Weekly Threat Bulletin – January 28th, 2026
This weekly threat bulletin highlights several critical vulnerabilities and emerging threats. A severe RCE vulnerability in React Server Components and Next.js (CVE-2025-55182) is being actively exploited. CISA added four critical flaws to its 'Must-Patch' list, including vulnerabilities in Versa Concerto, eslint-config-prettier, Zimbra Collaboration Suite, and Vite. GitLab released patches for multiple high-severity vulnerabilities. A new macOS malware called MonetaStealer targets crypto wallets and financial data. Lastly, a critical RCE vulnerability in Oracle E-Business Suite (CVE-2025-61882) is being actively exploited by threat actors, including the Clop ransomware group.
Pulse ID: 697a0fb2c327ef769cb46467
Pulse Link: https://otx.alienvault.com/pulse/697a0fb2c327ef769cb46467
Pulse Author: AlienVault
Created: 2026-01-28 13:31:30
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CISA #CyberSecurity #FinancialData #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Vulnerability #Zimbra #bot #AlienVault
