UINAT
NewsRankingsCompaniesGuidesBreachesCompliance
TagsAbout
Home/News

Security News

Breaking cybersecurity news, vulnerability disclosures, and industry updates.

DockerDash Vulnerability in Ask Gordon AI Enables Code Execution via Image Metadata

Noma Labs discovered a critical flaw in Docker's Ask Gordon AI assistant allowing attackers to hijack AI reasoning through malicious image metadata, leading to remote code execution or data exfiltration.

February 3, 2026 DockerAI securityvulnerability

NationStates Browser Game Confirms Data Breach After RCE Exploit

NationStates shut down its site after a vulnerability reporter chained input sanitization flaws to achieve remote code execution, copying user emails, password hashes, and IP addresses.

February 2, 2026 data breachRCEgaming

Notepad++ Update Mechanism Hijacked by Chinese Threat Actors to Deliver Malware

Lotus Blossom APT compromised Notepad++'s hosting provider to intercept update traffic and deliver the Chrysalis backdoor to targeted government and financial organizations over a six-month period.

February 2, 2026 supply chainmalwareChina

Critical vLLM Vulnerability Lets Attackers Hijack AI Servers via Video Link

CVE-2026-22778, a critical RCE in vLLM versions 0.8.3-0.14.0, chains a PIL information leak with a JPEG2000 heap overflow to achieve code execution through a malicious video link.

February 2, 2026 vLLMAI securityvulnerability

OpenClaw AI Agent Vulnerability Enables One-Click Remote Code Execution

CVE-2026-25253 (CVSS 8.8) allows attackers to steal authentication tokens and achieve RCE through a single malicious link via cross-site WebSocket hijacking—even on localhost-only OpenClaw instances.

February 2, 2026 OpenClawAI securityRCE

400+ Malicious OpenClaw Skills Flood ClawHub With Info-Stealing Malware

Over 400 malicious OpenClaw AI agent skills on ClawHub deploy Atomic Stealer via ClickFix-style social engineering. The hightower6eu account alone published 314 malicious skills targeting crypto and developer credentials.

February 2, 2026 OpenClawMoltBotmalware

Microsoft Announces Three-Phase Plan to Disable NTLM by Default

Microsoft will disable the 33-year-old NTLM authentication protocol by default in future Windows releases through a phased rollout: enhanced auditing now, Kerberos improvements in H2 2026, and disabled-by-default in future major releases.

February 2, 2026 MicrosoftNTLMKerberos

New n8n Sandbox Escape Vulnerabilities Allow Remote Code Execution

JFrog discovered two sandbox escape flaws in n8n: CVE-2026-1470 (CVSS 9.9) bypasses JavaScript sandboxing via deprecated 'with' statement, and CVE-2026-0863 (CVSS 8.5) escapes Python restrictions via AttributeError.obj.

February 2, 2026 n8nvulnerabilityRCE

PDF Phishing Campaign Harvests Dropbox Credentials via Trusted Cloud Infrastructure

A phishing campaign uses clean PDF attachments hosted on Vercel to redirect victims to fake Dropbox login pages, bypassing email security by avoiding traditional malware or suspicious links.

February 2, 2026 phishingDropboxcredential theft

WinRAR Vulnerability Still Widely Exploited by Nation-State and Cybercrime Groups

CVE-2025-8088 (CVSS 8.8), a path traversal flaw abusing Windows Alternate Data Streams, continues to be exploited by Russian APTs, Chinese actors, and cybercriminals to achieve persistence via Startup folder drops.

February 2, 2026 WinRARCVE-2025-8088APT

Automated Extortion Campaign Wipes 1,400 MongoDB Servers, Demands Bitcoin Ransom

A single threat actor is conducting automated attacks against exposed MongoDB instances, wiping databases and demanding 0.005 BTC per server, with 208,500 instances publicly exposed worldwide.

February 1, 2026 extortionMongoDBdatabase security

EU AI Act Enforcement Enters Second Year — Commission Review Triggers Potential Expansion

The European Union's AI Act marks one year of prohibited AI enforcement on February 2, 2026, triggering Article 112's mandated Commission review. High-risk AI rules take effect August 2027.

February 1, 2026 EU AI ActAI regulationcompliance
‹ Prev
123…9
Next ›
SYS ONLINE
PAGES 963
UPDATED 2026-02-06
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

// Sections

  • › News
  • › Rankings
  • › Companies
  • › Breaches

// Resources

  • › Guides
  • › Compliance
  • › Tags
  • › About

// Feeds

  • › All Content
  • › News Only
  • › Breaches Only

> © 2026 UINAT. All rights reserved.

[ DEFEND THE PERIMETER ]

Search