A tumultuous day in cybersecurity for January 26, 2026, is marked by high-impact ransomware, critical zero-day vulnerabilities, and sophisticated nation-state espionage. The newly identified QuantumLeap ransomware has crippled logistics giant NaviGistics, demanding a $50 million ransom. Concurrently, a wormable RCE zero-day (CVE-2026-12345) in the NexusFlow API Gateway and a zero-click flaw (CVE-2026-23456) in iOS and Android are under active attack. Other major incidents include a supply chain attack on a popular NPM package, an AI-powered phishing campaign bypassing MFA, and continued espionage from threat actors like Volt Typhoon and SteelHydra targeting critical infrastructure and renewable energy sectors.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.