Latest Internet & Cybersecurity News

đź“…January 17, 2026 at 1:00 AM
Early 2026 sees ransomware surges, major data breaches at Nissan and TotalEnergies, Microsoft takedowns, critical patches, and rising AI-driven cyber threats globally.
1

Nissan Hit by Everest Ransomware, 900GB Data Stolen

Japanese automaker Nissan suffered a ransomware attack by the Everest group, which claims to have exfiltrated 900GB of sensitive data including internal records and dealer information. The breach was announced on January 10, 2026, raising concerns for global operations.Source 6 No ransom payment or recovery details have been disclosed yet.Source 6

2

TotalEnergies Alleged Data Breach Exposes 183M Records

Hackers claiming affiliation with HawkSec announced stealing nearly 184 million records from TotalEnergies, including bank details of French customers. The group posted samples on social media and a data leak forum, though legitimacy remains unverified.Source 8 HawkSec also claimed breaches at Discord and Orange Rwanda.Source 8

3

Microsoft Disrupts RedVDS Infrastructure for BEC Attacks

Microsoft used UK and US courts to seize domains of RedVDS, a virtual desktop service enabling phishing, business email compromises, and scams causing $40M in losses.Source 1Source 3 This action targets infrastructure widely used for malicious virtual machines.Source 3

4

Palo Alto Networks Patches Critical CVE-2026-0227 in PAN-OS

Palo Alto released updates for a high-severity vulnerability in GlobalProtect Gateway and Portal that enables denial-of-service attacks due to improper exception handling.Source 1Source 4 A proof-of-concept exploit is publicly available.Source 4 Organizations urged to patch immediately.Source 1

5

Instagram Data Leak Affects 17.5M Users

Threat actor 'Solonik' leaked data of 17.5 million Instagram users on dark web forums, including emails, phones, names, and geodata from a 2024 API breach.Source 2 This enables advanced social engineering attacks beyond simple credential stuffing.Source 2

6

Victorian Schools Breach Exposes 665K Students' Data

Unauthorized access hit a database for all 1,700 Victorian government schools, compromising names, emails, encrypted passwords, and year levels of over 665,000 students.Source 2 Systems were shut down for mass password resets ahead of school return.Source 2

7

Ledger Third-Party Breach via Global-e Exposes Millions

Cryptocurrency wallet maker Ledger disclosed exposure of customer order data through e-commerce partner Global-e, with ShinyHunters claiming over 200M records across brands.Source 2 This affects multiple companies using the service.Source 2

8

Microsoft Releases First 2026 Patch Tuesday Fixing Zero-Days

Microsoft's January patches address three zero-days, including one actively exploited and another from compromised modems; other vendors like Fortinet also issued updates.Source 3Source 4 Fixes target Windows and related vulnerabilities.Source 3

9

Lumen Sinkholes Kimwolf DDoS Botnet Disrupting 250K Devices

Internet firm Lumen disrupted the Kimwolf DDoS botnet by sinkholing over 550 C&C servers, severing control from nearly 250,000 infected devices.Source 4 The botnet partially recovered but at reduced scale.Source 4 It specializes in massive DDoS using residential proxies.Source 4

10

BreachForums User Database Leaked with 320K Accounts

The latest BreachForums incarnation suffered a leak of its MyBB user database containing over 320,000 accounts and private PGP keys, posted by ShinyHunters.Source 4 This exposes hacker forum users.Source 4

11

Chinese Hackers Breach North American Critical Infrastructure

Government-backed group UAT-8837, tracked by Cisco Talos, infiltrated multiple North American orgs using stolen credentials and a Sitecore zero-day (CVE-2025-53690).Source 4 They employed tools like Earthworm and Sharphound post-compromise.Source 4

12

Malicious Chrome Extensions Target Enterprise Platforms

Socket discovered five rogue Chrome extensions stealing auth data from Workday, NetSuite via cookie theft, DOM manipulation, and session hijacking.Source 4 They enable full account takeovers; Google notified.Source 4