Cybersecurity News | Daily Recap [26 Jan 2026]

Cybersecurity News | Daily Recap [26 Jan 2026]

Daily Recap, VMware’s critical vCenter remote code execution flaw (CVE-2024-37079) is actively exploited, with federal agencies ordered to patch within three weeks after a June 2024 DCERPC heap-overflow fix. 1Password adds auto-enabled phishing warnings to curb credential theft amid rising AI-amplified phishing risks, while Microsoft investigates Windows 11 boot failures due to UNMOUNTABLE_BOOT_VOLUME in KB5074109 affecting 25H2 and 24H2, with separate OOB fixes for Outlook PST cloud freezes, and HendryAdrian’s daily threat recap provides a weekly summary.
#VMware #CVE-2024-37079

Vulnerabilities & Exploits

  • CISA warns that a critical VMware vCenter remote code execution flaw (CVE-2024-37079) is being actively exploited and ordered federal agencies to patch within three weeks after a June 2024 DCERPC heap-overflow fix β€” VMware RCE

Product Security

  • Password manager 1Password added auto-enabled pop-up warnings for suspected phishing and typosquatted URLs (admins can enable for company accounts) to reduce credential theft amid rising AI-amplified phishing risks β€” 1Password Alert

Updates & Instability

  • Microsoft is investigating Windows 11 devices failing to boot with UNMOUNTABLE_BOOT_VOLUME stop errors after the January cumulative update KB5074109, impacting Windows 11 25H2 and 24H2, and provided separate OOB fixes for Outlook PST cloud freezes β€” Win11 Boot

Recaps

  • Daily threat research roundup and weekly summaries from HendryAdrian covering recent cybersecurity developments β€” Weekly Recap

Cybersecurity News | Daily Recap – hendryadrian.com