A maximum‑severity code injection flaw in HPE OneView (CVE-2025-37164) is being actively exploited, enabling unauthenticated remote code execution on management appliances. CISA added the bug to its Known Exploited Vulnerabilities catalog as exploit code is publicly available, increasing risk for unpatched instances. Organizations should patch immediately and restrict network access to infrastructure management interfaces.
Source: SecurityWeek
Critical n8n “Ni8mare” flaw enables takeover chains; PoCs published
Researchers detailed a CVSS 10.0 bug in n8n (CVE-2026-21858, “Ni8mare”) that can be abused without authentication via crafted file uploads to read arbitrary files and forge admin sessions, then chained to RCE using additional vulnerabilities. Technical write‑ups and proof‑of‑concept exploits are public, and multiple CVEs can be combined for full compromise on certain versions. Self‑hosted n8n users should upgrade to 1.121.0+ and harden/validate file‑handling webhooks.
Source: Rapid7
VMware ESXi zero‑day exploit likely built a year before disclosure
Fresh attacks against three ESXi vulnerabilities disclosed as zero‑days in March 2025 suggest the exploit chain was developed roughly a year earlier. The findings underscore how sophisticated actors can stockpile and operationalize hypervisor exploits against high‑value targets long before public fixes, reinforcing the need for rapid patching and layered controls around virtualization hosts.
Source: SecurityWeek
China‑linked UAT‑7290 targets telecom infrastructure in South Asia
Cisco Talos attributes a sophisticated espionage campaign against South Asian telecommunications providers to UAT‑7290, a China‑nexus APT. The actor emphasizes deep technical reconnaissance and long‑term persistence to access sensitive communications infrastructure, highlighting ongoing strategic pressure on regional telcos.
Source: Cisco Talos
Trend Micro Apex Central: Unauthenticated RCE flaw gets public PoC
Trend Micro fixed multiple bugs in on‑prem Apex Central, including CVE‑2025-69258, a critical unauthenticated RCE now accompanied by public technical details and proof‑of‑concept code. Because Apex Central governs security policy across endpoints, exploitation could enable rapid, broad impact; admins should apply the vendor’s patches without delay.
Source: Help Net Security
CISA retires 10 emergency directives amid KEV program maturation
CISA sunset 10 emergency directives issued between 2019 and 2024, citing the evolution and efficacy of the Known Exploited Vulnerabilities catalog to drive urgent, standardized remediation. The shift signals a more systemic, repeatable mechanism for directing patch priorities across federal networks and, by extension, influencing private‑sector risk decisions.
Source: The Record by Recorded Future
FBI: North Korea’s Kimsuky is spear‑phishing with malicious QR codes
US authorities warn that Kimsuky operators are embedding weaponized QR codes in targeted emails to think tanks, academic institutions, and government entities. The technique routes victims to credential‑harvesting sites while evading some traditional email controls, emphasizing the need to treat QR codes as untrusted links and enforce phishing‑resistant MFA.
Source: The Hacker News
You May Also Be Interested In...