216.73.216.6

Weekly Threat Bulletin – January 28th, 2026

· Published 28/01/2026 13:31 · Modified 28/01/2026 15:05

Export JSON

Essential information

Published
28/01/2026 13:31
Modified
28/01/2026 15:05
Tags
2026-01-28 CVE-2025-31125 CVE-2025-34026 CVE-2025-54313 CVE-2025-55182 CVE-2025-61882 CVE-2025-68645 agenda agendacrypt aisuru angryrebel bash0day bashlite beacon bpfdoor cisa clop cobalt strike compood etherrat gafgyt gitlab interlock kswapdoor lizkebab lzrd macos masuta miori mirai monetastealer morte next.js nezha noodle rat okiru oracle e-business suite peerblight pulsepack puremasuta qilin ransomware rce react resgod rondo rondobot rondodox satori scavenger sliver splinter torlus vshell wicked xmrig
Related entities
16 vulnerabilities (cve), 37 observables, 1 intrusion sets (apt), 20 techniques (mitre), 40 malware, 40 others

Description

This weekly threat bulletin highlights several critical vulnerabilities and emerging threats. A severe vulnerability in Server Components and () is being actively exploited. added four critical flaws to its 'Must-Patch' list, including vulnerabilities in Versa Concerto, eslint-config-prettier, Zimbra Collaboration Suite, and Vite. released patches for multiple high-severity vulnerabilities. A new malware called targets crypto wallets and financial data. Lastly, a critical vulnerability in () is being actively exploited by threat actors, including the group.

External references