This cybersecurity brief for January 9, 2026, covers a critical unauthenticated RCE vulnerability (CVSS 10.0) in the n8n platform, revelations that a Chinese state-sponsored actor possessed a VMware ESXi zero-day exploit for over a year before its disclosure, and an FBI warning about North Korean 'quishing' campaigns. Other major events include data breaches affecting London councils and New Zealand's largest patient portal, new malware strains like Ripper Ransomware, and CISA adding actively exploited flaws in HPE and legacy PowerPoint to its KEV catalog.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.