Week 6 - 2026 Weekly Digest

02 Feb 2026 – 08 Feb 2026 • Published: 09 Feb 2026

CVE News Ransomware 8Bit Content Week 6 2026

Critical CVEs

CVE-2026-21643 — SQL injection CVSS 9.8

Fortinet FortiClientEMS

A SQL injection vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized commands or code through specially crafted HTTP requests.

CVE-2026-25049 — Workflow Parameter Command Injection CVSS 9.4

n8n workflow

Before versions 1.123.17 and 2.5.2, in n8n an authenticated user with workflow edit permissions can exploit specially crafted parameters to execute commands on the server.

CVE-2026-25632 — Command Execution via Crafted JSON CVSS 10

Python EPyT-Flow

EPyT-Flow allows an attacker to execute operating system commands by sending specially crafted JSON requests to its REST API.

Top Security News

Notepad++ Hijacked by State-Sponsored Hackers News

Between June and December 2025, Notepad++ was affected by an infrastructure compromise that allowed attackers to redirect update traffic to malicious servers.

Source: Notepad Plus Plus

Norwegian intelligence discloses country hit by Salt Typhoon campaign News

The Norwegian internal security agency has confirmed that the espionage campaign, known as Salt Typhoon, compromised the network devices of Norwegian organizations.

Source: The Record

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities News

According to recent findings by Palo Alto, over the past year, an undocumented cyber-espionage group operating in Asia has infiltrated the networks of at least 70 government organizations.

Source: The Hacker News

Ransomware Activity

LABINF Ransomware

The threat actor clop claims responsibility for a ransomware attack against the victim in the Information Technology sector on February 7.

Parente Fireworks Ransomware

The threat actor qilin claims responsibility for a ransomware attack against the victim in the Pyrotechnics sector on February 6.

Silvi SRL Ransomware

The threat actor thegentlemen claims responsibility for a ransomware attack against the victim in the Automotive sector on February 6.

Comune di Battipaglia Ransomware

The threat actor Medusa claims responsibility for a ransomware attack against the victim in the Local Administrations sector on February 3.

Ferretti Construction Ransomware

The threat actor Akira claims responsibility for a ransomware attack against the victim in the Construction sector on February 2.

What we shipped at 8BitSecurity