Week 4 - 2026 Weekly Digest
19 Jan 2026 – 24 Jan 2026 • Published: 26 Jan 2026
Critical CVEs
CVE-2024-37079 — Heap-overflow vulnerability CVSS 9.8vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
CVE-2026-0920 — Unauthenticated admin‑creation flaw CVSS 9.8The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'lakit_bkrole' parameter during registration and gain administrator access to the site.
CVE-2026-21962 — Unauthorized access and data‑modification CVSS 10Vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug‑in that allows an unauthenticated attacker over HTTP to gain unauthorized access and modify critical data.
Top Security News
KONNI Adopts AI to Generate PowerShell Backdoors NewsCheck Point has identified a phishing campaign linked to KONNI, a North Korea–associated criminal group, aimed at distributing PowerShell‑based backdoors generated with the assistance of artificial intelligence
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware NewsA new multistage phishing campaign is targeting users in Russia with ransomware and the Amnesia RAT. It uses business‑themed documents as lures to mask silent malicious activity, and relies on multiple public cloud services, GitHub for scripts and Dropbox for binary payloads, to increase resilience and hinder takedown efforts
Sandworm hackers linked to failed wiper attack on Poland’s energy systems NewsA cyberattack against the Polish power grid in late December 2025 has been attributed to the pro‑Russian hacker group Sandworm, which deployed a new malware strain known as DynoWiper.
Ransomware Activity
Frandent RansomwareThe threat actor Lockbit5 claims responsibility for a ransomware attack against the victim in the automotive sector on January 21.
Sita Sud RansomwareThe threat actor Thegentlemen claims responsibility for a ransomware attack against the victim in the transport sector on January 20.
Mec Matica RansomwareThe threat actor Sarcoma claims responsibility for a ransomware attack against the victim in the engineering consulting sector on January 20.
San Carlo Gruppo Alimentare RansomwareThe threat actor Thegentlemen claims responsibility for a ransomware attack against the victim in the food and drinks businesses sector on January 20.
Casadei RansomwareThe threat actor Qilin claims responsibility for a ransomware attack against the victim in the manufacturing sector on January 19.



