Attackers are actively exploiting a maximum-severity code injection vulnerability in HPE OneView, enabling remote code execution without authentication against the platform that manages servers, storage, and networking. Organizations should patch immediately, restrict management plane exposure, and review logs for suspicious admin actions; CISA has also added the bug to its Known Exploited Vulnerabilities list, underscoring urgency.
Source: SecurityWeek
Zero‑day in discontinued D‑Link DSL routers under active attack (CVE‑2026‑0625)
A critical OS command injection flaw in legacy D‑Link DSL routers is being exploited in the wild, allowing unauthenticated remote attackers to run arbitrary shell commands. With these devices discontinued, users should immediately disable remote management, isolate/replace affected units, and monitor outbound traffic for compromise indicators.
Source: SecurityWeek
Two CVSS 10.0 flaws in n8n enable full takeover; patch now (Ni8mare: CVE‑2026‑21858; CVE‑2026‑21877)
Researchers disclosed Ni8mare (CVE‑2026‑21858), an unauthenticated, max‑severity vulnerability that lets attackers fully compromise exposed n8n workflow automation instances. A second CVSS 10.0 bug (CVE‑2026‑21877) allows authenticated RCE under certain conditions; admins should update to the latest version, disable or lock down public webhooks, rotate tokens/credentials, and review audit logs for suspicious workflow changes.
Source: The Hacker News
Veeam Backup & Replication fixes multiple code execution bugs; ransomware targets likely
Veeam released updates addressing several code execution vulnerabilities in Backup & Replication, including issues that could be abused by lower‑privileged operators. Given ransomware actors’ history of targeting backup infrastructure, teams should update urgently, minimize service account privileges, and ensure backup servers are segmented and not exposed to the internet.
Source: SecurityWeek
Microsoft warns: misrouted email flows enable “internal” phishing at scale
Threat actors are abusing complex mail routing and misconfigured SPF/DMARC/DKIM to spoof company domains, making phishing emails appear as if sent internally—often via Phishing‑as‑a‑Service kits like Tycoon2FA. Review all connectors and routing paths, enforce DMARC alignment (p=reject), and harden MFA workflows to blunt session and 2FA theft.
Source: SecurityWeek
900,000 installs: malicious Chrome extensions steal AI chats and browsing data
Two Chrome extensions impersonating AITOPIA were caught exfiltrating ChatGPT/DeepSeek conversations and users’ browsing activity. Enterprises should audit extension inventories, remove suspicious or look‑alike AI tool add‑ons, move to an allowlist policy for browser extensions, and rotate any credentials that may have been exposed in chats.
Source: SecurityWeek
Unpatched Totolink EX200 flaw enables device takeover via rogue Telnet
A vulnerability in the EX200 range extender’s firmware upload handler can trigger an unauthenticated, root‑level Telnet service, allowing attackers to seize control. Until a vendor fix is available, disable remote administration, ensure the device isn’t reachable from WAN networks, and segment IoT gear from sensitive assets.
Source: SecurityWeek
You May Also Be Interested In...
Cybercriminals are scaling phishing attacks with ready-made kits
Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages
Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances