Week 4 - 2026 Weekly Digest

19 Jan 2026 – 24 Jan 2026 • Published: 26 Jan 2026

CVE News Ransomware 8Bit Content Week 4 2026

Critical CVEs

CVE-2024-37079 — Heap-overflow vulnerability CVSS 9.8

VMware vCenter Server

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

CVE-2026-0920 — Unauthenticated admin‑creation flaw CVSS 9.8

WordPress LA-Studio Element Kit

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'lakit_bkrole' parameter during registration and gain administrator access to the site.

CVE-2026-21962 — Unauthorized access and data‑modification CVSS 10

Oracle Oracle HTTP Server, WebLogic Server Proxy Plug‑in

Vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug‑in that allows an unauthenticated attacker over HTTP to gain unauthorized access and modify critical data.

Top Security News

KONNI Adopts AI to Generate PowerShell Backdoors News

Check Point has identified a phishing campaign linked to KONNI, a North Korea–associated criminal group, aimed at distributing PowerShell‑based backdoors generated with the assistance of artificial intelligence

Source: Check Point

Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware News

A new multistage phishing campaign is targeting users in Russia with ransomware and the Amnesia RAT. It uses business‑themed documents as lures to mask silent malicious activity, and relies on multiple public cloud services, GitHub for scripts and Dropbox for binary payloads, to increase resilience and hinder takedown efforts

Source: The Hacker News

Sandworm hackers linked to failed wiper attack on Poland’s energy systems News

A cyberattack against the Polish power grid in late December 2025 has been attributed to the pro‑Russian hacker group Sandworm, which deployed a new malware strain known as DynoWiper.

Source: Bleeping Computer

Ransomware Activity

Frandent Ransomware

The threat actor Lockbit5 claims responsibility for a ransomware attack against the victim in the automotive sector on January 21.

Sita Sud Ransomware

The threat actor Thegentlemen claims responsibility for a ransomware attack against the victim in the transport sector on January 20.

Mec Matica Ransomware

The threat actor Sarcoma claims responsibility for a ransomware attack against the victim in the engineering consulting sector on January 20.

San Carlo Gruppo Alimentare Ransomware

The threat actor Thegentlemen claims responsibility for a ransomware attack against the victim in the food and drinks businesses sector on January 20.

Casadei Ransomware

The threat actor Qilin claims responsibility for a ransomware attack against the victim in the manufacturing sector on January 19.

What we shipped at 8BitSecurity