Multiple outlets published weekly cybersecurity roundups summarizing a mix of vulnerability disclosures, ransomware/breach reporting, and policy developments rather than a single discrete incident. TechTarget highlighted a surge in reported vulnerabilities (citing 48,000+ new CVEs in 2025) and called out several high-impact issues, including a critical ServiceNow weakness tied to weak authentication in the legacy Virtual Agent chatbot that became more dangerous when paired with agentic AI (Now Assist), potentially enabling impersonation and admin-level access into connected enterprise systems.
Other roundup coverage aggregated unrelated security events across sectors. Sherpa Intelligence’s “Five for Friday” compiled items including ransomware claims (e.g., Everest targeting Nissan; Nightspire claiming an attack on a Hyatt Place property) and breach reporting (e.g., a Korean Air employee-data breach attributed to Clop). The Cyber Express weekly roundup similarly mixed disparate topics (platform policy changes around AI abuse, senior government appointments, and national-level connectivity disruptions), reinforcing that the common thread is curation of multiple stories rather than new primary reporting on one specific cyber event.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
39 events from the most recent confirmed update back to the earliest known activity.
The UK's National Cyber Security Centre warned about Russia-linked hacktivist distributed denial-of-service activity. The warning underscored ongoing geopolitical cyber disruption risks.
CISA added several additional vulnerabilities to its Known Exploited Vulnerabilities catalog in late January 2026. The update was referenced alongside multiple vendor advisories as exploitation activity continued to expand.
Feras Khalil Ahmad Albashiti pleaded guilty to selling access to at least 50 corporate networks as an initial access broker. The plea was highlighted as a significant cybercrime law-enforcement outcome.
Security reporting said some fully patched FortiGate firewalls were still being compromised, possibly in connection with CVE-2025-59718. The development raised concerns that fixes or post-exploitation persistence issues were not fully resolved.
By late January, reporting indicated active probing of critical Cisco remote code execution flaw CVE-2026-20045. The activity suggested attackers were rapidly testing exposure before broad remediation could occur.
Cisco Talos disclosed multiple vulnerabilities affecting Foxit PDF Editor, Epic Games Store, and MedDream PACS, and vendors issued patches. The flaws included privilege escalation, use-after-free, and cross-site scripting issues that could enable code execution or unauthorized access.
Dutch police were reported to be operating a fake ticket website as a public anti-scam education effort. The initiative was presented as a proactive law-enforcement awareness campaign.
Slack published the design of an internal multi-agent triage system intended to reduce investigation time while preserving quality checks before human escalation. The architecture was highlighted as a notable security operations engineering development.
Google and Mandiant released Net-NTLMv1 rainbow tables to accelerate pressure for deprecating the weak authentication scheme. The release was framed as a defensive move to expose the protocol's continued risk.
Researchers reported 'CodeBreach,' an AWS CodeBuild misconfiguration that could have enabled supply-chain compromise of AWS GitHub repositories. The issue was highlighted as a cloud and software supply-chain risk.
CyberArk researchers exploited a cross-site scripting flaw in the StealC malware control panel to observe and hijack operator sessions. The work demonstrated offensive counterintelligence opportunities against criminal infrastructure.
Academic researchers disclosed 'WhisperPair' vulnerabilities affecting Google Fast Pair audio accessories from multiple major vendors. The flaws raised concerns about the security of widely used Bluetooth pairing ecosystems.
The Qilin ransomware group claimed Moen as a victim, though reporting said no proof of exfiltration was provided. The claim was included in roundup coverage of current ransomware activity.
Grubhub confirmed unauthorized access to internal systems while extortion claims circulated involving Salesforce and Zendesk-related data. The company acknowledgment marked the incident as an active enterprise breach response.
CIRO publicly disclosed that the August 2025 phishing attack exposed personal information belonging to roughly 750,000 individuals. The organization said some systems were shut down, but critical operations were not affected.
Threat researchers published analysis of VoidLink, a China-affiliated cloud-native Linux malware framework designed for stealthy long-term access. Coverage noted the framework's capabilities even though no confirmed infections were reported.
Reporting highlighted active exploitation or disclosure of a WordPress plugin vulnerability, tracked in one roundup as CVE-2026-23550, that allowed unauthenticated administrator takeover. The issue was treated as a high-risk web application threat.
Researchers reported active exploitation of CVE-2025-37164, a critical HPE OneView remote code execution flaw, by the RondoDox botnet. The vulnerability was also noted as added to CISA's KEV catalog.
Lumen reported null-routing and blocking more than 550 command-and-control servers tied to AISURU and Kimwolf botnet activity. The action was presented as a major infrastructure disruption against DDoS-related operations.
CISA added actively exploited vulnerabilities in Microsoft Windows and Gogs to its Known Exploited Vulnerabilities catalog. The move signaled elevated urgency for defenders to patch affected systems.
A joint Ukraine-Germany operation targeted Black Basta leadership, with reporting also linking Black Basta to Conti through blockchain analysis. The action was highlighted in multiple weekly roundups.
Spanish authorities, supported by Europol, carried out an operation against the Black Axe criminal organization. The action was cited as a significant law-enforcement move against cyber-enabled fraud.
A breach affecting Eurail and Interrail travelers was reported in weekly security coverage. The incident was highlighted as a notable consumer-impacting data exposure.
Public proof-of-concept exploit code was released for critical Fortinet FortiSIEM flaw CVE-2025-64155, an unauthenticated issue that could lead to remote code execution via crafted TCP requests. Multiple roundups also described thousands of internet-exposed instances at risk.
Meta denied claims that Instagram had suffered a breach exposing data from 17.5 million accounts. The denial came amid reports that users were seeing repeated password reset prompts.
A privilege-escalation issue involving Google Vertex AI service agents was reported in mid-January 2026. The finding was highlighted as a cloud security concern in roundup coverage.
Security researchers reported the 'Reprompt' attack, which used prompt injection and URL parameter abuse to enable stealthy data exfiltration from Microsoft Copilot. Later roundup coverage noted the issue had since been fixed.
A separate Clop-linked breach was reported to have affected Korean Air employee records. The incident appeared in roundup reporting on notable enterprise data exposures.
The Everest ransomware group was reported as targeting Nissan following an earlier breach involving ASUS. The development was cited as part of ongoing ransomware victim disclosures.
The Nightspire ransomware group claimed it attacked the Hyatt Place New York / Chelsea Hotel. The claim was reported in a January 16 roundup of current ransomware activity.
Microsoft, working with international law enforcement and through related legal action, disrupted the RedVDS cybercrime-as-a-service platform. RedVDS had been used to support large-scale phishing and fraud operations.
Researchers reported a new Android banking malware family, deVixor, targeting users in Iran through phishing-distributed APK files. The malware was presented as an emerging mobile banking threat.
Spanish energy company Endesa disclosed a breach affecting customers of its Energía XXI unit. Subsequent reporting described the incident as a large-scale data exposure tied to Spain.
Iran experienced a fourth consecutive day of nationwide internet disruption during unrest linked to the collapse of the rial. The blackout was reported as a major public-stability and information-control event.
The NSA named Timothy Kosiba as its 21st Deputy Director. The appointment was cited as a significant U.S. national security leadership development in mid-January 2026.
X, formerly Twitter, tightened controls on Grok AI to curb generation of nonconsensual sexualized images. The move followed reported abuse and investigations by U.S. and European authorities.
Microsoft's January 2026 Patch Tuesday addressed 114 vulnerabilities, including an actively exploited Desktop Window Manager zero-day tracked as CVE-2026-20805. The update was highlighted across multiple January security roundups.
Reporting later attributed a late-2025 cyberattack on Poland's power grid to the Russia-linked Sandworm group. The attribution appeared in January 2026 roundup coverage as a notable geopolitical development.
In August 2025, a sophisticated phishing attack compromised the personal information of about 750,000 individuals tied to the Canadian Investment Regulatory Organization. Some systems were shut down in response, but critical functions were reported as unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourceblog.talosintelligence.com
Open sourcelinkedin.com
Open sourcesecurityaffairs.com
Open sourcesherpaintelligence.substack.com
Open sourcetechtarget.com
Open sourcethecyberexpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.