Coordinated action with UK, German authorities, and Europol takes down subscription service that operated 2,600 VMs sending over 1 million phishing emails daily. Microsoft's 35th civil action against cybercrime.

January 14, 2026 Microsoftcybercrimefraud

Critical WordPress Plugin Vulnerability Actively Exploited in the Wild

CVE-2026-23550 in Modular DS plugin scores maximum CVSS 10.0, enabling unauthenticated privilege escalation. Attacks began January 13 targeting 40,000+ installations.

January 14, 2026 WordPressvulnerabilityexploitation

Belgian Hospital Shuts Down Systems After Cyberattack, Transfers Critical Patients

AZ Monica hospital in Antwerp shut down all servers at 6:32 AM after detecting ransomware, canceling 70+ operations and transferring 7 critical patients. Belgium pledged €10M for hospital cybersecurity.

January 13, 2026 healthcareransomwareBelgium

Microsoft January 2026 Patch Tuesday: 114 Vulnerabilities Fixed, Three Zero-Days

Monthly security update addresses 114 CVEs including CVE-2026-20805, a Windows Desktop Window Manager flaw under active exploitation enabling ASLR bypass. Eight critical RCE and privilege escalation flaws patched.

January 13, 2026 MicrosoftPatch Tuesdayvulnerabilities

SAP Patches Critical SQL Injection in S/4HANA with CVSS 9.9 Score

January 2026 Security Patch Day addresses 19 vulnerabilities including CVE-2026-0501, a critical SQL injection in S/4HANA's General Ledger that enables full system compromise through arbitrary SQL execution.

January 13, 2026 SAPSQL injectionpatch

Volt Typhoon Discovered Pre-Positioned in Additional US Critical Infrastructure Sectors

Joint CISA/NSA/FBI advisory reveals Chinese state-sponsored group Volt Typhoon has expanded persistent access into US water, energy, and transportation infrastructure, maintaining dormant footholds for 12-18 months undetected.

January 12, 2026 Volt TyphoonChinacritical infrastructure

BreachForums Database Leaked — 324,000 Cybercriminal Accounts Exposed

A former ShinyHunters member leaked the BreachForums user database with 324,000 accounts, including usernames, emails, password hashes, and 70,000 IP addresses. Law enforcement interest is likely.

January 10, 2026 BreachForumsShinyHuntersdark web

Russia's Fancy Bear APT Runs Low-Cost Credential Harvesting Campaign Against Global Targets

APT28 targets energy, defense, and policy organizations in Turkey, the Balkans, and Central Asia with phishing campaigns using legitimate PDFs from real think tanks and free hosting infrastructure.

January 9, 2026 APTRussiaFancy Bear

Disputifier Shopify App Hack Exposes 200,000+ Merchant Records

Exposed API tokens in Disputifier's frontend allowed attackers to process unauthorized refunds and exfiltrate data from Shopify merchants. The app was delisted after the company allegedly refused bug bounty negotiations.

January 9, 2026 ShopifyDisputifierdata breach
‹ Prev
1…6789
Next ›
SYS ONLINE
PAGES 963
UPDATED 2026-02-06
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

// Sections

  • › News
  • › Rankings
  • › Companies
  • › Breaches

// Resources

  • › Guides
  • › Compliance
  • › Tags
  • › About

// Feeds

  • › All Content
  • › News Only
  • › Breaches Only

> © 2026 UINAT. All rights reserved.

[ DEFEND THE PERIMETER ]

Search