<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 1/7/2026

SHARE

Breaches

Sedgwick confirms breach at government contractor subsidiary

Claims administration and risk management company Sedgwick has confirmed that its federal contractor subsidiary, Sedgwick Government Solutions, was the victim of a security breach. Sedgwick also employs over 33,000 people and serves 10,000 clients across 80 countries, including 59% of the Fortune 500, and its subsidiary serves over 20+ government agency clients. A Sedgwick spokesperson said that the company is currently investigating a security breach that impacted its subsidiary. READ MORE...

Hacking

One million customers on alert as extortion group claims massive Brightspeed data haul

US fiber broadband company Brightspeed is investigating claims by the Crimson Collective extortion group that it stole sensitive data belonging to more than 1 million residential customers, including extensive personally identifiable information (PII), as well as account and billing details. Brightspeed is one of the largest fiber broadband providers in the US and serves customers across 20 states. READ MORE...


Scattered Lapsus$ Hunters Snared in Cyber Researcher Honeypot

Researchers with the security firm Resecurity said they caught threat actors from Scattered Lapsus$ Hunters in a honeypot using what the company described as "synthetic data." Resecurity announced the development on Jan. 3 as an update to a December post describing how a threat actor (not necessarily affiliated with the aforementioned group) probed Resecurity's resources looking for a way to get a hold of sensitive company data. READ MORE...

Trends

Gen AI data violations more than double

Security teams track activity that moves well beyond traditional SaaS platforms, with employees interacting daily with generative AI tools, personal cloud services, and automated systems that exchange data without direct human input. These patterns shape how sensitive information moves across corporate environments and where security controls apply. The Cloud and Threat Report 2026 from Netskope examines this shifting activity through telemetry collected over the past year. READ MORE...

Software Updates

Critical Dolby Vulnerability Patched in Android

The January 2026 Android update patches a single vulnerability, a critical Dolby audio decoder issue whose existence came to light in October 2025. The flaw, tracked as CVE-2025-54957, was described at the time of its disclosure as a medium-severity out-of-bounds write issue impacting the widely used Dolby Digital Plus (DD+) Unified Decoder. The vulnerability, exploitable using specially crafted media files, was discovered by Google researchers and reported to Dolby in June 2025. READ MORE...

Exploits/Vulnerabilities

Hackers Exploit Zero-Day in Discontinued D-Link Devices

An OS command injection vulnerability in discontinued D-Link gateway devices has been exploited in the wild as a zero-day. Tracked as CVE-2026-0625 (CVSS score of 9.3), the security defect exists because the dnscfg.cgi library does not properly sanitize user-supplied DNS configuration parameters. The issue allows remote, unauthenticated attackers to inject and execute arbitrary shell commands, achieving remote code execution (RCE), vulnerability intelligence company VulnCheck explains. READ MORE...


New Veeam vulnerabilities expose backup servers to RCE attacks

Veeam released security updates to patch multiple security flaws in its Backup & Replication software, including a critical remote code execution (RCE) vulnerability. This RCE security flaw affects Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds. "This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter," Veeam explained in a Tuesday advisory. READ MORE...

On This Date

  • ...in 1782, the first American commercial bank, the Bank of North America, opens.
  • ...in 1912, artist Charles Addams, the creator of the original "The Addams Family" cartoons in "The New Yorker", is born in Westfield, NJ.
  • ...in 1954, IBM gives the first public demonstration of machine translation, in which an IBM 701 mainframe translated 60 Russian phrases to English.
  • ...in 1964, actor Nicolas Cage ("National Treasure", "Raising Arizona") is born in Long Beach, CA.