Author: Robert Timlick

  • 3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026

    3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026

    Beyond the direct impact of cyberattacks, enterprises suffer from a secondary but potentially even more costly risk: operational downtime, any amount of which translates into very real damage. That’s why for CISOs, it’s key to prioritize decisions that reduce dwell time and protect their company from risk. 
    Three strategic steps you can take this year for better results:
    1. Focus on today’s
  • SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass

    SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass

    SolarWinds has released security updates to address multiple security vulnerabilities impacting SolarWinds Web Help Desk, including four critical vulnerabilities that could result in authentication bypass and remote code execution (RCE).
    The list of vulnerabilities is as follows –

    CVE-2025-40536 (CVSS score: 8.1) – A security control bypass vulnerability that could allow an unauthenticated

  • Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks

    Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks

    Google on Wednesday announced that it worked together with other partners to disrupt IPIDEA, which it described as one of the largest residential proxy networks in the world.
    To that end, the company said it took legal action to take down dozens of domains used to control devices and proxy traffic through them. As of writing, IPIDEA’s website (“www.ipidea.io”) is no longer accessible. It
  • Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware

    Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware

    Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly Clawdbot) on the official Extension Marketplace that claims to be a free artificial intelligence (AI) coding assistant, but stealthily drops a malicious payload on compromised hosts.
    The extension, named “ClawdBot Agent – AI Coding Assistant” (“clawdbot.clawdbot-agent”)
  • Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid

    Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid

    The “coordinated” cyber attack targeting multiple sites across the Polish power grid has been attributed with medium confidence to a Russian state-sponsored hacking crew known as ELECTRUM.
    Operational technology (OT) cybersecurity company Dragos, in a new intelligence brief published Tuesday, described the late December 2025 activity as the first major cyber attack targeting distributed energy
  • Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution

    Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution

    A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system.
    The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0 on the CVSS scoring system.
    “In vm2 for version 3.10.0, Promise.prototype.then Promise.prototype.catch
  • Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution

    Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution

    Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution.
    The weaknesses, discovered by the JFrog Security Research team, are listed below –

    CVE-2026-1470 (CVSS score: 9.9) – An eval injection vulnerability that could allow an authenticated user to bypass the Expression

  • Password Reuse in Disguise: An Often-Missed Risky Workaround

    Password Reuse in Disguise: An Often-Missed Risky Workaround

    When security teams discuss credential-related risk, the focus typically falls on threats such as phishing, malware, or ransomware. These attack methods continue to evolve and rightly command attention. However, one of the most persistent and underestimated risks to organizational security remains far more ordinary.
    Near-identical password reuse continues to slip past security controls, often
  • Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

    Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

    Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild.
    The vulnerability, assigned the CVE identifier CVE-2026-24858 (CVSS score: 9.4), has been described as an authentication bypass related to FortiOS single sign-on (SSO). The flaw also affects FortiManager and FortiAnalyzer. The company said it’s
  • Goldendale’s Energy Storage Project receives FERC approval, despite tribal opposition

    Goldendale’s Energy Storage Project receives FERC approval, despite tribal opposition

    GOLDENDALE — With a 40-year construction and operations license secured from the Federal Energy Regulatory Commission on Jan. 22, Rye Development can now start building Goldendale’s Energy Storage Project.