Vendors
-
Palo Alto Networks to acquire Koi in deal aimed at agentic AI security
Palo Alto Networks announced plans to buy Koi to address risks from agentic AI. Terms were not disclosed, but a report by Globes said the payment will be about 400 million dollars.
-
Law firm sues Lenovo over alleged bulk transfer of US data to China
A law firm filed a class action accusing Lenovo of exposing 100,000 or more US consumers’ data to Chinese entities via website trackers. The suit seeks class action relief, restitution, disgorgement and statutory damages.
-
SmartLoader campaign trojanized Oura MCP server to deliver StealC infostealer
A SmartLoader campaign trojanized an Oura MCP server to deliver the StealC infostealer using fake GitHub accounts. The trojanized server remains listed on the MCP registry.
-
Developer beta adds end-to-end encryption for RCS in iOS and iPadOS 26.4
The iPhone maker released an iOS and iPadOS 26.4 developer beta that adds end-to-end encryption for RCS messages in testing, limited to the company’s devices, and includes Memory Integrity Enforcement and stolen device protections.
-
Google patches actively exploited Chrome zero-day CVE-2026-2441
Google released Chrome updates to fix CVE-2026-2441, a high severity use after free bug in CSS that is being exploited in the wild. Users should update Chrome to the patched versions to reduce risk.
-
In-the-wild exploitation observed for critical BeyondTrust RCE CVE-2026-1731
Researchers observed overnight exploitation attempts for CVE-2026-1731 targeting BeyondTrust Remote Support and Privileged Remote Access. The flaw is rated CVSS 9.9. Patches are available for affected versions and administrators should apply updates immediately.
-
Odido cyberattack exposes personal data of 6.2 million customers
A Dutch telecom provider detected a cyberattack that exposed personal data for about 6.2 million customers. The provider blocked access, notified the data regulator, and is emailing affected customers with details.
-
Apple issues updates to fix exploited dyld zero-day across iOS, macOS and other platforms
Apple released multiple OS updates to fix an exploited dyld memory corruption zero-day, CVE-2026-20700. The advisory credits Google Threat Analysis Group. Users should install the published updates for their devices.
-
Warlock ransomware breaches network through unpatched SmarterMail instance
A SmarterTools community advisory says the Warlock gang breached an unpatched SmarterMail instance on January 29, 2026, affecting about 12 Windows servers and a secondary data center. Updates and isolation were recommended to limit spread.
-
Conduent breach exposed personal data of nearly 17,000 Volvo employees
Nearly 17,000 US Volvo employees had personal data exposed after a Conduent breach. A Maine Attorney General filing shows 16,991 people were affected, with intruder access dated October 21, 2024 to January 13, 2025.










