This cybersecurity publication for January 7, 2026, covers a series of critical threats and developments. Highlights include the disclosure of two maximum-severity unauthenticated and authenticated RCE vulnerabilities (CVSS 10.0) in the n8n automation platform, a major warning from Microsoft about a surge in phishing attacks exploiting email routing and DNS misconfigurations, and intelligence suggesting the Lapsus$ extortion group has resurfaced with evolved tactics. Other key stories include the 'Zestix' actor breaching 50 companies via stolen credentials on MFA-less portals, a ransomware attack on claims giant Sedgwick by the TridentLocker group, and significant updates to US data privacy laws and UK government cyber strategy.
Help others stay informed about cybersecurity threats