Sami Laiho
@samilaiho.com
📤 1598
📥 179
📝 2748
Keynote-speaker, Chief Research Officer, Microsoft MVP since 2011 More info:
https://samilaiho.com/
thehackernews.com/2026/01/cert...
loading . . .
CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
A flaw in the binary-parser npm package before version 2.3.0 lets attackers execute arbitrary JavaScript via unsanitized parser input.
https://thehackernews.com/2026/01/certcc-warns-binary-parser-bug-allows.html
about 12 hours ago
0
1
0
securityaffairs.com/187110/hacki...
loading . . .
Critical TP-Link VIGI camera flaw allowed remote takeover of surveillance systems
TP-Link fixed a critical flaw that exposed over 32 VIGI C and VIGI InSight camera models to remote hacking.
https://securityaffairs.com/187110/hacking/critical-tp-link-vigi-camera-flaw-allowed-remote-takeover-of-surveillance-systems.html
about 12 hours ago
0
0
0
Don't click on the LastPass 'create backup' link - it's a scam
www.theregister.com/2026/01/21/l...
loading . . .
Don’t click the LastPass 'create backup' link
: Phishing campaign tries to reel in master passwords
https://www.theregister.com/2026/01/21/lastpass_backup_phishing_campaign/
about 12 hours ago
0
0
0
Tesla hacked, 37 zero-days demoed at Pwn2Own Automotive 2026
www.bleepingcomputer.com/news/securit...
loading . . .
Tesla hacked, 37 zero-days demoed at Pwn2Own Automotive 2026
Security researchers have hacked the Tesla Infotainment System and earned $516,500 after exploiting 37 zero-days on the first day of the Pwn2Own Automotive 2026 competition.
https://www.bleepingcomputer.com/news/security/tesla-hacked-37-zero-days-demoed-at-pwn2own-automotive-2026/
about 12 hours ago
0
0
0
ACF plugin bug gives hackers admin on 50,000 WordPress sites
www.bleepingcomputer.com/news/securit...
loading . . .
ACF plugin bug gives hackers admin on 50,000 WordPress sites
A critical-severity vulnerability in the Advanced Custom Fields: Extended (ACF Extended) plugin for WordPress can be exploited remotely by unauthenticated attackers to obtain administrative permission...
https://www.bleepingcomputer.com/news/security/acf-plugin-bug-gives-hackers-admin-on-50-000-wordpress-sites/
about 12 hours ago
0
0
0
VoidLink cloud malware shows clear signs of being AI-generated
www.bleepingcomputer.com/news/securit...
loading . . .
VoidLink cloud malware shows clear signs of being AI-generated
The recently discovered cloud-focused VoidLink malware framework is believed to have been developed by a single person with the help of an artificial intelligence model.
https://www.bleepingcomputer.com/news/security/voidlink-cloud-malware-shows-clear-signs-of-being-ai-generated/
about 12 hours ago
0
0
0
Oracle Critical Patch Update Advisory - January 2026 URL:
www.oracle.com/security-ale...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
loading . . .
https://www.oracle.com/security-alerts/cpujan2026.html
about 18 hours ago
0
0
0
www.greenbone.net/en/blog/cve-...
loading . . .
CVE-2025-64155: In the Wild Exploitation of FortiSIEM for Unauthenticated Root-Level RCE
CVE-2025-64155 in FortiSIEM disclosed ⚡ Actively exploited unauthenticated root RCE. Secure systems now.
https://www.greenbone.net/en/blog/cve-2025-64155-fortisiem-root-rce-cvss-9-8/
1 day ago
0
0
0
For the price of Netflix, crooks can now rent AI to run cybercrime
www.theregister.com/2026/01/20/g...
loading . . .
For the price of Netflix, crooks can rent AI crime ops
: Group-IB says crims forking out for Dark LLMs, deepfakes, and more at subscription prices
https://www.theregister.com/2026/01/20/group_ib_ai_cycercrime_subscriptions/
1 day ago
0
0
0
Google Gemini Flaw Turns Calendar Invites Into Attack Vector
www.darkreading.com/cloud-securi...
loading . . .
Google Gemini Flaw Turns Calendar Invites Into Attack Vector
The indirect prompt injection vulnerability allows an attacker to weaponize Google invites to circumvent privacy controls and access private data.
https://www.darkreading.com/cloud-security/google-gemini-flaw-calendar-invites-attack-vector
1 day ago
0
1
0
Fake ad blocker extension crashes the browser for ClickFix attacks
www.bleepingcomputer.com/news/securit...
loading . . .
Fake ad blocker extension crashes the browser for ClickFix attacks
A malvertising campaign is using a fake ad-blocking Chrome and Edge extension named NexShield that intentionally crashes the browser in preparation for ClickFix attacks.
https://www.bleepingcomputer.com/news/security/fake-ad-blocker-extension-crashes-the-browser-for-clickfix-attacks/
1 day ago
0
0
0
New PDFSider Windows malware deployed on Fortune 100 firm's network
www.bleepingcomputer.com/news/securit...
loading . . .
New PDFSider Windows malware deployed on Fortune 100 firm's network
Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.
https://www.bleepingcomputer.com/news/security/new-pdfsider-windows-malware-deployed-on-fortune-100-firms-network/
1 day ago
0
0
0
reposted by
Sami Laiho
Atla Hrafney
3 days ago
In the 2010s, the Icelandic tv station Channel 2 accidentally added subtitles from a gritty crime drama to an episode of Teletubbies. I have translated some of the highlights
94
6792
3258
seclists.org/oss-sec/2026...
GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
loading . . .
oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
https://seclists.org/oss-sec/2026/q1/89
2 days ago
0
1
0
UK govt. warns about ongoing Russian hacktivist group attacks
www.bleepingcomputer.com/news/securit...
loading . . .
UK govt. warns about ongoing Russian hacktivist group attacks
The U.K. government is warning of continued malicious activity from Russian-aligned hacktivist groups targeting critical infrastructure and local government organizations in the country in disruptive ...
https://www.bleepingcomputer.com/news/security/uk-govt-warns-about-ongoing-russian-hacktivist-group-attacks/
3 days ago
0
0
0
ABB Ability OPTIMAX Authentication Bypass in Single-Sign On with Azure Active Directory URL:
search.abb.com/library/Down...
loading . . .
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A1331
3 days ago
0
0
0
ABB Ability OPTIMAX Authentication Bypass in Single-Sign On with Azure Active Directory URL:
search.abb.com/library/Down...
loading . . .
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A1331
3 days ago
0
0
0
JVNDB-2026-001380 Multiple vulnerabilities in Canon Small Office Multifunction Printers and Laser Printers URL:
jvndb.jvn.jp/en/contents/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.8
loading . . .
JVNDB-2026-001380 - JVN iPedia
https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-001380.html
3 days ago
0
0
0
AVEVA Process Optimization URL:
www.cisa.gov/news-events/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
loading . . .
AVEVA Process Optimization | CISA
https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01
3 days ago
0
0
0
Malicious GhostPoster browser extensions found with 840,000 installs
www.bleepingcomputer.com/news/securit...
loading . . .
Malicious GhostPoster browser extensions found with 840,000 installs
Another set of 17 malicious extensions linked to the GhostPoster campaign has been discovered in Chrome, Firefox, and Edge stores, where they accumulated a total of 840,000 installations.
https://www.bleepingcomputer.com/news/security/malicious-ghostposter-browser-extensions-found-with-840-000-installs/
4 days ago
0
1
0
Iran’s internet shutdown is now one of its longest ever, as protests continue
techcrunch.com/2026/01/15/i...
loading . . .
Iran’s internet shutdown is now one of its longest ever, as protests continue | TechCrunch
Iran’s government-imposed internet shutdown enters its second week as authorities continue their violent crackdown on protesters.
https://techcrunch.com/2026/01/15/irans-internet-shutdown-is-now-one-of-its-longest-ever-as-protests-continue/
5 days ago
0
2
0
Canadian investment regulator confirms hackers hit 750,000 investors
therecord.media/canada-ciro-...
loading . . .
Canadian investment regulator confirms hackers hit 750,000 investors
The nongovernmental Canadian Investment Regulatory Organization, which oversees the country's debt and equity marketplaces as well as some financial institutions, released details about an August 2025...
https://therecord.media/canada-ciro-investing-regulator-confirms-data-breach
5 days ago
0
2
0
Winter Olympics Could Share Podium With Cyberattackers
www.darkreading.com/remote-workf...
loading . . .
Cyber Threats Loom Over 2026 Winter Olympics
The Games in the Italian Alps are attracting hacktivists looking to reach billions of people and state-sponsored cyber-spies targeting the glitterati.
https://www.darkreading.com/remote-workforce/winter-olympics-podium-cyberattackers
5 days ago
0
1
0
Black Basta boss makes it onto Interpol's 'Red Notice' list
www.bleepingcomputer.com/news/securit...
loading . . .
Black Basta boss makes it onto Interpol's 'Red Notice' list
The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol.
https://www.bleepingcomputer.com/news/security/black-basta-boss-makes-it-onto-interpols-red-notice-list/
5 days ago
0
0
0
cymulate.com/blog/cve-202...
loading . . .
CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center
Cymulate Research Labs uncovered CVE-2026-20965, a token validation flaw in Azure Windows Admin Center enabling tenant-wide RCE and lateral movement.
https://cymulate.com/blog/cve-2026-20965-azure-windows-admin-center-tenant-wide-rce/
5 days ago
0
1
0
CISA, Allies Sound Alarm on OT Network Exposure
www.databreachtoday.com/cisa-allies-...
loading . . .
CISA, Allies Sound Alarm on OT Network Exposure
U.S. and allied cyber agencies issued new guidance warning that insecure operational technology connectivity - driven by remote access, third-party vendors and IT
https://www.databreachtoday.com/cisa-allies-sound-alarm-on-ot-network-exposure-a-30534
5 days ago
0
0
0
CISA, Allies Sound Alarm on OT Network Exposure
www.databreachtoday.com/cisa-allies-...
loading . . .
CISA, Allies Sound Alarm on OT Network Exposure
U.S. and allied cyber agencies issued new guidance warning that insecure operational technology connectivity - driven by remote access, third-party vendors and IT
https://www.databreachtoday.com/cisa-allies-sound-alarm-on-ot-network-exposure-a-30534
5 days ago
0
1
1
Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks
www.bleepingcomputer.com/news/securit...
loading . . .
Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks
Attackers are now exploiting a critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code.
https://www.bleepingcomputer.com/news/security/hackers-now-exploiting-critical-fortinet-fortisiem-vulnerability-in-attacks/
5 days ago
0
0
0
Cisco finally fixes AsyncOS zero-day exploited since November
www.bleepingcomputer.com/news/securit...
loading . . .
Cisco finally fixes AsyncOS zero-day exploited since November
​Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025.
https://www.bleepingcomputer.com/news/security/cisco-finally-fixes-asyncos-zero-day-exploited-since-november/
5 days ago
0
1
0
Google now lets you change your @gmail.com address, rolling out
www.bleepingcomputer.com/news/technol...
loading . . .
Google now lets you change your @gmail.com address, rolling out
Google has confirmed that it's now possible to change your @gmail.com address. This means that if your current email is
[email protected]
, you can now change it to
[email protected]
.
https://www.bleepingcomputer.com/news/technology/google-now-lets-you-change-your-gmailcom-address-rolling-out/
5 days ago
0
1
0
www.darkreading.com/remote-workf...
loading . . .
'Most Severe AI Vulnerability to Date' Hits ServiceNow
The ITSM giant tacked agentic AI onto a largely unguarded legacy chatbot, exposing customers' data and connected systems.
https://www.darkreading.com/remote-workforce/ai-vulnerability-servicenow
6 days ago
0
1
0
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation
cloud.google.com/blog/topics/...
loading . . .
Releasing Rainbow Tables to Accelerate Protocol Deprecation | Google Cloud Blog
Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1.
https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables/
6 days ago
0
0
1
Critical flaw lets hackers track, eavesdrop via Bluetooth audio devices
www.bleepingcomputer.com/news/securit...
loading . . .
Critical WhisperPair flaw lets hackers track, eavesdrop via Bluetooth audio devices
A critical vulnerability in Google's Fast Pair protocol can allow attackers to hijack Bluetooth audio accessories like wireless headphones and earbuds, track users, and eavesdrop on their conversation...
https://www.bleepingcomputer.com/news/security/critical-flaw-lets-hackers-track-eavesdrop-via-bluetooth-audio-devices/
6 days ago
0
1
0
Trio of Critical Bugs Spotted in Delta Industrial PLCs
www.darkreading.com/ics-ot-secur...
loading . . .
Trio of Critical Bugs Spotted in Delta Industrial PLCs
Experts disagree on whether the vulnerabilities in a programmable logic controller from Delta are a five-alarm fire or not much to worry over.
https://www.darkreading.com/ics-ot-security/critical-bugs-delta-industrial-plcs
6 days ago
0
0
0
A simple CodeBuild flaw put every AWS environment at risk – and pwned 'the central nervous system of the cloud'
www.theregister.com/2026/01/15/c...
loading . . .
A simple CodeBuild flaw put every AWS environment at risk
: And it's 'not unique to AWS,' researcher tells The Reg
https://www.theregister.com/2026/01/15/codebuild_flaw_aws/
6 days ago
0
1
0
UAT-8837 targets critical infrastructure sectors in North America
blog.talosintelligence.com/uat-8837/
loading . . .
UAT-8837 targets critical infrastructure sectors in North America
Cisco Talos is closely tracking UAT-8837, a threat actor we assess with medium confidence is a China-nexus advanced persistent threat (APT) actor.
https://blog.talosintelligence.com/uat-8837/
6 days ago
0
0
0
New Remcos Campaign Distributed Through Fake Shipping Document
www.fortinet.com/blog/threat-...
loading . . .
New Remcos Campaign Distributed Through Fake Shipping Document
FortiGuard Labs analyzes a phishing campaign delivering a fileless Remcos RAT via malicious Word templates, CVE-2017-11882 exploitation, and in-memory execution.…
https://www.fortinet.com/blog/threat-research/new-remcos-campaign-distributed-through-fake-shipping-document
6 days ago
0
0
0
Critical Privilege Escalation Vulnerability in Modular DS plugin affecting 40k+ Sites exploited in the wild URL:
patchstack.com/articles/cri...
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0
loading . . .
Critical Privilege Escalation Vulnerability in Modular DS plugin affecting 40k+ Sites exploited in the wild - Patchstack
Unauthenticated privilege escalation vulnerability discovered in the Modular DS plugin. 🚨 Learn how attackers gain wp-admin access, active exploitation details, and how to stay protected.
https://patchstack.com/articles/critical-privilege-escalation-vulnerability-in-modular-ds-plugin-affecting-40k-sites-exploited-in-the-wild/
7 days ago
0
0
0
learn.microsoft.com/en-us/answer...
loading . . .
Lenova laptop no longer shutdown after installing KB5073455 - Microsoft Q&A
Hello all, it is very critical, effecting multiple systems, Lenova laptop no longer shutdown after installing KB5073455, any idea or bug from Microsoft for the same
https://learn.microsoft.com/en-us/answers/questions/5708943/lenova-laptop-no-longer-shutdown-after-installing
7 days ago
0
3
0
state-of-iranblackout.whisper.security
loading . . .
Iran Internet Shutdown Report | Whisper
Forensic analysis of Iran's coordinated internet shutdown with real-time BGP and censorship data.
https://state-of-iranblackout.whisper.security/
7 days ago
0
0
0
www.bleepingcomputer.com/news/securit...
loading . . .
Palo Alto Networks warns of DoS bug letting hackers disable firewalls
Palo Alto Networks patched a high-severity vulnerability that could allow unauthenticated attackers to disable firewall protections in denial-of-service (DoS) attacks.
https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-dos-bug-letting-hackers-disable-firewalls/
7 days ago
0
0
0
Exploit code public for critical FortiSIEM command injection flaw
www.bleepingcomputer.com/news/securit...
loading . . .
Exploit code public for critical FortiSIEM command injection flaw
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinet's Security Information and Event Management (SIEM) solution that could be leveraged by a remo...
https://www.bleepingcomputer.com/news/security/exploit-code-public-for-critical-fortisiem-command-injection-flaw/
7 days ago
0
0
0
France fines telcos €42M for sub-par security prior to 24M customer breach
www.theregister.com/2026/01/14/f...
loading . . .
France fines telcos €42M for issues leading to 2024 breach
: Three major GDPR violations, including a lack of basic security controls, lead to hefty dent in profits
https://www.theregister.com/2026/01/14/france_fines_free_free_mobile/
7 days ago
0
1
0
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
www.varonis.com/blog/reprompt
loading . . .
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
Varonis Threat Labs discovered a way to bypass Copilot’s safety controls, steal users’ darkest secrets, and evade detection.
https://www.varonis.com/blog/reprompt
7 days ago
0
0
0
Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations
www.microsoft.com/en-us/securi...
loading . . .
Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations | Microsoft Security Blog
Microsoft’s investigation into RedVDS services and infrastructure uncovered a global network of disparate cybercriminals purchasing and using to target multiple sectors. In collaboration with law enfo...
https://www.microsoft.com/en-us/security/blog/2026/01/14/inside-redvds-how-a-single-virtual-desktop-provider-fueled-worldwide-cybercriminal-operations/
7 days ago
0
0
0
Designing safer links: secure connectivity for operational technology
www.ncsc.gov.uk/blog-post/de...
loading . . .
Designing safer links: secure connectivity for operational technology
New principles help organisations to design, review, and secure connectivity to (and within) OT systems.
https://www.ncsc.gov.uk/blog-post/designing-safer-links-secure-connectivity-for-ot
7 days ago
0
0
0
Cyberattack forces Belgian hospital to transfer critical care patients
therecord.media/belgium-hosp...
loading . . .
Cyberattack forces Belgian hospital to transfer critical care patients
The AZ Monica hospital system in Antwerp reported a cyberattack that required the assistance of the Red Cross to send several patients to other facilities.
https://therecord.media/belgium-hospital-cyberattack-antwerp-az-monica
7 days ago
0
0
0
www.bleepingcomputer.com/news/securit...
loading . . .
Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners
Cloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP cust...
https://www.bleepingcomputer.com/news/security/cloud-marketplace-pax8-accidentally-exposes-data-on-1-800-msp-partners/
8 days ago
0
1
2
1980s Hacker Manifesto
www.schneier.com/blog/archive...
loading . . .
1980s Hacker Manifesto - Schneier on Security
Forty years ago, The Mentor—Loyd Blankenship—published “The Conscience of a Hacker” in Phrack. You bet your ass we’re all alike… we’ve been spoon-fed baby food at school when we hungered for steak… th...
https://www.schneier.com/blog/archives/2026/01/1980s-hacker-manifesto.html
8 days ago
0
0
0
Signal creator Moxie Marlinspike wants to do for AI what he did for messaging
arstechnica.com/security/202...
loading . . .
Signal creator Moxie Marlinspike wants to do for AI what he did for messaging
Introducing Confer, an end-to-end AI assistant that just works.
https://arstechnica.com/security/2026/01/signal-creator-moxie-marlinspike-wants-to-do-for-ai-what-he-did-for-messaging/
8 days ago
0
0
1
Load more
feeds!
log in