Heroes, here's the curated threat landscape for Jan 22, 2026.
Critical Threats
Cisco Patches Actively Exploited Zero-Day in Unified Communications
Cisco has released an emergency patch for a critical vulnerability in its Unified Communications and Webex Calling products that is currently being exploited in the wild. CISA has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate action for federal agencies.
Business Impact
If exploited, attackers gain remote code execution capabilities without authentication. This could lead to total compromise of communication infrastructure, eavesdropping on sensitive calls, and a pivot point for ransomware deployment, resulting in severe operational disruption and regulatory fines.
Recommended Action
Ask your IT team: "Have we verified the version of our Cisco Unified Communications Manager today, and is the patch for CVE-2026-20045 applied?" Isolate vulnerable instances immediately if patching is delayed.
Surge in Automated Attacks Targeting FortiGate Firewalls
Arctic Wolf and SecurityWeek report a new wave of automated attacks targeting FortiGate firewalls, leveraging authentication bypass vulnerabilities to create unauthorized generic admin accounts. Reports suggest fully patched devices may still be vulnerable or compromised via persistence mechanisms from CVE-2025-59718.
Business Impact
A compromised firewall grants attackers a foothold at the network perimeter. This can lead to data exfiltration, unauthorized configuration changes, and deep network infiltration, triggering breach notification requirements under HIPAA and SOX.
Recommended Action
Ask your security operations team: "Have we audited our FortiGate user list for unknown generic accounts in the last 24 hours?" Verify firmware integrity beyond standard patch levels.
BlueNoroff APT Shifts Focus to MacOS and Financial Targets
BlueNoroff, a financially motivated subgroup of the Lazarus collective, is intensifying operations against financial institutions and cryptocurrency assets, with a notable shift toward targeting MacOS environments. They are known for high-profile heists like the Bangladesh SWIFT hack.
Business Impact
Financial institutions face direct monetary loss and severe reputational damage. The shift to MacOS targeting means traditional Windows-centric defenses may miss their initial access vectors.
Recommended Action
Ask your threat intelligence team: "Are our detection rules updated to identify BlueNoroff's specific MacOS tradecraft?"
High Severity
Critical Gaps Identified in Google Workspace Security
Agile companies often rely on default Google Workspace configurations that prioritize growth over resilience, leaving gaps in incident response and compliance. Security teams are struggling to manage these environments effectively without specialized tools.
Business Impact
Misconfigured workspace settings can lead to accidental data leaks and failed compliance audits (SOX). Inadequate logging hampers incident investigation capabilities.
Recommended Action
Ask your IT Director: "When was the last time we performed a configuration review of our Google Workspace tenant against security best practices?"
Third-Party Web Apps Accessing Sensitive Data Without Justification
A new study by Reflectiz reveals a sharp escalation in client-side risk, with most third-party web applications accessing sensitive data without clear justification. This highlights the growing "Shadow IT" problem in web environments.
Business Impact
Unchecked third-party scripts on corporate websites can scrape customer data (Magecart-style attacks), leading to GDPR/CCPA fines and loss of customer trust.
Recommended Action
Verify which third-party scripts are running on your payment and login pages.
AI Models Vulnerable to Prompt Injection Attacks
Security expert Bruce Schneier highlights that Large Language Models (LLMs) remain fundamentally susceptible to prompt injection attacks, where malicious instructions override safety guardrails. This is compared to social engineering against a naive employee.
Business Impact
As organizations integrate LLMs into customer service and internal tools, prompt injection could lead to unauthorized data disclosure or manipulation of business logic.
Recommended Action
Review all AI implementations for "human-in-the-loop" verification before executing sensitive actions.
NIST Faces Staff Cuts Impacting Encryption Standards
NIST is starting 2026 with reduced staff and budget, potentially slowing down critical updates to encryption standards and cybersecurity guidance. This could delay industry-wide adoption of post-quantum cryptography standards.
Other Noteworthy
NIST Faces Staff Cuts Impacting Encryption Standards
NIST is starting 2026 with reduced staff and budget, potentially slowing down critical updates to encryption standards and cybersecurity guidance. This could delay industry-wide adoption of post-quantum cryptography standards.
Vendor Spotlight
Valence Security (Specialized Vendor)
Specialization: SaaS Security Posture Management (SSPM)
Why Valence Security Today: Valence Security specializes in SaaS Security Posture Management (SSPM), which is directly relevant to the threat regarding 'Filling the Most Common Gaps in Google Workspace Security.' Their platform is designed to secure business-critical SaaS applications like Google Workspace by detecting misconfigurations, identity risks, and third-party integration vulnerabilities.
Key Capability: Automated remediation of SaaS misconfigurations and third-party integration risks in platforms like Google Workspace.
Recommended Actions: 1. Navigate to Inventory → Third-Party Integrations → Filter by 'Google Workspace' → Sort by 'Risk Level: High' 2. Navigate to Posture → Misconfigurations → Select 'Google Workspace' → Filter by 'Severity: Critical' 3. Navigate to Data Security → External Sharing → Filter by 'Link Sharing: Public/Anyone with link'
Verification Steps: - Navigate to Workflows → Activity Log after initiating a remediation action (e.g., revoking a token) - Review the 'Security Score' or 'Posture Trends' widget on the main Dashboard
Detection & Response
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. Vendor Platform Configuration - Valence Security
2. YARA Rule for FortiGate Config Attacks
3. SIEM Query — Cisco Unified Comm Exploitation (CVE-2026-20045)
4. PowerShell Script — Detect Inkscape MacOS Presence (For Hybrid Mgmt)
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!