THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Exploited HPE OneView RCE Added to CISA’s KEV

A maximum‑severity code injection flaw in HPE OneView (CVE-2025-37164) is being actively exploited, enabling unauthenticated remote code execution on management appliances. CISA added the bug to its Known Exploited Vulnerabilities catalog as exploit code is publicly available, increasing risk for unpatched instances. Organizations should patch immediately and restrict network access to infrastructure management interfaces.

Source: SecurityWeek


Critical n8n “Ni8mare” flaw enables takeover chains; PoCs published

Researchers detailed a CVSS 10.0 bug in n8n (CVE-2026-21858, “Ni8mare”) that can be abused without authentication via crafted file uploads to read arbitrary files and forge admin sessions, then chained to RCE using additional vulnerabilities. Technical write‑ups and proof‑of‑concept exploits are public, and multiple CVEs can be combined for full compromise on certain versions. Self‑hosted n8n users should upgrade to 1.121.0+ and harden/validate file‑handling webhooks.

Source: Rapid7


VMware ESXi zero‑day exploit likely built a year before disclosure

Fresh attacks against three ESXi vulnerabilities disclosed as zero‑days in March 2025 suggest the exploit chain was developed roughly a year earlier. The findings underscore how sophisticated actors can stockpile and operationalize hypervisor exploits against high‑value targets long before public fixes, reinforcing the need for rapid patching and layered controls around virtualization hosts.

Source: SecurityWeek


China‑linked UAT‑7290 targets telecom infrastructure in South Asia

Cisco Talos attributes a sophisticated espionage campaign against South Asian telecommunications providers to UAT‑7290, a China‑nexus APT. The actor emphasizes deep technical reconnaissance and long‑term persistence to access sensitive communications infrastructure, highlighting ongoing strategic pressure on regional telcos.

Source: Cisco Talos


Trend Micro Apex Central: Unauthenticated RCE flaw gets public PoC

Trend Micro fixed multiple bugs in on‑prem Apex Central, including CVE‑2025-69258, a critical unauthenticated RCE now accompanied by public technical details and proof‑of‑concept code. Because Apex Central governs security policy across endpoints, exploitation could enable rapid, broad impact; admins should apply the vendor’s patches without delay.

Source: Help Net Security


CISA retires 10 emergency directives amid KEV program maturation

CISA sunset 10 emergency directives issued between 2019 and 2024, citing the evolution and efficacy of the Known Exploited Vulnerabilities catalog to drive urgent, standardized remediation. The shift signals a more systemic, repeatable mechanism for directing patch priorities across federal networks and, by extension, influencing private‑sector risk decisions.

Source: The Record by Recorded Future


FBI: North Korea’s Kimsuky is spear‑phishing with malicious QR codes

US authorities warn that Kimsuky operators are embedding weaponized QR codes in targeted emails to think tanks, academic institutions, and government entities. The technique routes victims to credential‑harvesting sites while evading some traditional email controls, emphasizing the need to treat QR codes as untrusted links and enforce phishing‑resistant MFA.

Source: The Hacker News


You May Also Be Interested In...

Cybersecurity — January 9, 2026 | Briefing24