vulnerability

Chinese Hackers Exploiting Dell Zero-day Flaw Since Mid-2024

Chinese hackers have been exploiting a critical Dell security flaw, identified as CVE-2026-22769, in their RecoverPoint for Virtual Machines since mid-2024. The UNC6201 group uses hardcoded credentials for unauthorized access, deploying sophisticated malware like Grimbolt to infiltrate VMware networks. To mitigate these attacks, Dell advises affected customers to apply recommended remediations.

https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/

Major ‘vibe-coding’ Platform Orchids Is Easily Hacked, Researcher Finds

A security flaw in Orchids AI platform led to a BBC reporter's laptop being hacked without any user action. A cybersecurity researcher exploited vulnerabilities, demonstrating risks associated with “vibe-coding” tools that allow non-technical users to create applications. This zero-click attack could compromise sensitive data and device security, raising concerns about the convenience of AI tools. Experts warn of a new class of vulnerabilities in AI systems.

https://www.bbc.com/news/articles/cy4wnw04e8wo

Claude Desktop Extensions 0-Click RCE Vulnerability Exposes 10,000+ Users to Remote Attacks

Critical vulnerability in Claude Desktop Extensions allows 0-click remote code execution, affecting 10,000+ users. Attackers exploit this flaw via Google Calendar events, enabling unauthorized commands without user consent. LayerX warns of severe trust boundary violations; fixes are currently not planned by Anthropic.

https://cybersecuritynews.com/claude-desktop-extensions-0-click-vulnerability/

2026-01-14: The Day the Telnet Died

On January 14, 2026, global telnet traffic dropped 59% abruptly due to potential port 23 filtering by U.S. internet providers, coinciding with the discovery of CVE-2026-24061, a critical telnet vulnerability. Eighteen ASNs lost all telnet sessions, and five countries dropped from data completely. The post suggests the drop was a response to an exploitable vulnerability, emphasizing the importance of patching or disabling GNU Inetutils telnetd. The sustained reduction in telnet traffic indicates a shift away from insecure protocols among ISPs.

https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/

A Rise in Hacktivist Attacks Puts All Web Applications at Risk, Warns UK’s NCSC

UK's NCSC warns of rising pro-Russia hacktivist DDoS attacks threatening web applications. These attacks disrupt services, erode trust, and may target sensitive data. Organizations must enhance web application security to protect against DDoS and other threats, ensuring operational resilience. Barracuda offers multilayered protection, including real-time threat intelligence, to safeguard digital services.

https://blog.barracuda.com/2026/02/06/hacktivist-attacks-web-applications-risk-ncsc

Critical N8n Flaws Disclosed Along With Public Exploits

Critical vulnerabilities in the n8n workflow automation platform (CVE-2026-25049) allow any authenticated user to execute remote code, potentially gaining full control over the server. Discovered by multiple cybersecurity firms, these issues stem from inadequate sandboxing, enabling attackers to access sensitive data and configurations. Users are advised to update to versions 1.123.17 and 2.5.2, rotate encryption keys, and scrutinize workflows for suspicious activity, as no exploits have been reported yet.

https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/

From Magic to Malware: How OpenClaw’s Agent Skills Become an Attack Surface

TLDR: OpenClaw presents security risks as its agent skills access sensitive data through markdown files that can disguise harmful commands. Instances of malware disguised as “skills” have been identified, posing threats to corporate devices. Users are warned against using OpenClaw on work devices, emphasizing the importance of security measures for skill registries and agent frameworks to prevent exploitation.

https://1password.com/blog/from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface

Notepad++ Hijacked by State-Sponsored Hackers

Notepad++ was hijacked by state-sponsored hackers, likely Chinese, compromising update traffic from June to December 2025. The former hosting provider confirmed the server was breached, allowing attackers to redirect Notepad++ updates. All security vulnerabilities were addressed by December 2, 2025, and the site was migrated to a more secure host. Users are advised to download v8.9.1, which includes security enhancements, and manual updates. No specific indicators of compromise were found during the investigation.

https://notepad-plus-plus.org/news/hijacked-incident-info-update/

Russia-linked Attackers Abuse New Microsoft Office Zero-day

Russia-linked APT28 hackers exploit latest Microsoft Office zero-day, targeting Ukrainian government and EU organizations. Ukraine's CERT reports rapid weaponization of the CVE-2026-21509 vulnerability, leading to phishing campaigns and malware deployment via malicious DOC files. Microsoft has issued patches, but concerns about increasing cyberattacks persist due to slow user updates.

https://www.theregister.com/2026/02/02/russialinked_apt28_microsoft_office_bug/

Notepad Hijacked

Notepad++ update servers were compromised by a likely Chinese state-sponsored group from June to December 2025. Attackers intercepted update traffic, redirecting users to malicious binaries due to inadequate validation of update packages. Following the breach, Notepad++ enhanced security measures, including stricter validation processes and plans to implement XMLDSig in future updates to prevent such incidents.

https://cybersecuritynews.com/notepad-hijacked/

175K Exposed Ollama Hosts Allow Remote Code Execution

175,000 exposed Ollama AI servers across 130 countries present significant remote code execution risks due to insufficient security. Researchers found 7.23 million observations and highlighted a core of 23,000 persistent hosts, with many capable of executing code and interacting with external systems, heightening threat levels. Security risks include resource hijacking, spam, and prompt injection attacks, particularly as many hosts lack adequate monitoring. The global infrastructure complicates traditional governance, necessitating improved security measures for edge-deployed AI models.

https://cyberpress.org/175k-exposed-ollama-hosts-allow-remote-code-execution/

Two High-Severity N8n Flaws Allow Authenticated Remote Code Execution

Two high-severity vulnerabilities in the n8n workflow automation platform could lead to remote code execution by authenticated users. Discovered by JFrog Security Research, these vulnerabilities include CVE-2026-1470 (eval injection, CVSS 9.9) and CVE-2026-0863 (Python task executor bypass, CVSS 8.5). Exploiting these flaws may allow attackers to gain full control of n8n instances, especially in internal execution mode. Users are advised to update to specific safe versions to mitigate these risks.

https://thehackernews.com/2026/01/two-high-severity-n8n-flaws-allow.html

Hand CVE Over to the Private Sector

The Common Vulnerability Enumeration (CVE) initiative, created in 1999, is criticized for being redundant and mismanaged. Despite receiving substantial government funding, MITRE’s CVE program is perceived as lacking objectivity, quick response capability, and expertise in vulnerability database management. The author argues that the program’s high costs and slow response times suggest it is not meeting the requirements of a federally funded research and development center.

https://www.darkreading.com/cybersecurity-operations/hand-cve-over-to-private-sector

PackageGate: 6 Zero-Days in JS Package Managers But NPM Won’t Act

Koi identifies six zero-day vulnerabilities in JavaScript package managers (npm, pnpm, vlt, and Bun) regarding defenses against the Shai-Hulud attack. While npm declined to address vulnerabilities, pnpm, vlt, and Bun acted swiftly. These flaws allow attackers to bypass script execution prevention and lockfile integrity checks, undermining the security claims of the tools. Koi stresses that the ecosystem requires better security and urges organizations to be vigilant, use lockfiles, disable scripts, and consider using more secure package managers.

https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act

Nearly 800,000 Telnet Servers Exposed to Remote Attacks

Nearly 800,000 Telnet servers are vulnerable to remote attacks exploiting an authentication bypass flaw (CVE-2026-24061) in GNU InetUtils. This flaw allows attackers to gain root access without proper authentication. The vulnerability affects versions 1.9.3 to 2.7, with a patch available in version 2.8. Cybersecurity firm GreyNoise reports that limited exploit attempts have already begun following the vulnerability's disclosure. Admins are advised to disable Telnet services or block TCP port 23 if they cannot upgrade immediately.

https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-servers-exposed-to-remote-attacks/

Scroll to Top