The open-source workflow automation platform n8n has alerted users to a serious security vulnerability, identified as CVE-2026-21877, which carries a CVSS score of 10.0. This flaw could allow authenticated users to execute untrusted code remotely, posing a significant risk to both self-hosted and cloud versions of the software. Users and organizations utilizing n8n need to be aware of this vulnerability as it could lead to unauthorized access and potential data breaches. The company recommends that affected users take immediate action to secure their systems. As of now, the specific details regarding patches or updates have not been disclosed, but users should monitor official channels for further instructions.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Hackers are exploiting a serious vulnerability in older D-Link DSL routers, identified as CVE-2026-0625. This flaw allows attackers to execute commands remotely, potentially compromising users' devices and networks. The vulnerability has a high severity score of 9.3, which indicates that it poses a significant risk. Users of legacy D-Link DSL routers need to be aware of this issue as it could lead to unauthorized access and control over their internet-connected devices. As attackers actively exploit this flaw, it is crucial for affected users to take immediate action to protect their systems.
A hacker group known as Zestix has successfully breached around 50 companies by exploiting a lack of multi-factor authentication (MFA). These breaches involved the use of infostealers, which are malicious programs designed to gather sensitive information from users. The absence of MFA made it easier for attackers to gain access to sensitive data without needing additional verification steps. This incident serves as a stark reminder for businesses to implement stronger security measures, as it shows how quickly attackers can exploit basic vulnerabilities. Organizations that haven't adopted MFA may find themselves at greater risk of data theft and financial loss.
Help Net Security
New research reveals that risks can emerge unexpectedly when artificial intelligence agents interact over time. The study shows that as these agents communicate and coordinate, they can create feedback loops and shared signals that lead to unforeseen outcomes, impacting entire technical and social systems. This means that even if individual AI agents operate within safe parameters, their collective behavior can introduce new risks. Understanding these dynamics is crucial for developers and organizations using AI, as it emphasizes the need for careful monitoring of AI interactions to prevent potential harm. This research raises important questions about the safety and reliability of multi-agent systems in various applications.
Help Net Security
A recent report from Kiteworks reveals that European security and compliance teams are facing significant challenges in implementing regulatory frameworks effectively. Although organizations have established strong regulations, particularly around GDPR and forthcoming AI regulations, they struggle with operationalizing these rules in real-world scenarios. This gap is particularly evident in areas like AI incident response and supply chain visibility. The report suggests that without better systems to put regulations into practice, organizations may be vulnerable to compliance failures and security incidents. This situation is concerning for businesses that need to align their operations with legal requirements while ensuring effective security measures are in place.
The Hacker News
A serious security vulnerability has been identified in legacy D-Link DSL gateway routers, specifically affecting the 'dnscfg.cgi' endpoint. This flaw, known as CVE-2026-0625, has a high severity score of 9.3 and allows unauthenticated remote attackers to execute commands through improper handling of user-provided DNS configuration inputs. Current reports indicate that this vulnerability is actively being exploited in the wild, putting users of these older routers at risk. It is crucial for individuals and organizations using these devices to be aware of the potential for unauthorized access and control. The situation underscores the need for users to assess their network security and consider upgrading their hardware to mitigate these risks.
The Federal Communications Commission (FCC) has introduced new penalties aimed at combatting robocalls, particularly after a notable incident involving President Joe Biden's voice being cloned. Under these new regulations, telecom companies will face fines of $10,000 for submitting false or late caller identification information. This move is part of a broader effort to hold telecom providers accountable for the robocall epidemic that has frustrated consumers and undermined trust in phone communications. These penalties are expected to encourage telecom companies to improve their caller ID systems and take more responsibility for the calls that originate from their networks. This regulatory change is significant as it directly impacts how telecom companies operate and could lead to a decrease in fraudulent calls that misuse caller information.
Taiwan's National Security Bureau has reported a significant increase in cyberattacks from China targeting its energy sector, with incidents rising tenfold in 2025 compared to the previous year. This surge in attacks raises serious concerns about the security of Taiwan's critical infrastructure, particularly as tensions between the two nations continue to escalate. The energy sector is vital for maintaining the country's operations, and disruptions could have widespread implications for both the economy and public safety. Taiwan's government is likely to enhance its cybersecurity measures to protect against these aggressive tactics. This situation highlights the ongoing cyber conflict in the region and the need for robust defenses against state-sponsored threats.
CERT/CC has issued a warning about a serious vulnerability in the TOTOLINK EX200 Wi-Fi range extender, identified as CVE-2025-65606. This flaw allows a remote authenticated attacker to take complete control of the device, posing a significant risk to users. As this vulnerability remains unpatched, anyone using the TOTOLINK EX200 is advised to take immediate action to secure their networks. The potential for exploitation means that attackers could manipulate settings, access sensitive data, or use the device as a foothold into larger networks. Users need to be aware of this threat and consider alternative security measures while awaiting a fix.
Researchers set a trap for members of the Lapsus$ hacking group, also known as ShinyHunters, by creating a realistic but mostly fake dataset. This honeypot successfully attracted these cybercriminals, allowing the researchers to gather insights into their tactics and methods. The operation demonstrates the ongoing challenges that cybersecurity professionals face as they try to outsmart sophisticated attackers. By luring in these hackers, the researchers hope to better understand their strategies and potentially mitigate future attacks. This incident serves as a reminder of the persistent threat posed by groups like Lapsus$, which have been involved in high-profile breaches targeting major organizations around the world.
Recent reports indicate that attackers are actively exploiting a command injection vulnerability in several D-Link DSL gateway routers. These devices, which are considered legacy products, have not received support for years, making them particularly vulnerable. Users of affected routers may face unauthorized access to their networks, potentially allowing attackers to execute malicious commands. The exploitation of this vulnerability highlights the risks associated with using unsupported hardware. D-Link has not specified any patches or updates, leaving users with few options other than to replace these outdated routers to protect their networks.
The Hacker News
Cybersecurity researchers have identified two malicious Chrome extensions that have collectively attracted over 900,000 users. These extensions, named 'Chat GPT for Chrome with GPT-5' and 'Claude Sonnet & DeepSeek AI,' are designed to steal conversations from OpenAI's ChatGPT and DeepSeek, along with users' browsing data. The stolen information is sent to servers controlled by the attackers. This incident raises significant concerns about user privacy and data security, as many individuals may unknowingly be exposing sensitive information through these extensions. Users are urged to remove these extensions immediately and review their online security practices to protect their data.
Hackread – Cybersecurity News, Data Breaches, AI, and More
Ledger has confirmed a data breach linked to its partner Global-e, which has resulted in the exposure of customer information. While sensitive data such as passwords and crypto recovery phrases were not compromised, users are now facing active phishing attempts that may target them using the leaked information. This incident raises concerns about the security of personal data in the cryptocurrency space and serves as a reminder for users to remain vigilant against phishing scams. Ledger is advising its customers to be cautious and verify any communications they receive that claim to be from the company or its partners. Staying alert is crucial as scammers may use this data to trick users into revealing more sensitive information.
A new malware campaign known as PHALT#BLYX ClickFix is targeting the hospitality sector, exploiting social engineering tactics and the MSBuild.exe tool. This multi-stage attack has been specifically designed to infiltrate hospitality organizations, putting sensitive data and operations at risk. Researchers have noted that the campaign employs deceptive strategies to trick users into executing malicious code. As a result, affected companies could face significant disruptions and potential data breaches, making it crucial for hospitality organizations to remain vigilant and enhance their cybersecurity measures. The ongoing threat emphasizes the need for robust employee training and awareness to combat social engineering tactics effectively.
Cybersecurity Blog | SentinelOne
SentinelLABS' research for 2025 reveals significant trends in cybersecurity, particularly the adaptation of ransomware for espionage activities and the growing exploitation of cloud platforms. This shift indicates that attackers are increasingly targeting sensitive information stored in cloud environments, which could put numerous enterprises at risk. Companies using cloud services need to be vigilant and enhance their security measures to protect against these evolving threats. The report suggests that the landscape of cybercrime is becoming more sophisticated, making it essential for organizations to stay informed and prepared. Understanding these trends can help enterprises better defend their systems and data against potential breaches.