This cybersecurity publication for January 7, 2026, covers a series of critical threats and developments. Highlights include the disclosure of two maximum-severity unauthenticated and authenticated RCE vulnerabilities (CVSS 10.0) in the n8n automation platform, a major warning from Microsoft about a surge in phishing attacks exploiting email routing and DNS misconfigurations, and intelligence suggesting the Lapsus$ extortion group has resurfaced with evolved tactics. Other key stories include the 'Zestix' actor breaching 50 companies via stolen credentials on MFA-less portals, a ransomware attack on claims giant Sedgwick by the TridentLocker group, and significant updates to US data privacy laws and UK government cyber strategy.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.