Week 3 - 2026 Weekly Digest

12 Jan 2026 – 18 Jan 2026 • Published: 19 Jan 2026

CVE News Ransomware 8Bit Content Week 3 2026

Critical CVEs

CVE-2026-0227 — Denial of service vulnerability CVSS 7.6

palo alto globalprotect pan-os

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

CVE-2026-20952 — Use after free vulnerability CVSS 8.4

microsoft office

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-64155 — Improper neutralization vulnerability CVSS 9.4

fortinet fortisiem

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Top Security News

Microsoft: Some Windows PCs fail to shut down after January update News

Microsoft has confirmed a new issue that prevents Windows 11 23H2 devices with System Guard Secure Launch enabled from shutting down. System Guard Secure Launch is a Windows security feature designed to protect the boot process from firmware-level attacks and malware such as rootkits.

Source: BleepingComputer

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection News

The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that's designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives.

Source: The Hacker News

Phishing scammers are posting fake “account restricted” comments on LinkedIn News

Recently, fake LinkedIn profiles have started posting comment replies claiming that a user has “engaged in activities that are not in compliance” with LinkedIn’s policies and that their account has been “temporarily restricted” until they submit an appeal through a specified link in the comment.

Source: MalwareBytes

Ransomware Activity

Colacem Ransomware

The threat actor Qilin claims responsibility for a ransomware attack against the victim in the manufacturing sector on January 17.

Fluorsid Spa Ransomware

The threat actor Qilin claims responsibility for a ransomware attack against the victim in the manufacturing sector on January 17.

depotnapoli.com Ransomware

The threat actor Lockbit5 claims responsibility for a ransomware attack against the victim in the entertainment sector on January 15.

Adriatic Port Authority Ransomware

The threat actor Anubisclaims responsibility for a ransomware attack against the victim in the transport sector on January 14.

stimgroup Ransomware

The threat actor Qilin claims responsibility for a ransomware attack against the victim in the agriculture sector on January 13.

What we shipped at 8BitSecurity