Week 6 - 2026 Weekly Digest
02 Feb 2026 – 08 Feb 2026 • Published: 09 Feb 2026
Critical CVEs
CVE-2026-21643 — SQL injection CVSS 9.8A SQL injection vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized commands or code through specially crafted HTTP requests.
CVE-2026-25049 — Workflow Parameter Command Injection CVSS 9.4Before versions 1.123.17 and 2.5.2, in n8n an authenticated user with workflow edit permissions can exploit specially crafted parameters to execute commands on the server.
CVE-2026-25632 — Command Execution via Crafted JSON CVSS 10EPyT-Flow allows an attacker to execute operating system commands by sending specially crafted JSON requests to its REST API.
Top Security News
Notepad++ Hijacked by State-Sponsored Hackers NewsBetween June and December 2025, Notepad++ was affected by an infrastructure compromise that allowed attackers to redirect update traffic to malicious servers.
Norwegian intelligence discloses country hit by Salt Typhoon campaign NewsThe Norwegian internal security agency has confirmed that the espionage campaign, known as Salt Typhoon, compromised the network devices of Norwegian organizations.
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities NewsAccording to recent findings by Palo Alto, over the past year, an undocumented cyber-espionage group operating in Asia has infiltrated the networks of at least 70 government organizations.
Ransomware Activity
LABINF RansomwareThe threat actor clop claims responsibility for a ransomware attack against the victim in the Information Technology sector on February 7.
Parente Fireworks RansomwareThe threat actor qilin claims responsibility for a ransomware attack against the victim in the Pyrotechnics sector on February 6.
Silvi SRL RansomwareThe threat actor thegentlemen claims responsibility for a ransomware attack against the victim in the Automotive sector on February 6.
Comune di Battipaglia RansomwareThe threat actor Medusa claims responsibility for a ransomware attack against the victim in the Local Administrations sector on February 3.
Ferretti Construction RansomwareThe threat actor Akira claims responsibility for a ransomware attack against the victim in the Construction sector on February 2.



