IT Security Newsletter

IT Security Newsletter - 1/20/2026

Written by Cadre | Tue, Jan 20, 2026

Hacker admits to leaking stolen Supreme Court data on Instagram

A Tennessee man has pleaded guilty to hacking the U.S. Supreme Court's electronic filing system and breaching accounts at the AmeriCorps U.S. federal agency and the Department of Veterans Affairs. Federal prosecutors said that 24-year-old Nicholas Moore, of Springfield, Tennessee, had accessed the Supreme Court's restricted electronic filing system at least 25 times between August and October 2023 using stolen credentials. READ MORE...

Initial access broker pleads guilty to selling access to 50 corporate networks

A 40-year-old Jordanian man has admitted to selling unauthorized access to computer networks of at least 50 companies, the US Attorney's Office of the District of New Jersey has announced. Feras Khalil Ahmad Albashiti has pleaded guilty last Thursday to fraud and related activity in connection with access devices. The threat actor was spotted offering 30 SonicVPN and 50 Microsoft Exchange accesses with a 'working exploit' on XXS Forum in June 2022. READ MORE...

Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution

Anthropic has fixed three bugs in its official Git MCP server that researchers say can be chained with other MCP tools to remotely execute malicious code or overwrite files via prompt injection. The Git MCP server, mcp-server-git, connects AI tools such as Copilot, Claude, and Cursor to Git repositories and the GitHub platform, allowing them to read repositories and code files, and automate workflows, all using natural language interactions. READ MORE...

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

TP-Link has patched a serious vulnerability that can be exploited to take control of more than 32 of its VIGI C and VIGI InSight series professional surveillance camera models. The security hole, tracked as CVE-2026-0629 and classified as high severity, is described in a TP-Link advisory published last week as an authentication bypass flaw affecting the password recovery feature in the cameras' local web interface. READ MORE...

New PDFSider Windows malware deployed on Fortune 100 firm's network

Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems. The attackers employed social engineering in their attempt to gain remote access by impersonating technical support workers and to trick company employees into installing Microsoft's Quick Assist tool. Researchers at cybersecurity company Resecurity found PDFSider during an incident response. READ MORE...

Predator bots are exploiting APIs at scale. Here's how defenders must respond.

The rise of malicious bots is changing how the internet operates, underscoring the need for stronger safeguards that keep humans firmly in control. Bots now account for more than half of global web traffic, and a new class of "predator bots" has emerged, unleashing self-learning programs that adapt in real time, mimic human behavior, and exploit APIs and business logic in order to steal data, scalp goods, and hijack transactions. READ MORE...

Fake browser crash alerts turn Chrome extension into enterprise backdoor

Browser extensions are a high-risk attack vector for enterprises, allowing threat actors to bypass traditional security controls and gain a foothold on corporate endpoints. Case in point: A recently identified malicious extension called NexShield proves that a single user install from an official and nominally safe online marketplace can escalate into full remote access. Huntress researchers found that it downloads a previously undocumented Windows remote access trojan. READ MORE...

ChatGPT Health Raises Big Security, Safety Concerns

The recent announcement of LLM health chatbot product ChatGPT Health suggests a world where health advice will be at the consumer's fingertips more than ever before, but with the product also comes a wide range of safety and data security concerns. On Jan. 7, OpenAI announced ChatGPT Health, described by the LLM firm as "a dedicated experience that securely brings your health information and ChatGPT's intelligence together." READ MORE...

Meet Veronika, the tool-using cow

Far Side fans might recall a classic 1982 cartoon called "Cow Tools," featuring a cow standing next to a jumble of strange objects-the joke being that cows don't use tools. That's why a pet Swiss brown cow in Austria named Veronika has caused a bit of a sensation: she likes to pick up random sticks and use them to scratch herself. According to a new paper published in the journal Current Biology, this suggests that the cognitive capabilities of cows have been underestimated by scientists. READ MORE...

  • ...in 1918, Mexican composer and bandleader Juan Garcia Esquivel, known as "The King of Space Age Pop", is born in Tampico, Mexico.
  • ...in 1920, actor DeForest Kelley, best known as Dr. Leonard "Bones" McCoy from "Star Trek", is born in Toccoa, GA.
  • ...in 1946, film/TV director and screenwriter David Lynch ("Blue Velvet", "Twin Peaks") is born in Missoula, MT.
  • ...in 2009, Barack Obama is inaugurated as the 44th President of the United States, becoming the first African-American man to hold the office.